<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CipherWatch — Software Development Security</title><description>Security intelligence covering Software Development Security: Secure SDLC, code review, application vulnerabilities, DevSecOps, and software security testing.</description><link>https://cipherwatch.io/</link><language>en-gb</language><item><title>Over 400 Arch Linux AUR Packages Poisoned with eBPF Rootkit in Coordinated Maintainer Compromise</title><link>https://cipherwatch.io/articles/2026-06-16-arch-linux-aur-400-packages-ebpf-rootkit-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-16-arch-linux-aur-400-packages-ebpf-rootkit-supply-chain/</guid><description>More than 400 packages in the Arch Linux User Repository were compromised by an attacker who spoofed trusted maintainer identities to push malicious preinstall scripts. The scripts deploy an ELF infostealer harvesting developer credentials and an optional eBPF rootkit that persists across package removal attempts.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>arch-linux</category><category>rootkit</category><category>ebpf</category><category>linux</category><category>developer-credentials</category></item><item><title>Miasma / Shai Hulud Supply Chain Campaign: 100+ npm and PyPI Packages Compromised Including Red Hat Namespace</title><link>https://cipherwatch.io/articles/2026-06-14-miasma-shai-hulud-npm-pypi-supply-chain-100-packages/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-14-miasma-shai-hulud-npm-pypi-supply-chain-100-packages/</guid><description>Security researchers have attributed a coordinated software supply chain attack to a threat cluster tracked as Miasma (also Shai Hulud), which compromised over 100 packages across npm and PyPI by stealing publisher credentials and injecting malicious code. The campaign reached the official Red Hat npm namespace, exposing organisations that rely on internal package mirror strategies as a security control.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>npm</category><category>pypi</category><category>miasma</category><category>shai-hulud</category><category>package-manager</category><category>credential-theft</category><category>red-hat</category><category>oss-security</category></item><item><title>The AI Infrastructure Security Deficit: Langflow, LiteLLM, and a Repeating Pattern</title><link>https://cipherwatch.io/articles/2026-06-12-ai-infrastructure-security-pattern-2026/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-12-ai-infrastructure-security-pattern-2026/</guid><description>Two AI infrastructure components — Langflow and LiteLLM — have reached the CISA Known Exploited Vulnerabilities catalogue in June 2026, both with command injection vulnerabilities in Python-based AI tooling. The pattern reflects a systemic gap: AI infrastructure is being deployed in enterprise environments under procurement and security processes designed for end-user applications, not for server-side infrastructure with network-accessible APIs.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>ai-infrastructure</category><category>langflow</category><category>litellm</category><category>cve-2026-5027</category><category>cve-2026-42271</category><category>command-injection</category><category>python</category><category>cisa-kev</category><category>developer-security</category><category>ai-security</category></item><item><title>Langflow CVE-2026-5027 Exploitation Accelerates: AI Workflow Builder&apos;s Path Traversal RCE Under Active Attack</title><link>https://cipherwatch.io/articles/2026-06-10-langflow-cve-2026-5027-exploitation-ai-workflow/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-10-langflow-cve-2026-5027-exploitation-ai-workflow/</guid><description>Exploitation of CVE-2026-5027 in Langflow, the AI workflow builder, has intensified following public PoC release. The path traversal remote code execution vulnerability, added to CISA&apos;s KEV on 8 June, is being used to deploy credential stealers and post-exploitation agents against organisations running unsecured Langflow instances. Upgrade to Langflow 1.3.5 immediately.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>langflow</category><category>cve-2026-5027</category><category>ai-infrastructure</category><category>rce</category><category>path-traversal</category><category>cisa-kev</category><category>actively-exploited</category><category>python</category><category>ai-workflow</category><category>llm</category></item><item><title>Veeam Backup &amp; Replication CVE-2026-44963 (CVSS 9.4): Domain Users Can Execute Remote Code on Backup Infrastructure</title><link>https://cipherwatch.io/articles/2026-06-10-veeam-backup-replication-cve-2026-44963-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-10-veeam-backup-replication-cve-2026-44963-rce/</guid><description>Veeam has patched CVE-2026-44963, a CVSS 9.4 remote code execution vulnerability in Veeam Backup &amp; Replication that allows any domain user to execute arbitrary code on the Veeam backup server. The vulnerability exploits insufficient authorisation in the Veeam Backup Service API. Organisations using Veeam in Active Directory environments should apply the patch immediately.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>veeam</category><category>backup</category><category>cve-2026-44963</category><category>rce</category><category>domain-users</category><category>active-directory</category><category>ransomware</category><category>backup-security</category><category>cvss-9-4</category></item><item><title>CVE-2026-42271: BerriAI LiteLLM Command Injection Reaches CISA KEV — AI Infrastructure Under Attack</title><link>https://cipherwatch.io/articles/2026-06-08-litellm-cve-2026-42271-ai-infrastructure-cisa-kev/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-08-litellm-cve-2026-42271-ai-infrastructure-cisa-kev/</guid><description>CISA added CVE-2026-42271 in BerriAI LiteLLM to the Known Exploited Vulnerabilities catalogue on 8 June, confirming active exploitation of a command injection vulnerability that allows API keys with limited privileges to execute arbitrary commands on the LiteLLM host. Organisations running LiteLLM as an AI gateway should update to v1.83.7-stable immediately.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>litellm</category><category>cve-2026-42271</category><category>ai-infrastructure</category><category>command-injection</category><category>cisa-kev</category><category>api-security</category><category>llm-gateway</category><category>actively-exploited</category></item><item><title>VS Code Adds Two-Hour Extension Auto-Update Delay to Reduce Supply Chain Attack Window</title><link>https://cipherwatch.io/articles/2026-06-08-vscode-extension-2hr-update-delay-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-08-vscode-extension-2hr-update-delay-supply-chain/</guid><description>Microsoft has released VS Code 1.101 with a configurable two-hour delay on automatic extension updates. The change is a direct response to supply chain attacks in which malicious updates were pushed to popular extensions, executing on developer machines within minutes of publication. The delay gives security teams a detection window before malicious updates execute across the developer fleet.