Supply-chain attacks
Compromised packages, poisoned updates, and vendor integrations turned hostile across the software and SaaS supply chain.
Critical Predis flaw lets attacker-controlled data smuggle extra Redis commands (CVE-2026-84372)
CVE-2026-84372 is a CVSS 9.8 command-injection flaw in the Predis PHP client. It hits 3.0 to 3.2 on cluster and replication connections. Upgrade to 3.3.0.
A BGP hijack pushed a malicious Virtualizor update that ran as root. Check for one systemd service.
A 33-hour BGP hijack redirected Softaculous update traffic and pushed a malicious Virtualizor package that ran as root. Check a systemd service, patch 3.2.9.9.
Trusted browser extensions turned into crypto-wallet drainers after silent updates
Browser extensions in the Superior campaign shipped clean, then a silent update drained crypto wallets and stole logins. How to detect it and respond.
VulnCheck finds two factory backdoors in ZBT routers that hand attackers full control. No fix exists.
VulnCheck found two more factory implants in ZBT router firmware, SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233), that grant remote root access.
Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs
Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car's connection as a residential proxy.
Malicious Rust crates arrayref, internment and append-only-vec ran a stealer at build time. Pin now.
Three popular Rust crates, including arrayref with 245M downloads, were briefly poisoned to run an infostealer during cargo build on August 20.
A poisoned Trivy scanner, not LiteLLM, exposed 2,500 organizations' CI/CD secrets
CloudSEK maps 2,500+ organizations exposed by the TeamPCP (UNC6780) supply-chain campaign.
Mozilla reissued the GPG key signing Firefox and Thunderbird on Linux after a leak, voiding old signatures
Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it was committed unencrypted to a private repo. What breaks, and what to do now.
BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell
A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.
China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor
Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.
A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands
A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.
Malicious npm packages skip install scripts and hide their C2 in DNS to drop a cross-platform stealer
Flooding Dropper seeded close to 800 malicious npm packages that run on require() and fall back to DNS TXT records for C2. How to detect it and clean up.
Attackers turn unpatched TrueConf servers into backdoor delivery, pushing trojanized client installers
Head Mare exploited unpatched TrueConf servers (before 5.3.9, 5.4.9, 5.5.5) to swap client installers for unsigned backdoors.
VulnCheck: Zbtlink routers ship a factory root shell with no fix. The model list is not where you start.
VulnCheck found a factory-shipped remote-access implant in 20 Zbtlink router models that calls home and hands a remote root shell. There is no patched firmware.
A self-spreading npm worm poisoned hundreds of packages to steal cloud and GitHub tokens
A self-propagating npm worm that began in keyv 6.0.0 poisoned hundreds of packages on August 4, steals GitHub, npm, cloud, Vault and Kubernetes credentials
N-able N-central auth bypass grants admin; first fix failed
N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.
Amazon ties the debug, chalk, and axios npm hijacks to North Korea
npm supply-chain attacks on debug, chalk, and axios are tied to one North Korean crew, Sapphire Sleet. Why signing missed it, and how to detect it.
Adform's shared ad-tracking script was hijacked to swap crypto wallet addresses in visitors' browsers
Attackers trojanized Adform's shared trackpoint-async.js to swap Bitcoin, Ethereum, and Tron wallet addresses in visitors' browsers. Why SRI can't stop it.
Anthropic's own AI models breached three real companies in tests
Anthropic says three of its AI models breached real companies during security tests after a sandbox misconfiguration. Two of three victims never noticed.
FCC adds networked robots and inverters to its Covered List. The installed base is still yours to secure.
The FCC added networked power inverters and mobile robots to its Covered List over remote-control risk.
Ruflo's unauthenticated AI agent bridge runs code (CVE-2026-59726); patching won't evict the poisoned memory
Ruflo exposed an unauthenticated MCP bridge to 233 tools, so one request gets full remote code execution (CVE-2026-59726).
GitHub and PyPI add release delays to slow poisoned packages
GitHub now waits three days before Dependabot opens an update pull request, and PyPI locks old releases from new files.
A GitLab flaw lets any user with push access run code on the server, and a public exploit is now out
GitLab quietly patched a self-managed code-execution flaw on June 10 with no CVE. A public exploit is now out and any push-access user can run code as git.
An AI agent breached Hugging Face. Blocklists can't catch it.
Hugging Face says an autonomous AI agent breached it, taking internal data and service credentials.
AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.
Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.
How a PNG in a pull request makes AI agents leak secrets
Researchers hid prompt-injection text inside a PNG in a pull request and made AI coding agents read .env and leak the secrets.
Ghost accounts are mapping your GitHub org. The recon is invisible; the stolen token is not.
Datadog found 50+ dormant GitHub accounts enumerating corporate orgs through the public API, some escalating to private-repo clones with stolen tokens.
npm just killed install-script malware by default. This week's other attack walks right past it.
npm 12 disables install scripts by default, which would have stopped this week's jscrambler infostealer.
