Issue #206 - July 6, 2026
- Jul 6
- 2 min read
'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
Source: Dark Reading
Researchers disclosed GitLost, a prompt-injection weakness in GitHub agentic workflows that could let unauthenticated attackers use a public GitHub issue to pull private repository data. The story highlights a fast-growing risk: AI agents with broad access can be manipulated by ordinary text if trust boundaries are weak.
Fake IT support calls on Microsoft Teams push EtherRAT malware
Source: BleepingComputer
Attackers are combining phishing emails, Microsoft Teams voice calls, remote-control tooling, and a Node.js malware loader to deploy EtherRAT. The campaign impersonates IT support and persuades users to grant control, showing how collaboration platforms can become high-trust channels for initial access.
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Source: The Hacker News
A suspected China-aligned cluster is exploiting Roundcube webmail flaws against U.S. and Canadian university departments tied to physics, engineering, and national security research. The campaign uses vulnerable webmail servers to steal credentials, deploy web shells, and maintain access with post-exploitation tooling.
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Source: SecurityWeek
CERT/CC warned that multiple Tenda firmware versions contain an undocumented backdoor enabling authentication bypass and administrative access. No patch has been released, so exposed routers, switches, and other devices could be reconfigured or weakened by attackers unless remote management is disabled and access is restricted.
Armored Likho APT Targeting Government, Electric Power Entities
Source: SecurityWeek
Kaspersky researchers described Armored Likho, an APT targeting government and electric power organizations with modular RATs, infostealers, tunneling tools, and spear-phishing lures. The group blends espionage and financially motivated activity, using malware capable of credential theft, screenshots, file enumeration, persistence, and remote access.