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><category>vscode</category><category>supply-chain</category><category>extension-security</category><category>developer-tools</category><category>microsoft</category><category>update-delay</category><category>ci-cd</category><category>devops-security</category></item><item><title>Magento Extension Supply Chain Risk: CVE-2026-45247 and the Third-Party Plugin Attack Surface</title><link>https://cipherwatch.io/articles/2026-06-04-magento-php-extension-supply-chain-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-04-magento-php-extension-supply-chain-risk/</guid><description>CVE-2026-45247 in the Mirasvit Full Page Cache Warmer illustrates a structural security problem in the Magento ecosystem: eCommerce site security is determined not just by the core platform version, but by every third-party extension installed. This guide covers how to assess and reduce the Magento extension attack surface.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>magento</category><category>php</category><category>supply-chain</category><category>cve-2026-45247</category><category>extension-security</category><category>ecommerce</category><category>dependency-management</category><category>deserialization</category></item><item><title>CVE-2026-45247: CISA Adds Mirasvit Magento Cache Warmer RCE to KEV — Unauthenticated PHP Deserialization Exploited in Wild</title><link>https://cipherwatch.io/articles/2026-06-03-mirasvit-magento-cve-2026-45247-rce-cisa-kev/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-03-mirasvit-magento-cve-2026-45247-rce-cisa-kev/</guid><description>CISA added CVE-2026-45247 to the Known Exploited Vulnerabilities catalogue on 3 June, confirming active exploitation of a CVSS 9.8 PHP deserialization vulnerability in the Mirasvit Full Page Cache Warmer extension for Magento 2. Attackers exploit a malicious serialised cookie value to execute arbitrary code without authentication. The patch has been available since 25 May; organisations running Mirasvit FPC Warmer must update immediately.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>magento</category><category>mirasvit</category><category>cve-2026-45247</category><category>php-deserialization</category><category>rce</category><category>cisa-kev</category><category>ecommerce</category><category>actively-exploited</category></item><item><title>ServiceNow API Security Configuration: Access Controls, ACLs, and Endpoint Hardening to Prevent Zero-Auth Exposure</title><link>https://cipherwatch.io/articles/2026-06-02-servicenow-api-security-configuration-access-controls/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-02-servicenow-api-security-configuration-access-controls/</guid><description>The ServiceNow API breach highlights the risk of zero-auth API endpoint exposure in SaaS ITSM platforms. ServiceNow&apos;s platform provides granular access control mechanisms — ACLs, application scope policies, and API gateway controls — that, if properly configured, limit the blast radius of similar incidents. This guide covers the core security configuration for ServiceNow REST APIs.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>servicenow</category><category>api-security</category><category>access-control</category><category>acl</category><category>itsm</category><category>saas-security</category><category>configuration</category><category>hardening</category></item><item><title>CISA Adds Three Developer Toolchain Supply-Chain Attacks to KEV — DAEMON Tools, TanStack Query, Nx Console Compromised</title><link>https://cipherwatch.io/articles/2026-05-27-cisa-kev-daemon-tools-tanstack-nx-console-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-27-cisa-kev-daemon-tools-tanstack-nx-console-supply-chain/</guid><description>CISA added three software supply-chain vulnerabilities to the Known Exploited Vulnerabilities catalogue on 27 May: CVE-2026-8398 (DAEMON Tools signed installer trojanised), CVE-2026-45321 (TanStack Query malicious npm package), and CVE-2026-48027 (Nx Console VS Marketplace extension backdoored). All three are attributed to TeamPCP&apos;s &apos;Mini Shai-Hulud&apos; campaign targeting developer workstations.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>supply-chain</category><category>teampcp</category><category>daemon-tools</category><category>tanstack</category><category>nx-console</category><category>developer-toolchain</category><category>npm</category><category>vs-marketplace</category></item><item><title>TeamPCP &apos;Mini Shai-Hulud&apos;: Inside the Developer Toolchain Attack Campaign Now on CISA KEV</title><link>https://cipherwatch.io/articles/2026-05-27-teampcp-mini-shai-hulud-developer-toolchain-campaign/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-27-teampcp-mini-shai-hulud-developer-toolchain-campaign/</guid><description>TeamPCP&apos;s simultaneous compromise of three developer toolchain components — a code-signed installer, an npm package, and a VS Code extension — follows a refined methodology the group has been developing across multiple 2026 campaigns. The technical approach explains why these attacks reach environments that are otherwise well-defended.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>teampcp</category><category>supply-chain</category><category>developer-security</category><category>npm</category><category>vs-code</category><category>signed-installer</category><category>credential-theft</category><category>dprk</category></item><item><title>WishList Member WordPress Plugin: Four CVSS 8.8 Vulnerabilities Enable Subscriber-to-Admin Escalation on 100,000+ Sites</title><link>https://cipherwatch.io/articles/2026-05-23-wishlist-member-wordpress-four-cvss88-privilege-escalation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-23-wishlist-member-wordpress-four-cvss88-privilege-escalation/</guid><description>Wordfence published advisories for four CVSS 8.8 authorization failure vulnerabilities in WishList Member, a WordPress membership plugin with 100,000+ active installs, on 23 May 2026. Subscriber-level authenticated attackers can exploit the flaws to escalate to administrator access, read sensitive member data, and modify arbitrary site content. Patches are available.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>wishlist-member</category><category>membership-plugin</category><category>privilege-escalation</category><category>cve-2026-6419</category><category>cve-2026-6895</category><category>authorization-failure</category></item><item><title>Golang crypto/ssh Mass Advisory: Nine CVEs Including CVSS 10.0 Re-Opened SSH Auth Bypass Affect Enterprise DevOps Infrastructure</title><link>https://cipherwatch.io/articles/2026-05-22-golang-crypto-ssh-mass-advisory-cvss10-auth-bypass/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-22-golang-crypto-ssh-mass-advisory-cvss10-auth-bypass/</guid><description>The Go security team published a coordinated batch of nine CVE fixes for the golang.org/x/crypto SSH library on 22 May, including CVE-2026-46595 (CVSS 10.0), which re-opens a previously patched SSH authentication bypass for services using non-public-key authentication callbacks. Enterprise environments using Go-based SSH tooling, CI/CD pipelines, Kubernetes components, and cloud management tooling are affected.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>golang</category><category>go</category><category>ssh</category><category>cryptography</category><category>cve-2026-46595</category><category>supply-chain</category><category>devops</category><category>kubernetes</category><category>cicd</category></item><item><title>SketchUp CVE-2026-9264: Malicious SKP File Delivers RCE via Embedded IE11 Browser — CVSS 9.3</title><link>https://cipherwatch.io/articles/2026-05-22-sketchup-cve-2026-9264-malicious-skp-rce-ie11/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-22-sketchup-cve-2026-9264-malicious-skp-rce-ie11/</guid><description>Trimble disclosed CVE-2026-9264, a CVSS 9.3 remote code execution vulnerability in SketchUp 2026, on 22 May. An attacker who convinces a user to open a crafted .skp file can achieve code execution and local file exfiltration via XSS in SketchUp&apos;s Dynamic Components feature, which renders HTML content using an embedded IE11 browser with full local file system access.