The Wire.Tracking threats to Agents 312 raw → 45 curated · updated 27 Jun 2026

Incident · curated 27 Jun 2026

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

First reported 22 Jun 2026 · 4d ago

Coverage timeline

22 Jun 2026

Single-source incident — first reported, latest, and curated coincide.

Cross-tenant exposure of AI chats in a widely used agentic workflow platform could leak sensitive data from any organization relying on Dify.

Researchers at Zafran Security disclosed four vulnerabilities, collectively codenamed DifyTap, in the open-source agentic workflow platform Dify that could allow unauthenticated attackers to stealthily read AI conversations from other customers' applications across tenants.

Why it matters

Cross-tenant exposure of AI chats in a widely used agentic workflow platform could leak sensitive data from any organization relying on Dify.

Curated from sources around the web.
Permalinks stay valid even if an incident is later merged.   Feed · Search · API docs · RSS