Dify — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
June 23, 2026
Last Seen
June 23, 2026

Dify is a technology platform tracked by ThreatCluster, appearing in 2 threat clusters built from 5 intelligence report mentions.

Dify is a technology platform tracked across 2 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed June 23, 2026; most recent activity June 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • 4 vulnerabilities in Dify expose cross-tenant data | brief — Scworld · June 23, 2026
  • Dify AI Platform Hit by Four CVEs, Worst One Still Unpatched — Aiweekly.Co · June 23, 2026
  • DifyTap: Four Bugs Put over 1 million AI Apps at Risk — Securityaffairs.Co · June 23, 2026
  • Cordyceps Supply chain Vulnerability Impacting Code Repositories at thousands of Organizations — Gbhackers · June 23, 2026
  • DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps — Gbhackers · June 23, 2026

Frequently asked questions

What is Dify?

Dify is a technology platform tracked by ThreatCluster, appearing in 2 threat clusters built from 5 intelligence report mentions.

Is Dify still active?

The most recent intelligence report mentioning Dify on ThreatCluster is dated June 23, 2026.

What is Dify associated with?

Across ThreatCluster reporting, Dify most frequently co-occurs with Dropping Elephant, Data Breach, Supply Chain Attack, Cloudflare, Microsoft Azure, among 12 tracked related entities.

What are the latest developments involving Dify?

The most significant recent cluster is “Cordyceps Vulnerability Exposes Thousands of Code Repositories to Attacks” (13 articles · Updated June 23, 2026). Dify appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Dify?

Dify appears in 5 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown