OpenAPI Code Generator Worm Hijacks Trusted Publishing
Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
Reader edition
Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
CISA confirms exploitation of a critical Artifactory flaw and requires federal forensic triage. Self-hosted operators have six fixed-version floors to verify.
A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts support checks of routers, authentication servers, and Linux hosts.
CISA confirmed exploitation of a 2019 SQL Server flaw and now requires affected systems to be patched after evidence preservation and forensic triage.
PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Shadowserver's retrospective Dysphoria report identifies about 296,000 compromised IoT devices and gives network owners evidence to locate and rebuild affected systems.
Five newly fixed WordPress flaws expose conditional paths to admin takeover or server code execution; defenders should verify six component versions and review AJAX and account activity.
A double-read type confusion lets guest JavaScript corrupt host memory; upgrade isolated-vm 6.x to 6.2.0 or 7.x to 7.0.1.
CISA says attackers are exploiting a Linux IPv6 kernel flaw that can give a local user root and, on affected RHEL 10 systems, escape a container.
Citrix documents denial of service. Separate research demonstrates a SAML path to root code execution but has not confirmed that it maps to this CVE.
An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.