Dify: When Your AI Platform Becomes the Attack Surface

Executive Summary We identified a couple of vulnerabilities in AI automation platform Dify resulting in cross-tenant sensitive information disclosure and one-click account takeover. These findings reinforce the pattern we documented in our previous n8n blogpost: even though AI automation platforms are increasingly becoming integration hubs for complex workflows, their security posture still lags behind their rapid evolution and operational importance.  Introduction Dify is an open-source platform for building LLM-powered applications: agents,…

Philippine Gov’t IOs Receive Cybersecurity Training

Government information officers across the Philippines’ Western Visayas region participated in specialized cybersecurity training at Iloilo Science and Technology University on April 29, 2025. This article has been indexed from CyberMaterial Read the original article: Philippine Gov’t IOs Receive Cybersecurity…

NCSC Releases Agentic AI Security Guidance

The UK’s National Cyber Security Centre (NCSC) has released new security guidance for organizations deploying agentic AI systems, highlighting the unique cyber risks posed by autonomous artificial intelligence agents. This article has been indexed from CyberMaterial Read the original article:…

Pwn2Own Berlin 2026: 47 zero-days, $1.3M rewards

The Pwn2Own Berlin 2026 hacking competition concluded with security researchers successfully exploiting 47 zero-day vulnerabilities across multiple products, earning collective rewards totaling $1,298,250. This article has been indexed from CyberMaterial Read the original article: Pwn2Own Berlin 2026: 47 zero-days, $1.3M…

Paper Werewolf APT Spreads EchoGather RAT

A sophisticated threat actor known as Paper Werewolf has launched targeted cyberattacks against Russian organizations across industrial, financial, and transport sectors during a two-month campaign spanning March and April 2026. This article has been indexed from CyberMaterial Read the original…