ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories — Ravie LakshmananJul 23, 2026Hacking News / Cybersecurity News [https

threatsday-android-spyware-plc-attacks-ai-image-prompt-injection-12-more-stories

What’s new: This week’s cybersecurity threats include a malicious npm package that installs a macOS infostealer, a rogue Visual Studio Code extension that opens a backdoor, and a fake Android app masquerading as a civil defense alert tool that collects sensitive data. Additionally, Iranian-affiliated actors are targeting PLCs in critical infrastructure sectors, and a new attack technique called GhostCommit uses images to exfiltrate repository secrets.

Who’s affected

Organizations using GitHub Enterprise Server, npm users on macOS, Visual Studio Code users, and individuals in Portugal targeted by phishing campaigns. Additionally, critical infrastructure sectors in the U.S. are at risk from Iranian-affiliated cyber activity.

What to do

  • Update GitHub Enterprise Server to the latest patch release before August 18, 2026.
  • Monitor npm packages and avoid installing unverified packages.
  • Be cautious of extensions in the Visual Studio Code marketplace and verify their legitimacy.
  • Implement security measures to protect PLCs and restrict direct internet access.
  • Educate users about the risks of downloading apps from unofficial sources.

Sources