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>sketchup</category><category>cve-2026-9264</category><category>rce</category><category>ie11</category><category>xss</category><category>cad</category><category>architecture</category><category>engineering</category></item><item><title>ChromaDB CVSS 10.0 Pre-Auth RCE CVE-2026-45829: AI Vector Database Compromise via HuggingFace Model Injection</title><link>https://cipherwatch.io/articles/2026-05-20-chromadb-cve-2026-45829-cvss10-pre-auth-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-20-chromadb-cve-2026-45829-cvss10-pre-auth-rce/</guid><description>HiddenLayer and the Cloud Security Alliance published disclosures of CVE-2026-45829, a CVSS 10.0 unauthenticated remote code execution vulnerability in ChromaDB&apos;s Python FastAPI server, on 18–20 May 2026. Attackers can inject malicious code via a crafted HuggingFace-hosted model before the authentication gate fires. Approximately 73% of ChromaDB deployments are internet-exposed. No patch exists for affected versions.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>chromadb</category><category>vector-database</category><category>ai-security</category><category>cve-2026-45829</category><category>rce</category><category>huggingface</category><category>rag-pipeline</category><category>llm-security</category></item><item><title>Drupal SA-CORE-2026-004: Highly Critical SQL Injection CVE-2026-9082 — PostgreSQL Sites Must Patch Immediately</title><link>https://cipherwatch.io/articles/2026-05-20-drupal-sa-core-2026-004-sql-injection-cve-2026-9082/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-20-drupal-sa-core-2026-004-sql-injection-cve-2026-9082/</guid><description>Drupal published SA-CORE-2026-004 on 20 May, disclosing CVE-2026-9082, a highly critical unauthenticated SQL injection vulnerability in Drupal&apos;s database abstraction API affecting sites running PostgreSQL. The flaw is zero-click and unauthenticated, and Drupal warned that exploit code turnaround would be measured in hours. CISA added the CVE to the Known Exploited Vulnerabilities catalogue on 22 May after confirmed exploitation.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>drupal</category><category>cms</category><category>sql-injection</category><category>cve-2026-9082</category><category>postgresql</category><category>web-security</category><category>critical-patch</category></item><item><title>AI Coding Agents in CI/CD Pipelines: Mapping the Attack Surface After Pwn2Own AI Category Results</title><link>https://cipherwatch.io/articles/2026-05-18-ai-agent-cicd-pipeline-access-attack-surface/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-18-ai-agent-cicd-pipeline-access-attack-surface/</guid><description>The Pwn2Own Berlin 2026 AI category results — five products exploited — have a compounding implication for organisations where AI coding agents are integrated with CI/CD pipelines, code repositories, and cloud deployment infrastructure. An exploited AI agent running in a pipeline is not a developer workstation compromise; it is a supply chain entry point.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>cicd</category><category>supply-chain</category><category>developer-tools</category><category>pipeline-security</category><category>github-actions</category><category>devsecops</category></item><item><title>AI Coding Environments Join Pwn2Own Target List: LM Studio and OpenAI Codex Exploited via Sandbox Escapes</title><link>https://cipherwatch.io/articles/2026-05-16-ai-coding-environments-pwn2own-lm-studio-codex-exploited/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-16-ai-coding-environments-pwn2own-lm-studio-codex-exploited/</guid><description>Pwn2Own Berlin 2026 introduced an AI products category and saw both LM Studio and OpenAI Codex exploited on the same day through sandbox escapes and environment variable injection. The results raise urgent questions about the security of AI development tools running inside enterprise environments with access to code repositories, credentials, and production pipelines.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>pwn2own</category><category>sandbox-escape</category><category>lm-studio</category><category>openai-codex</category><category>developer-tools</category><category>supply-chain</category></item><item><title>Burst Statistics WordPress Plugin Authentication Bypass Actively Exploited for Mass Site Takeovers</title><link>https://cipherwatch.io/articles/2026-05-14-burst-statistics-wordpress-auth-bypass-exploitation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-14-burst-statistics-wordpress-auth-bypass-exploitation/</guid><description>Threat actors are actively exploiting an authentication bypass vulnerability in the Burst Statistics WordPress analytics plugin, allowing unauthenticated attackers to gain administrative access to any WordPress site with the plugin installed. Over 100,000 WordPress sites use Burst Statistics. Sites have been observed being defaced, backdoored, and redirected to malicious domains within hours of exploitation.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>authentication-bypass</category><category>burst-statistics</category><category>cms</category><category>mass-exploitation</category></item><item><title>OpenAI Confirms Developer Devices Breached via TanStack Supply Chain Attack — Code-Signing Certificates Rotated</title><link>https://cipherwatch.io/articles/2026-05-14-openai-tanstack-supply-chain-breach-certs-rotated/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-14-openai-tanstack-supply-chain-breach-certs-rotated/</guid><description>OpenAI confirmed that two developer devices were compromised as a result of the TanStack npm supply chain attack disclosed on 12 May, with malicious postinstall hooks executing on machines running npm install within the six-minute poisoning window. OpenAI rotated all affected code-signing certificates and npm tokens and is investigating whether any internal packages published using the compromised credentials were delivered downstream.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>openai</category><category>tanstack</category><category>supply-chain</category><category>code-signing</category><category>credential-theft</category></item><item><title>Apple Releases Safari and WebKit Security Update Patching Memory Corruption and CSP Bypass Vulnerabilities</title><link>https://cipherwatch.io/articles/2026-05-13-apple-webkit-safari-security-update-csp-bypass/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-13-apple-webkit-safari-security-update-csp-bypass/</guid><description>Apple released a security update for Safari and WebKit on 13 May addressing more than ten vulnerabilities including memory corruption flaws enabling potential arbitrary code execution and a Content Security Policy bypass allowing cross-origin data access. The update applies to macOS Ventura, Sonoma, Sequoia, iOS, and iPadOS. Users should update immediately given WebKit&apos;s role as the rendering engine for all iOS browsers.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>apple</category><category>webkit</category><category>safari</category><category>csp-bypass</category><category>memory-corruption</category></item><item><title>TanStack npm Supply Chain Attack: GitHub Actions OIDC Token Hijack Used to Publish 84 Malicious Package Versions</title><link>https://cipherwatch.io/articles/2026-05-12-tanstack-npm-oidc-hijack-supply-chain-attack/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-12-tanstack-npm-oidc-hijack-supply-chain-attack/</guid><description>Attackers exploited a GitHub Actions misconfiguration in the TanStack project to publish 84 malicious versions of popular React ecosystem packages to the npm registry. The attack chained a Pwn Request misconfiguration, workflow cache poisoning, and runtime OIDC token theft to operate under TanStack&apos;s trusted publisher identity.