[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fkroDejo1QDDtNf2-BMJ00YnO-E4wnPMABmak63k3ZG8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"7eeaf290-7df4-4403-8793-b05ffbaf3276","critical-dify-ai-platform-flaws-enable-silent-chat-history-theft","ffece90b-affd-4b18-8896-d40f2d8cfa71","Critical Dify AI Platform Flaws Enable Silent Chat History Theft","Four critical vulnerabilities (CVE-2024-28910 through CVE-2024-28913) in the Dify open-source AI platform allowed attackers to silently intercept and exfiltrate sensitive user data, including AI chat histories, without detection. The flaws affected all versions prior to 0.6.1, meaning any unpatched deployment remained exposed to covert 'wiretapping' of potentially sensitive conversations. This is particularly concerning because AI platforms increasingly handle confidential business logic, personal data, and proprietary prompts that carry significant privacy and regulatory implications. The incident underscores that open-source AI tooling — rapidly adopted without the same security scrutiny as enterprise software — can introduce serious data exposure risks into production environments.","**Immediate Actions:**\n- Upgrade all Dify deployments to version 0.6.1 or later immediately to remediate all four CVEs.\n- Audit chat history logs and access records for signs of unauthorized data exfiltration prior to patching.\n- Restrict public-facing Dify instances behind a VPN or authenticated reverse proxy until patching is confirmed.\n\n**Long-Term Improvements:**\n- Maintain a complete, up-to-date inventory of all open-source AI and third-party platform components with associated version tracking.\n- Integrate automated Software Composition Analysis (SCA) tools into CI\u002FCD pipelines to detect vulnerable dependencies before deployment.\n- Classify AI chat history and prompt data as sensitive and apply encryption-at-rest and encryption-in-transit controls accordingly.\n\n**Detection Measures:**\n- Deploy behavioral monitoring and anomaly detection on AI platform APIs to flag unexpected bulk data access or export events.\n- Subscribe to CVE feeds and vendor security advisories for all open-source platforms in use to enable rapid response to newly disclosed vulnerabilities.\n- Implement Data Loss Prevention (DLP) controls to alert on unusual exfiltration patterns from AI platform storage systems.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 3.4: Deploy Automated Operating System Patch Management Tools","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 SC-8: Transmission Confidentiality and Integrity","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST CSF ID.RA-1: Asset Vulnerabilities are Identified and Documented","GDPR Article 32: Security of Processing (protection of personal data)","GDPR Article 33: Notification of a Personal Data Breach","OWASP A06:2021 – Vulnerable and Outdated Components","ITIL Change Management: Emergency Change Procedures for Critical Patches","published","2026-06-23T15:22:36.151635+00:00","2026-06-23T15:22:36.028+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Fdifytap-bugs-wiretap-ai-chat-histories","difytap-bugs-let-attackers-wiretap-ai-chat-histories-b83171","DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]