Related Threat Clusters
-
Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products
The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket has a serious broken access control vulnerability. This flaw allows attackers with valid user credentials to bypass multi-factor authentication…
3 articles · Updated June 17, 2026 -
RovoBlast Vulnerability Exposes Enterprise Data via One-Click Attack
Atlassian's Rovo AI assistant was found vulnerable to a one-click prompt injection attack, dubbed RovoBlast, which allows attackers to inject malicious instructions into authenticated user sessions. This vulnerability…
4 articles · Updated August 10, 2026 -
Claude Code MCP Traffic Hijacked to Steal OAuth Tokens
A new man-in-the-middle (MitM) attack has been identified, targeting Anthropic's Claude Code ecosystem. Threat actors exploit vulnerabilities in the Model Context Protocol (MCP) traffic to intercept OAuth authentication…
3 articles · Updated June 8, 2026 -
AI-Driven Command Injection Vulnerability Exposes Snowflake Jira Credentials
A critical command injection vulnerability was discovered in Snowflake's GitHub Actions workflow, allowing unauthenticated attackers to execute arbitrary commands. The flaw was introduced by an AI coding assistant,…
12 articles · Updated August 17, 2026 -
GitHub and Jira Notification Systems Exploited for Phishing Attacks
Cybercriminals have exploited GitHub and Atlassian Jira's notification systems to send phishing emails that appear legitimate. These emails bypass standard security checks such as SPF, DKIM, and DMARC because they…
2 articles · Updated April 14, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Prompt Injection Vulnerability in GitHub Actions AI Agents Exposes Secrets
Security researchers discovered a critical vulnerability in three AI agents integrated with GitHub Actions: Anthropic's Claude Code Security Review, Google's Gemini CLI Action, and Microsoft's GitHub Copilot. The…
12 articles · Updated April 15, 2026 -
Żabka Polska Cyberattack Exposes Employee Data and Source Code for Sale
Żabka Polska, Poland's largest convenience store chain, confirmed a cyberattack involving unauthorized access to its network. The breach was detected through an external service provider, and the company reported that…
2 articles · Updated August 5, 2026 -
Standard Bank Data Breach: Hackers Release Stolen Customer Data
On April 17, 2026, hackers publicly released data stolen from Standard Bank, following a breach disclosed on March 23, 2026. The breach involved unauthorized access to internal systems, exposing client records such as…
4 articles · Updated April 17, 2026 -
AI Agents Vulnerable to Zero-Click Attacks: A Growing Threat
Michael Bargury, CTO of Zenity, revealed that enterprise AI agents are highly susceptible to zero-click attacks, which exploit their gullibility. These attacks can manipulate AI systems like Cursor, Salesforce, and…
2 articles · Updated March 23, 2026
Recent Intelligence Reports
- Global sinkhole operation ends Sality botnet's 23-year run — Helpnetsecurity · September 2, 2026
- Spinone — spin.ai · September 1, 2026
- Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed — Infosecurity-Magazine · August 18, 2026
- Wiz agent finds Snowflake repo flaw in code co — Feeds.Feedburner · August 18, 2026
- AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira — News.Ycombinator · August 17, 2026
- Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant — Infosecurity-Magazine · August 10, 2026
- One — Csoonline · August 10, 2026
- Atlassian Rovo Prompt Injection Exfiltrates Jira and Confluence Data Without User Approval — Cybersecuritynews · August 10, 2026