{"id":1976,"date":"2026-07-23T17:00:03","date_gmt":"2026-07-23T17:00:03","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1976"},"modified":"2026-07-23T17:00:03","modified_gmt":"2026-07-23T17:00:03","slug":"android-spyware-plc-attacks-ai-image-prompt-injection-12-more-stories","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1976","title":{"rendered":"Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 23, 2026<\/span><\/span><span class=\"p-tags\">Hacking News \/ Cybersecurity News<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsmJNuemIhGxFuSqY6pq1opCEJECkmIjXm5VnOqOAEjfpoLxQ89Q-qXBqKQmM8YnwyVP2_feUo4c-VLZ3cC6s_J0VCXdwhLKFezoK1-i4lWQs68yXaZS8XtHGAsDj5zsdOToB7yD1QHzuMYIVQFvb14U6Zhd1cqDOm78tRY1O3v_1LFr7CC-4ItBLpLgZ3\/s1700-e365\/th.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Most of this week&#8217;s trouble came dressed as something useful.<\/p>\n<p>A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic.<\/p>\n<div class=\"article-board\">\n <b\/><\/p>\n<p>The threats change every week. <span data-push-topic=\"threatsday bulletin:t, recap:i\" data-push-label=\"ThreatsDay Bulletin\">Subscribe, and we\u2019ll alert you<\/span> when each new ThreatsDay Bulletin is out.<\/p>\n<\/div>\n<p>The danger was easy to miss because it looked ordinary. Here is the full list:<\/p>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<a name=\"more\"\/><\/p>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Support uploads face cutoff<\/span><\/p>\n<p class=\"td-desc\">\n      GitHub has announced an upcoming security change that may affect GitHub Enterprise Server (GHES) support bundle uploads. \u00abBeginning August 18, 2026, GitHub will start rejecting command-line support bundle uploads from older GHES appliances that have not been updated with the required security patches,\u00bb GitHub <a href=\"https:\/\/github.blog\/changelog\/2026-07-22-upcoming-ghes-change-impacting-uploading-support-bundles\/\" target=\"_blank\">said<\/a>. \u00abTo avoid any disruption when submitting support bundles with ghe-support-bundle, ghe-cluster-support-bundle, or ghe-support-upload commands, please update your GHES instance to the latest patch release available for your current version line.\u00bb At minimum, the required patch versions are: 3.21.3, 3.20.5, 3.19.9, 3.18.12, and 3.17.18.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Npm install triggers stealer<\/span><\/p>\n<p class=\"td-desc\">\n      An npm package named @copilot-mcp\/apex has been found to act as a postinstall dropper that installs a macOS infostealer on any machine that runs npm install or npx @copilot-mcp\/apex. The same payload is said to have been distributed via another dropper named @apexfdn\/apex. \u00abOn macOS, the dropper&#8217;s second stage decrypts and runs an AppleScript payload through osascript,\u00bb SefeDep <a href=\"https:\/\/safedep.io\/malicious-copilot-mcp-apex-npm-macos-infostealer\/\" target=\"_blank\">said<\/a>. \u00abThe decrypted payload is a 707-line AMOS-family stealer: it phishes the login password through a fake system prompt, then harvests browser credentials, 20+ crypto wallets, SSH keys, AWS and Kubernetes credentials, the login Keychain, Telegram, and shell history into \/tmp\/osalogging.zip and uploads it over chunked HTTPS PUT to attacker infrastructure.\u00bb The malware also sets up a LaunchAgent that polls the attacker&#8217;s command-and-control server every 60 seconds to ensure that the infection outlives the initial exfiltration.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake extension opens backdoor<\/span><\/p>\n<p class=\"td-desc\">\n      A Microsoft Visual Studio Code (VS Code) marketplace extension called \u00abMarkdown All Pro\u00bb (\u00abmarkdown.markdown-all-pro\u00bb) has been found to impersonate the legitimate \u00abMarkdown All in One\u00bb extension with over 14 million downloads. Installing the rogue extension allows the machine&#8217;s details to be shipped to the attacker and opens a channel through which the operator can send any additional commands without having to touch the extension again. \u00abOn install, these beacon the machine&#8217;s username and hostname to a hardcoded IP over cleartext HTTP and fetch a remote file to disk, with no user interaction required,\u00bb Manifold Security <a href=\"https:\/\/www.manifold.security\/blog\/a-beaconing-counterfeit-extension-on-the-vs-code-marketplace-the-markdown-all-pro-extension\" target=\"_blank\">said<\/a>. \u00abThis one is small, but it deliberately misrepresents itself as a trusted tool, and the remote fetch it performs is a live delivery channel whose payload the operator can change at any time.\u00bb After the extension was removed by Microsoft, it reappeared under an identical name (\u00abMarkdownLinks.markdown-links-pro\u00bb). The second extension has since been taken down as well.