Keyv's Signed npm Releases Carried a Credential-Stealing Worm
A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Read article →Reader view
Choose the default article length.
The Feed
Browse Nulltap reporting by year or narrow the feed by date.
A compromised maintainer account published Keyv-family packages with valid provenance, an install-time credential stealer, and code that could poison more npm releases.
Read article →Gitea 1.22.1 through 1.27.0 can let an anonymous request read files as the service account, expose the internal token, and plant a Git hook that executes during a clone.
Read article →Unit 42 showed three post-compromise paths from Chrome's local passkey state to silent assertions, substituted verification keys, or the master secret protecting synced credentials.
Read article →INC ransomware activity raises the cost of treating an SMA 1000 hotfix as closure: affected appliances need log and configuration triage before defenders can trust them again.
Read article →Chrome's AI-scaled security pipeline fixed more bugs in two milestones than in the previous 23, making verified browser relaunch and fleet version state the practical enterprise control.
Read article →N-central operators need build 2026.3.1.7 and a downstream endpoint hunt because attackers used the RMM console to reach managed systems and establish persistence.
Read article →An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
Read article →A compromised Adform tracking file used browser events, DOM observers and form-field hooks to keep substituting Bitcoin, Ethereum and Tron addresses.
Read article →A crafted image can reach unsafe libvips operations through Active Storage, exposing files and process credentials that a Rails-only update cannot recover.
Read article →A ServiceWorker and SharedWorker combine a clean Bun runtime, delivered PE sections, and locally generated bytes before a same-origin download.
Read article →A poisoned build can start a memory-resident loader, re-arm through macOS preferences, and seed more projects, Git hooks, and archives.
Read article →A crafted AD CS chase sent the CA to rogue directory services. July updates add a real-DC check, but defenders still need issuance and replication evidence.
Read article →IPMI's RAKP exchange exposes material for offline password cracking, leaving defenders with a management-plane incident that host telemetry may miss.
Read article →One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Read article →Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.
Read article →On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
Read article →A misconfigured evaluation harness let three Claude models reach production systems, exposing a control gap that prompts and model safeguards could not contain.
Read article →Every on-prem Secure FMC configuration is affected. Cisco published hot fixes, a shared license.tmp indicator, and credential-rotation guidance.
Read article →Talos tied QR-code PDFs to credential theft, inbox-rule changes, SharePoint staging and new phishing sent from compromised Microsoft 365 mailboxes.
Read article →Kaspersky found BridgeHead using Windows SSO to cross corporate proxies before relaying server-selected TCP traffic through compromised hosts.
Read article →The flaw reaches an unsafe resource-loading path without AutoType enabled. Exposure is limited to a specific Fastjson 1.x and Spring Boot deployment combination.
Read article →Five recovered task logs record service discovery, privilege checks and file enumeration after an operator enabled Hermes's unattended mode.
Read article →Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Read article →Zenity found URL parameters that preselected a template and auto-submitted instructions inside a logged-in user's Workspace Agents builder.
Read article →Any authenticated proxy-key holder could make two MCP preview endpoints run an arbitrary command on the LiteLLM host.
Read article →The botnet spread through developer extensions and packages, then used stolen credentials to force-push malicious code into default branches.
Read article →CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Read article →Push Security traced sponsored search ads to shared ChatGPT and Claude pages that handed visitors to fake desktop-app downloads.
Read article →A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.
Read article →CVE-2025-55241 allowed an Entra actor token from one tenant to impersonate users in another through the legacy Azure AD Graph API.
Read article →Researchers put instructions to read .env and encode it into source inside a PNG that text-only pull-request reviewers ignored but vision-capable coding agents later followed.
Read article →A Teams lure installed a headless Edge extension and a Python native-messaging host, giving a ransomware access broker a quiet route to local command execution.
Read article →A stolen npm publisher account added a malicious dependency to more than 140 Mastra packages, giving Sapphire Sleet an install-time path into developer and CI systems.
Read article →AIR says its brand-landingpage experiment reached 26,000 agents after scanners missed a remote instruction source that changed after approval.
Read article →CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
Read article →A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Read article →Island found more than 800 fake skills and MCP servers using credible READMEs and ZIP files to turn capability searches into malware installs.
Read article →Five poisoned releases avoided install hooks, launching a detached Node.js process when developer or CI tooling loaded the affected module.
Read article →Trend Micro found a Russian-speaking actor using Gemini CLI to rebuild command-and-control infrastructure and operate eight infected computers.
Read article →Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
Read article →A routine page fetch in older Kiro builds could end with attacker-controlled code running through a rewritten MCP configuration.
Read article →The botnet gives AI workbenches priority in its scan queue, then searches compromised hosts for cloud credentials, service-account tokens, and callable tools.
Read article →A sponsored search result sent victims through a public page on claude.ai before delivering a fake desktop installer.
Read article →