ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Summary
This weekly threat bulletin covers 15+ cybersecurity incidents, including malicious npm packages that steal credentials when installed, a fake VS Code extension that impersonates a legitimate tool to open a backdoor (remote access channel where attackers can send commands), and an AI image that can inject hidden orders into an AI agent. Most threats disguised themselves as useful software or blended into normal activity, making them easy to overlook.
Solution / Mitigation
GitHub: 'update your GHES instance to the latest patch release available for your current version line' with minimum required versions 3.21.3, 3.20.5, 3.19.9, 3.18.12, and 3.17.18. PyPI: implemented a new security change rejecting new file uploads to releases older than 14 days to prevent poisoning of stable releases. N/A -- no mitigations discussed for the npm stealer, fake VS Code extension, or AI image prompt injection incidents.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
First tracked: July 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 65%