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>npm</category><category>github-actions</category><category>oidc</category><category>tanstack</category></item><item><title>pnpm 11 Defaults to 24-Hour Package Age Minimum — Blocking Automated Post-Publish Supply Chain Attacks</title><link>https://cipherwatch.io/articles/2026-05-10-pnpm-v11-package-age-quarantine-supply-chain-defence/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-10-pnpm-v11-package-age-quarantine-supply-chain-defence/</guid><description>pnpm 11, released this week, introduces a package quarantine feature that by default blocks installation of any npm package published within the past 24 hours. The control targets the automated post-publish compromise pattern used by TeamPCP, CanisterSprawl, and similar supply chain threat actors who publish malicious package versions and immediately trigger mass installation before defenders can respond. It is the most substantive supply-chain-defensive default configuration added to a package manager since npm&apos;s provenance attestation.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><category>pnpm</category><category>npm</category><category>supply-chain</category><category>package-manager</category><category>developer-security</category><category>open-source</category><category>dependency-management</category><category>security-defaults</category></item><item><title>Fake OpenAI Repository on Hugging Face Reached #1 Trending, Delivered Rust Infostealer to 244,000 Users</title><link>https://cipherwatch.io/articles/2026-05-09-fake-openai-huggingface-repo-rust-infostealer-244k/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-09-fake-openai-huggingface-repo-rust-infostealer-244k/</guid><description>A malicious repository impersonating an official OpenAI project reached the top trending position on Hugging Face before being removed — delivering a Rust-compiled infostealer to an estimated 244,000 users who executed the repository&apos;s loader script. The attack exploited Hugging Face&apos;s trending algorithm and the high trust developers place in repositories attributed to the OpenAI organisation. Affected users should rotate all credentials accessible from the compromised machine.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><category>hugging-face</category><category>supply-chain</category><category>openai-impersonation</category><category>infostealer</category><category>rust-malware</category><category>ai-security</category><category>developer-security</category><category>credential-theft</category></item><item><title>JDownloader Official Download Site Hijacked to Serve Python RAT in Supply Chain Attack</title><link>https://cipherwatch.io/articles/2026-05-08-jdownloader-site-hijacked-python-rat-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-08-jdownloader-site-hijacked-python-rat-supply-chain/</guid><description>The official JDownloader download site was compromised during a window of approximately 18 hours between 6 and 7 May 2026, with legitimate installer downloads replaced by a trojanised package delivering a Python-based remote access trojan. JDownloader is a popular open-source download manager with millions of users. Users who installed JDownloader during the compromise window should treat their system as compromised and perform immediate credential rotation and system remediation.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>jdownloader</category><category>malware</category><category>python-rat</category><category>download-hijacking</category><category>installer-compromise</category><category>credential-theft</category></item><item><title>QLNX Linux RAT Harvests Developer Credentials to Enable Malicious Package Publishing on npm and PyPI</title><link>https://cipherwatch.io/articles/2026-05-08-qlnx-linux-rat-devops-credential-theft-npm-pypi/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-08-qlnx-linux-rat-devops-credential-theft-npm-pypi/</guid><description>Trend Micro researchers have identified QLNX (Quasar Linux), a Linux-targeting remote access trojan specifically designed to harvest developer credentials — npm tokens, PyPI upload credentials, AWS IAM keys, Docker registry credentials, and GitHub CLI tokens — from developer workstations. The harvested credentials are then used to publish malicious packages to npm and PyPI under the compromised developer&apos;s identity, enabling second-stage supply chain attacks against the developer&apos;s downstream users.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>linux</category><category>developer-security</category><category>npm</category><category>pypi</category><category>credential-theft</category><category>rat</category><category>devops</category><category>package-registry</category></item><item><title>LiteLLM CVE-2026-42208 — SQL Injection in AI Gateway Proxy Added to CISA KEV</title><link>https://cipherwatch.io/articles/2026-05-07-litellm-cve-2026-42208-sql-injection-cisa-kev/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-07-litellm-cve-2026-42208-sql-injection-cisa-kev/</guid><description>CVE-2026-42208, a SQL injection vulnerability in the LiteLLM AI gateway proxy, has been added to the CISA Known Exploited Vulnerabilities catalogue following confirmed exploitation. LiteLLM is widely deployed in enterprise environments as a unified API layer routing requests to multiple LLM providers (OpenAI, Anthropic, Azure OpenAI, Bedrock). Exploitation allows an attacker to read and modify the LiteLLM database, including API keys, user records, and model configuration. Update to LiteLLM 1.42.2 immediately.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>litellm</category><category>ai-infrastructure</category><category>sql-injection</category><category>cve</category><category>cisa-kev</category><category>llm</category><category>ai-gateway</category><category>enterprise-ai</category><category>api-security</category></item><item><title>vm2 Node.js Sandbox Escape CVE-2026-26956 — 1.3 Million Weekly Downloads, PoC Published</title><link>https://cipherwatch.io/articles/2026-05-06-vm2-nodejs-sandbox-escape-cve-2026-26956/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-06-vm2-nodejs-sandbox-escape-cve-2026-26956/</guid><description>A critical sandbox escape vulnerability in the vm2 Node.js sandboxing library allows a malicious script to break out of the sandbox and execute arbitrary code in the host Node.js process. CVE-2026-26956 affects all vm2 versions prior to 3.9.22 and is present in any application using vm2 to safely execute untrusted code — including serverless platforms, coding challenge sites, CI/CD systems, and plugin architectures. A PoC is publicly available.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>nodejs</category><category>vm2</category><category>sandbox-escape</category><category>cve</category><category>javascript</category><category>supply-chain</category><category>serverless</category><category>code-execution</category></item><item><title>108 Malicious Chrome Extensions Exfiltrating Browser Data Removed from Web Store</title><link>https://cipherwatch.io/articles/2026-05-04-108-malicious-chrome-extensions-data-theft/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-04-108-malicious-chrome-extensions-data-theft/</guid><description>Google has removed 108 extensions from the Chrome Web Store after researchers identified a coordinated malicious extension campaign conducting browser credential harvesting, session cookie theft, and clipboard monitoring across millions of installations. The extensions impersonated productivity tools, ad blockers, and security tools — with some active for over 18 months before detection. Enterprise Chrome deployments should audit installed extensions against the published IOC list.