DifyTap: Four Bugs Put over 1 million AI Apps at Risk
2026-06-23T20:51:47Z•537a7bb0365d1fce0d9e1db4d36529039a28d5968e239ea175fc2d091baec07f
ai-securitybootromcredential-theftdata-breachhealthcaremalwarenation-stateproxyremote-accessrouter-compromisesquidsupply-chainunpatchable-exploitvulnerabilitywordpress-plugin
What happened
A cluster of high-impact incidents and vulnerabilities reported 22–23 Jun 2026: Zafran Labs disclosed four Dify vulnerabilities (including two critical flaws) that exposed cross-tenant AI data across an ecosystem powering ~1M apps; Xsolis and Texas Parks & Wildlife breaches exposed personal and health data for ~1.4M and ~3M people respectively via phishing and a third‑party vendor; ShapedPlugin’s build/distribution pipeline was breached, pushing backdoored Pro plugin updates that steal credentials and 2FA secrets; Squidbleed (CVE-2026-47729) is a long-standing Squid Proxy memory overread that泄
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 537a7bb0365d1fce0d9e1db4d36529039a28d5968e239ea175fc2d091baec07f
- Enrichment time
- 2026-06-23T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.