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Old releases locked down<\/span><\/p>\n<p class=\"td-desc\">\n      The Python Package Index (PyPI) has made a new security change that rejects new files being uploaded to releases that are older than 14 days. \u00abThis restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised,\u00bb PyPI <a href=\"https:\/\/blog.pypi.org\/posts\/2026-07-22-releases-now-reject-new-files-after-14-days\/\" target=\"_blank\">said<\/a>. \u00abAs far as we are aware, this has not yet been abused, but there is no technical reason beyond that attackers weren&#8217;t aware it was possible.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Phishing delivers banking malware<\/span><\/p>\n<p class=\"td-desc\">\n      A new malware campaign is targeting Portuguese users through phishing emails impersonating financial and administrative communications to deliver the Lampion banking malware. First publicly documented in December 2019, the Brazilian banking malware family is derived from the ChePro lineage, and has consistently targeted Portugal and other Portuguese-speaking users. \u00abInitial payloads are delivered through ZIP archives containing heavily obfuscated HTML files designed to evade static detection and analysis,\u00bb Acronis <a href=\"https:\/\/www.acronis.com\/en\/tru\/posts\/lampions-portugal-focused-phishing-campaign-delivers-multistage-malware\/\" target=\"_blank\">said<\/a>. \u00abThe HTML stage retrieves and executes additional scripts from attacker-controlled infrastructure, leading to the deployment of a multistage VBS infection chain. Each stage employs extensive obfuscation techniques, including junk code, encrypted strings and dynamically generated scripts, significantly inflating file sizes while concealing core functionality. The infection chain is deliberately fragmented across multiple independent execution stages, complicating behavioral analysis and reducing the visibility of malicious activity.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Call endings trigger ads<\/span><\/p>\n<p class=\"td-desc\">\n      DoubleVerify has uncovered a growing wave of \u00abAfterCall\u00bb apps that trick users into granting special permissions, which then display intrusive ads immediately after Android users end a phone call. The ad fraud scheme is assessed to be responsible for hundreds of millions of ad impressions. \u00abThe fraud works by tricking users into granting overlay permissions, allowing malicious apps to display ads outside their normal context,\u00bb DoubleVerify <a href=\"https:\/\/medium.com\/doubleverify-engineering\/a-new-ad-fraud-trend-aftercall-ads-ec44279843b2\" target=\"_blank\">said<\/a>. \u00abThe apps also use evasion techniques that make them difficult for users to identify and uninstall.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake Claude app drops RAT<\/span><\/p>\n<p class=\"td-desc\">\n      Huntress disclosed that between July 21 and July 22, 2026, at least 29 organizations fell victim to a malvertising campaign that redirected them to a malicious Claude Artifact publicly hosted on the legitimate Claude.ai domain. \u00abThe malicious Claude Artifact redirected users to an attacker-controlled domain, where they downloaded what looks like a legitimate Claude desktop app (ClaudeDesktop.exe),\u00bb Huntress <a href=\"https:\/\/www.huntress.com\/blog\/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat\" target=\"_blank\">said<\/a>. \u00abIn reality, the executable led to the download of SectopRAT. The attackers used an array of anti-analysis techniques, including packaging the malware with VMProtect to make it difficult to reverse engineer and checking the graphics hardware on systems before deciding whether to actually execute the malicious payload as a way to suss out VMs.\u00bb The public Claude Artifact has been removed as of July 22, 2026. The campaign has been codenamed FakeAgent.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Image hides agent instructions<\/span><\/p>\n<p class=\"td-desc\">\n      A new attack technique called <a href=\"https:\/\/github.com\/asset-group\/ghostcommit\" target=\"_blank\">GhostCommit<\/a> employs a pull request that can steal a repository&#8217;s secrets by hiding the malicious instruction inside a PNG image that&#8217;s processed by an LLM reviewer. \u00abThe text rendered in that image names .env, tells the agent to read it byte-by-byte, to encode each byte as its ASCII codepoint, and ends with a self-check that must pass before commit: the decoded numbers have to equal the real .env,\u00bb the University of Missouri-Kansas City&#8217;s ASSET Research Group <a href=\"https:\/\/asset-group.github.io\/disclosures\/ghostcommit\/\" target=\"_blank\">said<\/a>. \u00abThe image is the only place in the entire pull request where any of this appears. Unfortunately, for a text-based reviewer, an image is a binary blob, so there is nothing to read.\u00bb Once the change is committed and merged,  the payload just sits in the repository, dormant, until the trap springs itself when a victim prompts the coding agent in an unrelated session. \u00abThe developer asks the coding agent for something ordinary, say a token-tracking module,\u00bb the researchers said. \u00abThe agent reads the merged AGENTS.md at startup, follows the pointer to build-spec.png, reads the procedure rendered inside, opens .env, and writes the requested module with a provenance constant near the top.