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>chrome-extensions</category><category>browser-security</category><category>data-theft</category><category>credential-harvesting</category><category>google</category><category>supply-chain</category><category>enterprise-browsers</category></item><item><title>PyTorch Lightning PyPI Package Compromised — Credential-Stealing Payload Delivered to AI/ML Development Environments</title><link>https://cipherwatch.io/articles/2026-05-02-pytorch-lightning-pypi-supply-chain-compromise/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-02-pytorch-lightning-pypi-supply-chain-compromise/</guid><description>PyTorch Lightning versions 2.6.2 and 2.6.3 on PyPI were found to contain a credential-stealing postinstall payload, extending the Mini Shai-Hulud supply chain campaign that previously compromised SAP&apos;s official npm packages. Organisations running AI/ML workloads should audit Python environments and rotate any credentials stored on affected development or CI/CD systems.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>pypi</category><category>pytorch</category><category>ai-ml</category><category>credential-theft</category><category>developer-security</category><category>mini-shai-hulud</category></item><item><title>GitHub Enterprise Server CVE-2026-3854 — Critical RCE via Single Git Push, No Authentication Required</title><link>https://cipherwatch.io/articles/2026-05-01-github-enterprise-server-cve-2026-3854-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-01-github-enterprise-server-cve-2026-3854-rce/</guid><description>CVE-2026-3854, a critical-severity remote code execution vulnerability in GitHub Enterprise Server, allows an attacker to execute arbitrary code on the server with a single specially crafted Git push, requiring no authentication. Any internet-exposed or internally-accessible GHES instance is vulnerable. GitHub has released hotfixes across all supported branches; apply immediately.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>github-enterprise</category><category>cve-2026-3854</category><category>rce</category><category>git</category><category>devops-security</category><category>source-code-security</category><category>ci-cd</category></item><item><title>Jenkins GitHub Plugin CVE-2026-42523 — CVSS 9.0 Stored XSS Enables Pipeline Hijacking and Secret Extraction</title><link>https://cipherwatch.io/articles/2026-04-30-jenkins-github-plugin-cve-2026-42523-stored-xss/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-30-jenkins-github-plugin-cve-2026-42523-stored-xss/</guid><description>CVE-2026-42523, rated CVSS 9.0, is a stored cross-site scripting vulnerability in the Jenkins GitHub Plugin 1.46.0 and earlier. Exploitation allows an attacker with job creation rights to inject malicious JavaScript that executes in the browser of any Jenkins administrator who views the affected job — enabling session hijacking, secret extraction, and full pipeline takeover. Update to GitHub Plugin 1.46.1 or later.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>jenkins</category><category>github-plugin</category><category>cve-2026-42523</category><category>xss</category><category>ci-cd</category><category>pipeline-security</category><category>devops-security</category></item><item><title>Official SAP npm Packages Compromised to Steal Enterprise Developer Credentials</title><link>https://cipherwatch.io/articles/2026-04-30-sap-npm-supply-chain-credential-theft/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-30-sap-npm-supply-chain-credential-theft/</guid><description>Threat actors compromised official SAP npm packages to insert credential-harvesting code targeting enterprise developers working on SAP integration projects. The malicious packages exfiltrate environment variables, SSH keys, and cloud credentials from developer workstations. Enterprise teams using SAP npm packages in their CI/CD pipelines should audit package integrity and rotate potentially exposed credentials.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>sap</category><category>npm</category><category>supply-chain</category><category>credential-theft</category><category>developer-security</category><category>package-manager</category></item><item><title>Apache Thrift 0.23.0 Patches Out-of-Bounds Read (CVE-2026-41604) and Node.js Uncontrolled Recursion DoS (CVE-2026-41636)</title><link>https://cipherwatch.io/articles/2026-04-29-apache-thrift-cve-2026-41604-41636-oob-read-nodejs-dos/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-29-apache-thrift-cve-2026-41604-41636-oob-read-nodejs-dos/</guid><description>Apache Thrift 0.23.0 addresses two vulnerabilities: CVE-2026-41604, an out-of-bounds read in the binary protocol parser affecting all language bindings that can crash Thrift-based services and potentially leak memory contents; and CVE-2026-41636, an uncontrolled recursion flaw in the Node.js library that enables remote denial of service via deeply nested Thrift structures. Organisations operating Thrift-based microservices or inter-service RPC should upgrade to 0.23.0.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>apache-thrift</category><category>rpc</category><category>cve-2026-41604</category><category>cve-2026-41636</category><category>out-of-bounds</category><category>denial-of-service</category><category>nodejs</category><category>microservices</category></item><item><title>Spring AI CVE-2026-40978 and CVE-2026-40967 — SQL Injection and Filter Expression Injection in RAG Vector Store Components</title><link>https://cipherwatch.io/articles/2026-04-29-spring-ai-cve-2026-40978-40967-cosmosdb-sql-injection/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-29-spring-ai-cve-2026-40978-40967-cosmosdb-sql-injection/</guid><description>Two injection vulnerabilities in Spring AI&apos;s vector store integration layer affect AI applications using retrieval-augmented generation pipelines. CVE-2026-40978 (CVSS 8.8) allows SQL injection through the CosmosDB vector store component; CVE-2026-40967 (CVSS 8.6) enables filter expression injection in the FilterExpressionConverter used across multiple backends. Both flaws affect Spring AI 1.0.x and 1.1.x and are patched in 1.1.5.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>spring-ai</category><category>sql-injection</category><category>rag</category><category>vector-store</category><category>cve-2026-40978</category><category>cve-2026-40967</category><category>ai-security</category><category>java</category></item><item><title>Spring Boot 4.0 CVE-2026-40976 — Default Security Misconfiguration Exposes All Actuator Endpoints Unauthenticated</title><link>https://cipherwatch.io/articles/2026-04-29-spring-boot-cve-2026-40976-actuator-auth-bypass/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-29-spring-boot-cve-2026-40976-actuator-auth-bypass/</guid><description>CVE-2026-40976 in Spring Boot 4.0.0 through 4.0.5 allows unauthenticated network access to all Spring Boot Actuator management endpoints when applications rely on the default Spring Security auto-configuration but omit the spring-boot-health dependency. Exposed endpoints include heapdump, env, mappings, and loggers — enough to extract secrets and manipulate application behaviour. Upgrade to Spring Boot 4.0.6 or later.