appsec.fyi · Sources

darkreading.com

17 curated AppSec resources from darkreading.com across 8 topics on appsec.fyi.

darkreading.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-08-19.

Date Added Resource Excerpt
2026-08-19 2026'CoSnitch' Attack Tricked Copilot into Revealing Own ArchitectureAIA new attack, dubbed 'CoSnitch', has successfully exploited GitHub Copilot to reveal its own underlying architecture. This vulnerability allows malicious actors to trick the AI code completion tool into disclosing sensitive information about its internal workings. The researchers behind the 'CoSnitch' attack demonstrated how they could prompt Copilot to leak details that would typically be kept private, potentially aiding further exploitation or understanding of the AI's security posture. The exact payout for this bug bounty was not explicitly stated in the provided content.
2026-08-17 2026Video Call Exploit Chains Two Flaws in Unisoc ModemsRCEA security vulnerability has been discovered in Unisoc modems that can be exploited during video calls. This exploit chains together two separate flaws, allowing an attacker to potentially gain unauthorized access or control. The specific details of how the exploit works are not provided, but it highlights a security risk within the modem's video calling functionality. Further information and the full technical analysis are available at the provided link.
2026-08-08 2026Flaws in Google APK for Python Unlock Agent-to-Agent AttackPythonThis article details security vulnerabilities found in Google's APK for Python that allow for agent-to-agent attacks. These flaws enable unauthorized access and manipulation between different agents, potentially compromising sensitive data or control. The exact payout amount for reporting these vulnerabilities is not specified in the provided content.
2026-07-29 2026When AppSec Scanners Become a Supply Chain Attack VectorSupply ChainApplication security (AppSec) scanners, designed to find vulnerabilities, can inadvertently become a supply chain attack vector. Malicious actors can compromise these tools or their development processes. If an AppSec scanner is compromised, it could potentially inject malicious code or misrepresent vulnerabilities. This could lead organizations to trust and implement insecure code or configurations, unknowingly opening their systems to attacks. The integrity and security of AppSec tools themselves are therefore critical to preventing broader supply chain risks.
2026-06-18 2026Developer Machines And Supply Chain Security RiskSupply ChainThis article discusses the significant supply chain security risks posed by compromised developer machines. It highlights how attackers can target these machines to inject malicious code into software projects, leading to widespread vulnerabilities and breaches. The content emphasizes the importance of securing developer environments, including endpoints, code repositories, and build pipelines, as a critical defense against such attacks. The goal is to prevent compromised development tools from becoming entry points for attackers into the software supply chain.
2026-05-14 2026Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply ChainSupply ChainA new worm, dubbed "Mini Shai-Hulud" by researchers, is actively infecting the software supply chain. This malware targets developers, aiming to compromise their development environments and potentially inject malicious code into legitimate software projects. The worm's propagation methods and specific targets are still under investigation, but its presence signifies a growing threat to the integrity of software development and distribution. Organizations are advised to enhance their security protocols and vigilance against such supply chain attacks.
2026-05-09 2026Every Old Vulnerability Is Now an AI VulnerabilityXSSThis article argues that as Artificial Intelligence (AI) systems become more integrated, traditional cybersecurity vulnerabilities are now also AI vulnerabilities. Existing exploits and weaknesses in software, hardware, and network infrastructure can be leveraged to target or compromise AI models. This means that the vast landscape of known security flaws presents a significant risk to AI systems, requiring a re-evaluation of security strategies to account for this expanded threat surface.
2026-05-07 2026'TrustFall' Exposes Claude Code Execution RiskRCE'TrustFall' Exposes Claude Code Execution Risk https://ift.tt/uApnWBD
2026-04-30 2026TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' AttackSupply ChainTeamPCP has developed a new attack targeting SAP applications called "Mini Shai-Hulud." This sophisticated threat leverages multiple vulnerabilities to bypass security controls and achieve remote code execution. The attack appears to be highly effective, capable of compromising SAP NetWeaver Application Server Java components. Further details on the exploit's mechanics and impact are available via the provided link. No specific bounty payout amounts were mentioned.
2026-04-29 2026AI Finds 38 Security Flaws in OpenEMRAIRCEAn AI security tool, DeepScribe, has identified 38 vulnerabilities in OpenEMR, a popular open-source electronic health record system. These flaws range in severity, with DeepScribe flagging 10 as critical. The company plans to disclose these findings responsibly to OpenEMR's development team. This discovery highlights the potential of AI in uncovering security weaknesses in complex software. The specific bounty payout amount for this discovery is not mentioned.
2026-04-21 2026Google Fixes Critical RCE Flaw in AI-Based Antigravity ToolRCEGoogle Fixes Critical RCE Flaw in AI-Based Antigravity Tool https://ift.tt/1QOIZsB
2026-04-17 2026SBOMs in 2026: Some Love, Some Hate, Much AmbivalenceSupply ChainSBOMs in 2026: Some Love, Some Hate, Much Ambivalence
2026-04-15 2026Privilege Elevation Dominates Massive Microsoft Patch UpdateAuthZLibrary of patches addressing Microsoft's April 2026 update, which included 165 CVEs, with a significant portion being elevation-of-privilege bugs. Key vulnerabilities detailed include CVE-2026-32201 (a SharePoint Server spoofing zero-day actively exploited), CVE-2026-33825 (a Defender privilege escalation zero-day), CVE-2026-33824 (a critical RCE in Windows IKE Service Extensions), and CVE-2026-33827 (a rare unauthenticated RCE in Windows secure tunneling). The update also featured numerous fixes for Microsoft Edge and Chromium.
2026-04-06 2026AI-Assisted Supply Chain Attack Targets GitHubSupply ChainAI-Assisted Supply Chain Attack Targets GitHub https://ift.tt/W3OMdbX
2026-04-03 2026Source Code Leaks Highlight Lack of Supply Chain OversightSupply ChainAnalysis of recent supply chain attacks, including compromises of Trivy, Axios, and Anthropic's Claude Code, reveals significant vulnerabilities in development pipelines and credential management. These incidents highlight risks from misconfigured GitHub Actions, compromised maintainer accounts, and inadequate content checks during publishing, allowing malicious code and sensitive source code to enter the supply chain. Attacks on AI coding agents also introduce new persistence vectors, impacting entire developer workstations and downstream software.
2025-10-24 2025Law Enforcement Cracks Down on XSS but Will It Last?XSSLaw enforcement is increasing efforts to combat Cross-Site Scripting (XSS) attacks. The effectiveness and longevity of these crackdowns are questioned.
2024-07-30 2024OAuth+XSS Attack Threatens Millions of Web Users With Account TakeoverAPI SecAuthNXSSAn attack flow that combines API flaws within "log in with" implementations and Web injection bugs could affect millions of websites.