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Iran-linked actors target PLCs<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. government has issued an update to an advisory published in April 2026 to warn organizations of ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology (OT) devices. \u00abThe update provides new guidance to detect malicious changes in reusable code modules used within Rockwell Automation PLC programs and adds more recommended mitigations,\u00bb the Cybersecurity and Infrastructure Security Agency (CISA) <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting\" target=\"_blank\">said<\/a>. \u00abIt also expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and possible other PLC manufacturers. The additional manufacturers being targeted emphasize the importance for OT owners and operators to restrict direct internet access and ensure secure PLC deployment.\u00bb The authoring agencies said the Iranian-affiliated activity has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. Targets include Water and Wastewater Systems, Energy, and Government Services and Facilities. The federal advisory does not mention any specific hacking groups.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake alert app enables surveillance<\/span><\/p>\n<p class=\"td-desc\">\n      Dream has disclosed details of an Android app that masquerades as a Bahraini Civil Defense \u00abBH Alert\u00bb siren app but embeds a malware called OctagonPanel to hoover sensitive data from a compromised device. \u00abIt is distributed through a network of look-alike domains that clone the Google Play Store and official Bahraini government sites, complete with fake install animations and ad-tracking pixels, and it deploys a four-stage surveillance platform capable of harvesting lockscreen credentials, SMS and one-time codes, contacts, and screenshots, running banking-app overlays, and taking full remote control of the device,\u00bb Dream <a href=\"https:\/\/dreamgroup.com\/blog\/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post\" target=\"_blank\">said<\/a>. \u00abIt relies on social engineering and the abuse of legitimate Android permissions, delivered under a public-safety brand at a moment when users are primed to install it.\u00bb Earlier this March, the cybersecurity vendor <a href=\"https:\/\/dreamgroup.com\/blog\/when-a-missile-alert-app-becomes-an-intelligence-tool\" target=\"_blank\">highlighted<\/a> another phishing campaign that distributed a trojanized version of the Israeli \u00abRed Alert\u00bb app to silently collect valuable data.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake apps deliver surveillance RAT<\/span><\/p>\n<p class=\"td-desc\">\n      An Iran-nexus threat actor tracked as TAG-182 has been observed disseminating MarkiRAT malware in support of Iranian government surveillance operations. \u00abIt is highly likely that TAG-182 is targeting Iranians living inside and outside the country using different lures, including free download tools and fake VPN applications,\u00bb Recorded Future <a href=\"https:\/\/www.recordedfuture.com\/research\/nexus-tag182-disseminates-markirat\" target=\"_blank\">said<\/a>. \u00abThe group&#8217;s operations are highly likely active across social media platforms like Instagram.\u00bb The malware is distributed through fake Android applications masquerading as legitimate services such as VPNs and media tools to collect intelligence from Iranian targets. \u00abThe MarkiRAT sample identified during this research shares notable tradecraft overlaps with historical variants, including the use of the Background Intelligent Transfer Service (BITS), suggesting a credible relationship between TAG-182 and activity previously attributed to Ferocious Kitten,\u00bb the cybersecurity company added.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI-built apps expose critical flaws<\/span><\/p>\n<p class=\"td-desc\">\n      An analysis of 28 vibe-coded apps has uncovered 434 unique and validated vulnerabilities. \u00abThe most common bug in AI-generated code overall is missing rate-limiting and DoS controls (such as unbounded pagination, no rate limits, or synchronous blocking work),\u00bb Xint <a href=\"https:\/\/go.xint.io\/the-top-security-vulnerabilities-generated-by-ai-code\" target=\"_blank\">said<\/a>. \u00abWhen we narrow our focus to the most critical bugs, a different picture emerges. Secret exposures made up the largest share of the most critical bugs in AI-generated code. These are hard-coded or default secrets that allow an attacker to forge sessions or tokens. Authorization and IDOR bugs &#8211; a type of flaw where a user gets access to data beyond their permissions &#8211; were more common in larger apps.