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>spring-boot</category><category>actuator</category><category>cve-2026-40976</category><category>auth-bypass</category><category>java</category><category>enterprise-framework</category></item><item><title>Hugging Face LeRobot CVE-2026-25874 — Critical Unpatched RCE via Pickle Deserialization in Unauthenticated gRPC Endpoint</title><link>https://cipherwatch.io/articles/2026-04-28-hugging-face-lerobot-cve-2026-25874-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-28-hugging-face-lerobot-cve-2026-25874-rce/</guid><description>A critical unpatched remote code execution vulnerability in Hugging Face&apos;s LeRobot robotics AI framework allows unauthenticated attackers to execute arbitrary code on any server running the gRPC control interface. CVE-2026-25874, rated CVSS 9.3, affects the project&apos;s dataset loading and remote control pipeline via Python pickle deserialization. No patch is available; mitigations focus on network isolation.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>hugging-face</category><category>lerobot</category><category>cve-2026-25874</category><category>pickle-deserialization</category><category>rce</category><category>ai-security</category><category>unpatched</category></item><item><title>SAP April 2026 Patch Day: CVE-2026-34256 ABAP Code-Overwrite Lets Authenticated Attacker Sabotage Core ERP Functions</title><link>https://cipherwatch.io/articles/2026-04-27-sap-april-2026-patch-day-cve-2026-34256-abap/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-27-sap-april-2026-patch-day-cve-2026-34256-abap/</guid><description>SAP&apos;s April 2026 Security Patch Day includes a fix for CVE-2026-34256, an ABAP code-overwrite vulnerability rated CVSS 7.1 that allows an authenticated attacker with low-privilege access to modify executable ABAP programme objects, potentially corrupting core business logic in SAP ERP, S/4HANA, and BW systems. The flaw requires no special administrative roles and affects all SAP NetWeaver ABAP Server releases through the current patched version.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>sap</category><category>abap</category><category>cve-2026-34256</category><category>erp</category><category>code-integrity</category><category>april-patch-day</category></item><item><title>DPRK&apos;s Sapphire Sleet Backdoors Axios npm Package: 100 Million Weekly Downloads at Risk</title><link>https://cipherwatch.io/articles/2026-04-26-axios-npm-supply-chain-sapphire-sleet-dprk-cisa/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-26-axios-npm-supply-chain-sapphire-sleet-dprk-cisa/</guid><description>North Korea&apos;s Sapphire Sleet compromised an axios npm maintainer account on March 31, publishing backdoored versions 1.14.1 and 0.30.4 that delivered a cross-platform RAT during a three-hour exposure window. Axios has approximately 100 million weekly downloads. CISA issued Advisory AA26-110A on April 20 — organisations that ran npm installs during the window should treat their CI/CD pipeline as compromised and rotate all secrets immediately.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>npm</category><category>dprk</category><category>sapphire-sleet</category><category>rat</category><category>cisa-advisory</category><category>actively-exploited</category></item><item><title>CanisterSprawl: Self-Propagating npm Worm Steals Developer Credentials and Re-Infects Package Ecosystems</title><link>https://cipherwatch.io/articles/2026-04-26-canistersprawl-self-propagating-npm-worm/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-26-canistersprawl-self-propagating-npm-worm/</guid><description>Researchers discovered CanisterSprawl, a self-propagating npm supply chain worm attributed to TeamPCP that compromised at least 16 packages including pgserve and @automagik/genie. A postinstall hook harvests npm tokens, cloud credentials, SSH keys, and AI tool configs, exfiltrating to a blockchain canister before using stolen tokens to inject the worm into every other package owned by the compromised developer. Organisations should audit postinstall scripts and rotate all credentials from affected development environments.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>npm</category><category>worm</category><category>teamPCP</category><category>credential-theft</category><category>developer-security</category><category>blockchain-exfiltration</category></item><item><title>LMDeploy RCE Vulnerability CVE-2026-33626 Weaponised in the Wild 13 Hours After Disclosure</title><link>https://cipherwatch.io/articles/2026-04-25-lmdeploy-cve-2026-33626-rce-exploited-13-hours/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-25-lmdeploy-cve-2026-33626-rce-exploited-13-hours/</guid><description>A critical remote code execution flaw in LMDeploy, a widely used LLM inference serving framework, was exploited in active attacks just 13 hours after public disclosure. Organisations running self-hosted AI inference infrastructure must treat these platforms with the same urgency as any internet-exposed web application server — because attackers already do.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>lmdeploy</category><category>llm-infrastructure</category><category>rce</category><category>actively-exploited</category><category>deserialization</category></item><item><title>KTransformers AI Inference Framework Exposes Unauthenticated RCE via Pickle Deserialization — CVSS 9.8</title><link>https://cipherwatch.io/articles/2026-04-24-ktransformers-ai-framework-unauthenticated-rce-cve-2026-26210/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-24-ktransformers-ai-framework-unauthenticated-rce-cve-2026-26210/</guid><description>CVE-2026-26210 is a CVSS 9.8 pre-authentication RCE in KTransformers, a popular AI inference acceleration framework. The scheduler&apos;s ZMQ ROUTER socket binds to all interfaces with no authentication and deserialises arbitrary pickle payloads — any network-reachable host can execute code on the inference server.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>rce</category><category>deserialization</category><category>python</category><category>open-source</category></item><item><title>TeamPCP Supply Chain Campaign Expands to npm and Docker Hub — Bitwarden CLI and Checkmarx KICS Both Backdoored</title><link>https://cipherwatch.io/articles/2026-04-24-teampcp-supply-chain-bitwarden-cli-checkmarx-kics-npm-docker/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-24-teampcp-supply-chain-bitwarden-cli-checkmarx-kics-npm-docker/</guid><description>The TeamPCP supply chain threat group has extended its campaign beyond GitHub Actions and PyPI to poison the @bitwarden/cli npm package and overwrite Checkmarx KICS Docker images and VS Code extensions. The campaign now spans four developer distribution channels across six weeks, deploying a self-propagating worm that exfiltrates SSH keys, cloud credentials, and MCP configuration files from compromised developer environments.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>npm</category><category>docker</category><category>vscode</category><category>bitwarden</category><category>checkmarx</category><category>teampcp</category><category>credential-theft</category></item><item><title>Marimo AI Notebook RCE CVE-2026-39987 Exploited at Scale — 662 Events in Three Days, NKAbuse Malware Deployed</title><link>https://cipherwatch.io/articles/2026-04-23-marimo-rce-cve-2026-39987-mass-exploitation-nkabuse/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-23-marimo-rce-cve-2026-39987-mass-exploitation-nkabuse/</guid><description>CVE-2026-39987 (CVSS 9.3) in the Marimo Python notebook has been weaponised at scale, with Sysdig recording 662 exploitation events over three days and attackers completing credential theft within minutes of gaining access. The unauthenticated WebSocket RCE is being used to deploy NKAbuse, a multi-platform malware using the NKN peer-to-peer network for command and control. Upgrade to Marimo 0.23.0 immediately.