TLDR

TLDR Information Security 2026-06-23

Apple Beats Wiretap Bug 🎧, Langflow Under Attack πŸ€–, MCP Agentjacking Risk πŸ”Œ

Save $400 on Gartner Identity & Access Management Summit 2026 (Sponsor)

πŸ”“

Attacks & Vulnerabilities

7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes (5 minute read)

Gizmodo readers hit with ClickFix malware prompts after account compromise (1 minute read)

Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap (3 minute read)

🧠

Strategies & Tactics

Reverse Once, Run Forever: Defending Code You Can't Hide (7 minute read)

A public Sentry key is all it takes to hijack Claude Code, Cursor, and Codex (4 minute read)

An update on FortiBleed β€” what's happening with victim orgs (7 minute read)

πŸ§‘β€πŸ’»

Launches & Tools

SpiderFoot (GitHub Repo)

Defending Code Reference Harness (GitHub Repo)

🎁

Miscellaneous

RFC 9958 - Post-Quantum Cryptography for Engineers (50 minute read)

Canada's Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices (3 minute read)

Why your microVM sandbox solves a particular problem very well, but not the agent security problem (4 minute read)

⚑️

Quick Links

Google hits 50% IPv6 (5 minute read)

Curated news πŸ“°, research πŸ§‘β€πŸ”¬, and tools πŸ”’ for information security professionals

Join 410,000 readers for one daily email