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI guardrails become attack tools<\/span><\/p>\n<p class=\"td-desc\">\n      An enterprising Russian-speaking threat actor known as Trim has \u00abspent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools,\u00bb Cato Networks <a href=\"https:\/\/www.catonetworks.com\/blog\/cato-ctrl-how-one-threat-actor-turned-frontier-ai-into-an-offensive-platform\/\" target=\"_blank\">said<\/a>. \u00abWhat started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform.\u00bb Trim has also outlined six techniques for jailbreaking Claude Opus: Context Warming, which involves opening with innocent professional queries before slipping in a malicious request; Black Box Principle, which strips the model of the ability to reason by instructing it via system prompt to analyze only code structure; Ghost Reset, which involves gaslighting the model mid-session by deleting an ongoing chat, reopening it, telling Claude that the internet dropped, and feeding it a softened version of the refused request; Model Cascading, which falls back to alternative AI models if one refuses to comply; Local Uncensored Models, which uses self-hosted or locally run AI models with few or no safety guardrails when commercial models block requests; and Gray-Market API Access, which obtains low-cost API keys from underground resellers to access commercial AI models. The findings once again demonstrate that frontier AI safety controls can be bypassed by a determined and technically literate adversary, and how quickly threat actors can capitalize on generative AI.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">DNS traffic conceals TrickBot C2<\/span><\/p>\n<p class=\"td-desc\">\n      A new version of the TrickBot malware has been observed using DNS tunneling to communicate with its command-and-control (C2) servers. \u00abTo protect itself from static analysis, TrickBot employs several obfuscation techniques,\u00bb Fortinet <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/inside-a-trickbot-variant-using-dns-tunneling-for-c2\" target=\"_blank\">said<\/a>. \u00abThis TrickBot maintains persistence on the victim&#8217;s computer by leveraging the Windows Task Scheduler. TrickBot wraps its command-and-control request packets in encrypted DNS query packets.\u00bb While normal DNS response packets typically contain the IP addresses associated with the queried domain, TrickBot uses it to hide the malicious data within the IP addresses of these responses. This, in turn, allows the malware to fetch commands to be executed on the machine or download and run additional modules.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI models pinpoint vulnerable code<\/span><\/p>\n<p class=\"td-desc\">\n      Cisco has unveiled <a href=\"https:\/\/blogs.cisco.com\/ai\/introducing-antares-the-most-efficient-open-weight-ai-models-for-vulnerability-localization\" target=\"_blank\">Antares<\/a>, which it frames as a \u00abfamily of security small language models (SLMs) purpose-built for one of the hardest, most time-consuming and expensive problems in security: pinpointing where known vulnerabilities exist within a codebase.\u00bb The network equipment company further noted that \u00abAntares follows an iterative search pattern that resembles how a human investigator works through a repository. Each model starts from a vulnerability description, searches for relevant code patterns, reads candidate files, incorporates new evidence, changes direction when a path is unhelpful, and narrows toward the files most likely to matter. The goal is not to replace expert judgment, but rather to help make the first stages of source-code vulnerability triage faster, more repeatable, and easier to review.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>The common thread was not advanced hacking. It was borrowed trust. Each threat used something people already accept: an install, a permission, a familiar name, or a normal system feature.<\/p>\n<p>That changes the job. The question is no longer only \u00abIs this safe?\u00bb It is also \u00abWhat can this do if it is not?\u00bb The smaller the action looks, the tighter its limits should be.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 23, 2026Hacking News \/ Cybersecurity News Most of this week&#8217;s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1977,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[281,24,2435,525,2691,684,1030,187],"class_list":["post-1976","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-android","tag-attacks","tag-image","tag-injection","tag-plc","tag-prompt","tag-spyware","tag-stories"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1976","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1976"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1976\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1977"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1976"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1976"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1976"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}