Coder Registry Hack Sent Credential-Stealing Code to Developers
Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →A public Telerik UI exploit chains two cryptographic oracles to unsafe type loading. Upgrade ASP.NET AJAX to 2026.2.708 and check IIS for post-exploit activity.
Read article →Ten malicious OpenAPI React Query Codegen releases ran on install and carried credential-stealing code with valid provenance. Teams must scope lockfiles, rebuild hosts and rotate credentials.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →StyleSmuggler turns poisoned Magento logs into server-side code execution, then hides a persistent implant outside the shop's webroot. Adobe has not issued a fix.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
Read article →CISA confirms exploitation of a critical Artifactory flaw and requires federal forensic triage. Self-hosted operators have six fixed-version floors to verify.
Read article →A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Read article →CISA confirmed exploitation of a 2019 SQL Server flaw and now requires affected systems to be patched after evidence preservation and forensic triage.
Read article →StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Five newly fixed WordPress flaws expose conditional paths to admin takeover or server code execution; defenders should verify six component versions and review AJAX and account activity.
Read article →A double-read type confusion lets guest JavaScript corrupt host memory; upgrade isolated-vm 6.x to 6.2.0 or 7.x to 7.0.1.
Read article →