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>rce</category><category>cve-2026-39987</category><category>marimo</category><category>python-notebook</category><category>nkabuse</category><category>active-exploitation</category></item><item><title>Microsoft Issues Emergency Patch for ASP.NET Core DataProtection Key Exposure — CVE-2026-40372</title><link>https://cipherwatch.io/articles/2026-04-22-aspnet-core-dataprotection-cve-2026-40372/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-22-aspnet-core-dataprotection-cve-2026-40372/</guid><description>A critical security regression in Microsoft.AspNetCore.DataProtection (CVSS 9.1) introduced in .NET 10.0.0 causes encryption keys to leak on Linux deployments. Applications using cookie authentication, anti-forgery tokens, or TempData are at immediate risk. Update to .NET 10.0.7 now.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>asp-net-core</category><category>microsoft</category><category>cve-2026-40372</category><category>out-of-band-patch</category><category>dotnet</category><category>key-exposure</category></item><item><title>Cohere Terrarium AI Sandbox Escape — CVSS 9.3 WebAssembly Flaw Allows Root Code Execution on Host</title><link>https://cipherwatch.io/articles/2026-04-22-cohere-terrarium-sandbox-escape-cve-2026-5752/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-22-cohere-terrarium-sandbox-escape-cve-2026-5752/</guid><description>CVE-2026-5752 (CVSS 9.3) in Cohere Terrarium allows an attacker to escape the Pyodide WebAssembly sandbox via JavaScript prototype chain traversal, achieving root code execution on the host Node.js process. Organisations running AI code execution environments should patch immediately and network-isolate these workloads.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>sandbox-escape</category><category>webassembly</category><category>cve-2026-5752</category><category>cohere</category><category>llm-security</category><category>prototype-chain</category></item><item><title>Google Antigravity AI Coding Assistant Had Two Chained Vulnerabilities — Prompt Injection to RCE and Reinstall-Surviving Backdoor</title><link>https://cipherwatch.io/articles/2026-04-22-google-antigravity-ide-prompt-injection-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-22-google-antigravity-ide-prompt-injection-rce/</guid><description>Mindgard researchers discovered two vulnerabilities in Google&apos;s Antigravity AI coding assistant: a prompt injection via the find_by_name tool that bypasses Strict Mode to achieve code execution, and a persistent backdoor via workspace trust that survives reinstallation of the IDE extension. Google has patched both; update immediately and audit workspace trust settings.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>ai-coding-assistant</category><category>prompt-injection</category><category>rce</category><category>google</category><category>workspace-security</category><category>persistent-backdoor</category></item><item><title>Vercel Confirms Breach via Compromised AI Tool — Developer Environment Variables and Credentials Exposed</title><link>https://cipherwatch.io/articles/2026-04-20-vercel-breach-context-ai-lumma-stealer-developer-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-20-vercel-breach-context-ai-lumma-stealer-developer-supply-chain/</guid><description>Cloud deployment platform Vercel has confirmed a breach traced to a Lumma infostealer infection at Context.ai, a third-party AI tool used by a Vercel employee. Attackers used the stolen Google Workspace OAuth access to reach Vercel&apos;s internal environments, exposing environment variables and a limited set of customer credentials. ShinyHunters is claiming responsibility and demanding $2 million for the stolen data.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>vercel</category><category>supply-chain</category><category>lumma-stealer</category><category>shinyhunters</category><category>infostealer</category><category>oauth</category><category>developer-credentials</category><category>ci-cd</category><category>environment-variables</category><category>third-party-risk</category></item><item><title>Five-Year-Old ShowDoc RCE Flaw CVE-2025-0520 (CVSS 9.4) Now Under Active Exploitation — Over 2,000 Instances Exposed</title><link>https://cipherwatch.io/articles/2026-04-19-showdoc-cve-2025-0520-rce-exploitation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-19-showdoc-cve-2025-0520-rce-exploitation/</guid><description>Threat actors are actively exploiting CVE-2025-0520, a critical unauthenticated remote code execution vulnerability in ShowDoc — an IT documentation tool used by developers and operations teams. The flaw, patched in October 2020 but present in thousands of unupgraded installations, allows file upload exploitation to deploy web shells. More than 2,000 publicly accessible ShowDoc instances remain vulnerable.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><category>rce</category><category>showdoc</category><category>documentation-tool</category><category>web-shell</category><category>n-day-exploitation</category><category>unpatched</category><category>devops</category><category>file-upload</category></item><item><title>nginx-ui CVE-2026-33032 Actively Exploited — Unauthenticated Full Server Takeover</title><link>https://cipherwatch.io/articles/2026-04-16-nginx-ui-cve-2026-33032-mcp-endpoint-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-16-nginx-ui-cve-2026-33032-mcp-endpoint-rce/</guid><description>A critical authentication bypass vulnerability (CVSS 9.8) in the nginx-ui web management interface allows any network attacker to take complete control of the underlying Nginx server without credentials. Over 2,600 instances are internet-exposed and the flaw is being actively exploited. Update to version 2.3.4 immediately.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><category>rce</category><category>nginx</category><category>nginx-ui</category><category>authentication-bypass</category><category>mcp</category><category>web-infrastructure</category><category>actively-exploited</category><category>cve-2026-33032</category></item><item><title>Apache ActiveMQ CVE-2026-34197: 13-Year-Old Jolokia API Flaw Enables Unauthenticated RCE</title><link>https://cipherwatch.io/articles/2026-04-10-apache-activemq-rce-jolokia-api/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-10-apache-activemq-rce-jolokia-api/</guid><description>A critical unauthenticated remote code execution vulnerability in Apache ActiveMQ&apos;s Jolokia management API allows attackers to execute arbitrary OS commands by invoking a management MBean. CVE-2026-34197 roots in a design flaw present since ActiveMQ 5.x and chains dangerously with CVE-2024-32114. Patches are available in ActiveMQ 6.2.3 and 5.19.4.