

Issue #206 - July 6, 2026

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
Source: Dark Reading
Researchers disclosed GitLost, a prompt-injection weakness in GitHub agentic workflows that could let unauthenticated attackers use a public GitHub issue to pull private repository data. The story highlights a fast-growing risk: AI agents with broad access can be manipulated by ordinary text if trust boundaries are weak.
Fake IT support calls on Microsoft Teams push EtherRAT malware
Source: BleepingComputer
Attackers are combining phishing emails, Microsoft Teams voice calls, remote-control tooling, and a Node.js malware loader to deploy EtherRAT. The campaign impersonates IT support and persuades users to grant control, showing how collaboration platforms can become high-trust channels for initial access.
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Source: The Hacker News
A suspected China-aligned cluster is exploiting Roundcube webmail flaws against U.S. and Canadian university departments tied to physics, engineering, and national security research. The campaign uses vulnerable webmail servers to steal credentials, deploy web shells, and maintain access with post-exploitation tooling.
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Source: SecurityWeek
CERT/CC warned that multiple Tenda firmware versions contain an undocumented backdoor enabling authentication bypass and administrative access. No patch has been released, so exposed routers, switches, and other devices could be reconfigured or weakened by attackers unless remote management is disabled and access is restricted.
Armored Likho APT Targeting Government, Electric Power Entities
Source: SecurityWeek
Kaspersky researchers described Armored Likho, an APT targeting government and electric power organizations with modular RATs, infostealers, tunneling tools, and spear-phishing lures. The group blends espionage and financially motivated activity, using malware capable of credential theft, screenshots, file enumeration, persistence, and remote access.


Talk to a Blue INK expert
From strengthening security and preparing for audits to navigating privacy and governing AI, we'll connect you directly with the right expert.

Have questions?
Let us know the best way to reach you and we will be in touch as soon as possible to answer your questions.


Stay ahead of new threats
Cut through the noise and stay ahead of emerging threats most relevant to your business. Our Weekly INK curates everything you need to know about cybersecurity threats targeting businesses.