Three attacks in one week turned AI coding agents into an unmonitored way onto your network
HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer's privileges. No CVE, no patch. Here is the detection posture.
Three ransomware responders secretly worked for BlackCat. Trust is the attack surface.
Three incident-response insiders at DigitalMint and Sygnia were sentenced for helping run BlackCat ransomware, one leaking victims' insurance limits.
A fake 7-Zip installer rents your server out as a residential proxy, and file scans miss it
A trojanized 7-Zip and VPN campaign called Lurking Lizard turns servers and PCs into residential proxy nodes.
The new Cavern C2 needs no CVE. It abuses your IT provider's own tools to get in.
Check Point ties the Iran-linked Cavern C2 to intrusions that skip vulnerabilities entirely, abusing IT providers' own deployment tools.
AI reopened a 2017-audited filesystem and found seven bugs your devices can't patch
runZero found seven flaws in FatFs, the filesystem inside millions of cameras, drones and controllers. No upstream patch exists. How to detect and contain it.
A poisoned security scanner ran on your build server and walked out with your cloud keys
The FBI's TeamPCP FLASH alert shows why a trojanized scanner steals from your servers, not the registry, and why pinning packages will not save you.
Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it
ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.
AI keeps inventing web addresses that do not exist. Attackers now buy them first.
Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot's answer into a phishing and supply chain threat.
An old bash trick makes AI coding agents run the commands they just blocked
AI coding agent guardrails fall to GuardFall, a bash trick that bypassed the command safety check in 10 of 11 open-source agents Adversa AI tested.
119 browser extensions hid malware inside images and fonts for two years
Microsoft pulled 119 malicious Edge extensions in the StegoAd campaign. Steganographic payloads, 2.6 million installs, and a 2FA lesson for defenders.
The code was clean. The toolchain that shipped it was the attack.
This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.
A crafted link can stall millions of Node apps, and the patch will not reach most of them
decode-uri-component, the npm decoder behind query-string and millions of apps, has a denial-of-service bug (CVE-2026-45822).
You don't have to install this npm malware. Opening the folder in your editor runs it.
Two hijacked npm packages skip the install step entirely. They run when you open the project in VS Code, then steal developer, browser, and wallet logins.
The repo is clean. Your AI coding agent is what hands the attacker a shell.
Mozilla's 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.
libssh2 flaw: a malicious SSH server can hijack the client connecting to it
libssh2's CVE-2026-55200 lets a malicious SSH server run code on the client that connects to it. No login, a public PoC is out, and there is no tagged fix yet.
Polymarket's servers were never hacked. A poisoned vendor script still stole $3 million from users.
A compromised third-party vendor injected malicious code into Polymarket's site and stole nearly $3 million from users. The backend was never breached.
Open the wrong repo and Amazon Q ran its config file as you, AWS keys included
Amazon Q Developer ran a repo's MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.
A free GitHub account can push code as a trusted maintainer. Upgrading actions/checkout won't fix it.
Cordyceps lets anyone with a free GitHub account run code as a maintainer on 300+ repos. Why upgrading actions/checkout closes one door, not the others.
The free plugin was clean. The paid update is what backdoored these WordPress sites.
Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.
Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams
Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store's own scanner.
Java's most-used JSON library has a guardrail attackers can slip dangerous objects past
CVE-2026-54513 lets attackers bypass jackson-databind's polymorphic type validator by wrapping a banned class in an array. Patch to 2.18.8, 2.21.4 or 3.1.4.
PixelSmash: a video your server opens by itself can run an attacker's code
PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.
Your self-hosted Gogs server lets any logged-in user read repos that aren't theirs
A validation gap in Gogs Mirror Settings (CVE-2026-52801) lets any authenticated user import local repositories and reach internal systems. Patch to 0.14.3 now.
One rigged account-sync update can poison your whole app and forge an admin
CVE-2026-48170 lets one SCIM PATCH request poison Object.prototype across a Node.js app using scim-patch, risking admin forgery. Update to 0.9.1 now.
Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.
The US used export-control powers to pull a frontier AI model that finds software bugs at scale.
The app you're testing can hijack the AI agent testing it: Appium MCP's XSS flaw
An XSS flaw in Appium's official MCP server let a hostile test app hijack the AI agent driving it and call its tools. Patch appium-mcp to 1.85.10 now.
Mastra's npm packages passed inspection, then turned hostile a day later
Attackers hijacked a dormant maintainer account to poison 140+ Mastra npm packages with a wallet-stealing payload.
Your Salesforce wasn't breached. A connected app handed over the data.
The Icarus group stole Salesforce CRM data through Klue's connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.
JetBrains Plugins Are Stealing AI API Keys, and You Find Out From the Bill
Aikido found 15 JetBrains Marketplace plugins stealing AI API keys across 70,000 installs.
Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.
OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.