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>apache</category><category>activemq</category><category>rce</category><category>jolokia</category><category>cve-2026-34197</category><category>unauthenticated</category><category>message-broker</category><category>java</category><category>cve-2024-32114</category></item><item><title>DPRK&apos;s Contagious Interview Campaign Spreads 1,700+ Malicious Packages Across Five Ecosystems</title><link>https://cipherwatch.io/articles/2026-04-10-dprk-contagious-interview-cross-ecosystem-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-10-dprk-contagious-interview-cross-ecosystem-supply-chain/</guid><description>North Korea&apos;s UNC1069 (BlueNoroff) threat group has expanded its Contagious Interview supply chain operation to five package registries — npm, PyPI, Go Modules, crates.io, and Packagist — publishing more than 1,700 malicious packages that deliver a cross-platform infostealer and RAT. The operation is the largest coordinated open-source supply chain attack attributed to a nation-state actor.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>north-korea</category><category>dprk</category><category>unc1069</category><category>bluenoroff</category><category>contagious-interview</category><category>supply-chain</category><category>npm</category><category>pypi</category><category>go</category><category>rust</category><category>php</category><category>malware</category><category>rat</category><category>infostealer</category></item><item><title>Progress ShareFile Pre-Auth RCE Chain Puts 30,000 Exposed Servers at Risk — Patch to 5.12.4</title><link>https://cipherwatch.io/articles/2026-04-09-progress-sharefile-pre-auth-rce-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-09-progress-sharefile-pre-auth-rce-chain/</guid><description>Researchers at watchTowr Labs have disclosed a two-vulnerability chain in Progress ShareFile Storage Zones Controller that enables unauthenticated remote code execution via webshell upload. Approximately 30,000 Storage Zone Controller instances are internet-exposed and remain at risk if not patched to version 5.12.4, which was released on 10 March 2026 before full public disclosure of the attack path.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate><category>sharefile</category><category>progress</category><category>rce</category><category>pre-auth</category><category>webshell</category><category>auth-bypass</category><category>file-upload</category><category>vulnerability-chain</category></item><item><title>Smart Slider 3 Pro Update Infrastructure Compromised — Backdoored Plugin Pushed to 800,000 Sites</title><link>https://cipherwatch.io/articles/2026-04-09-smart-slider-3-pro-wordpress-supply-chain/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-09-smart-slider-3-pro-wordpress-supply-chain/</guid><description>Attackers breached Nextend&apos;s update servers and distributed a fully weaponised backdoor through the official Smart Slider 3 Pro update channel, affecting WordPress and Joomla sites that auto-updated between 7–8 April 2026. The compromised version 3.5.1.35 creates rogue admin accounts, drops persistent remote access tools, and exfiltrates credentials — all delivered through the trusted plugin update mechanism.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>joomla</category><category>supply-chain</category><category>plugin</category><category>smart-slider</category><category>nextend</category><category>backdoor</category><category>cms</category><category>web-security</category><category>cve</category></item><item><title>CVSS 10.0 Flowise RCE Actively Exploited Across 12,000 Exposed Instances</title><link>https://cipherwatch.io/articles/2026-04-07-flowise-rce-cve-2025-59528-exploited/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-07-flowise-rce-cve-2025-59528-exploited/</guid><description>CVE-2025-59528, a maximum-severity remote code execution vulnerability in the Flowise AI workflow platform, is being actively exploited in the wild. Over 12,000 internet-exposed instances remain unpatched, allowing attackers to execute arbitrary JavaScript on host machines and extract API keys, credentials, and configuration secrets.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>rce</category><category>flowise</category><category>ai-platform</category><category>cve-2025-59528</category><category>supply-chain</category><category>api-keys</category><category>mcp</category></item><item><title>Langflow RCE CVE-2026-33017 Exploited Within 20 Hours, Added to CISA KEV</title><link>https://cipherwatch.io/articles/2026-03-30-langflow-cve-2026-33017-rce-cisa-kev/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-30-langflow-cve-2026-33017-rce-cisa-kev/</guid><description>A critical unauthenticated remote code execution vulnerability in Langflow AI pipeline builder was exploited in the wild within 20 hours of disclosure, with attackers harvesting API keys for OpenAI, Anthropic, and AWS from compromised instances. CISA added CVE-2026-33017 to the Known Exploited Vulnerabilities catalogue on 26 March, making patching mandatory for US federal agencies.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>langflow</category><category>rce</category><category>unauthenticated</category><category>ai-security</category><category>cisa-kev</category><category>cve-2026-33017</category><category>llm</category><category>api-key-theft</category></item><item><title>TeamPCP Backdoors LiteLLM on PyPI — AI Gateway Package With 3 Million Daily Downloads Compromised</title><link>https://cipherwatch.io/articles/2026-03-30-litellm-pypi-supply-chain-teampcp/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-30-litellm-pypi-supply-chain-teampcp/</guid><description>The LiteLLM Python package — a widely-deployed AI gateway library with three million daily downloads — was backdoored on PyPI on 24 March by threat actor TeamPCP. Malicious versions 1.82.7 and 1.82.8 deployed a three-stage payload stealing cloud credentials, Kubernetes secrets, and CI/CD tokens from any system that installed the package during a 40-minute window.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>supply-chain</category><category>pypi</category><category>litellm</category><category>teampcp</category><category>credential-theft</category><category>kubernetes</category><category>ai-security</category><category>cicd</category><category>backdoor</category></item><item><title>Craft CMS CVSS 10 Code Injection CVE-2025-32432 Added to CISA KEV</title><link>https://cipherwatch.io/articles/2026-03-24-craft-cms-cve-2025-32432-cisa-kev-rce/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-24-craft-cms-cve-2025-32432-cisa-kev-rce/</guid><description>CISA added CVE-2025-32432, a maximum-severity code injection vulnerability in Craft CMS, to its Known Exploited Vulnerabilities catalogue on 20 March 2026. The flaw allows unauthenticated remote attackers to execute arbitrary code on any publicly accessible Craft CMS installation. Exploitation has been ongoing since at least February 2025 and the Mimo threat actor has been actively using it to deploy cryptocurrency miners and residential proxy malware.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><category>craft-cms</category><category>rce</category><category>unauthenticated</category><category>code-injection</category><category>cisa-kev</category><category>cve-2025-32432</category><category>cms</category><category>web-application</category><category>mimo</category></item><item><title>Trivy Security Scanner Hijacked — 75 GitHub Action Tags Redirected to Credential Stealer</title><link>https://cipherwatch.io/articles/2026-03-24-trivy-supply-chain-cve-2026-33634-cicd-attack/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-24-trivy-supply-chain-cve-2026-33634-cicd-attack/</guid><description>The widely-used Aqua Security Trivy vulnerability scanner was compromised in a supply chain attack that replaced 75 version tags in the official trivy-action and setup-trivy GitHub Actions with credential-stealing malware. Threat actor TeamPCP leveraged non-atomic secret rotation to retain access after an initial February compromise, launching a second attack wave on 19 March. Any CI/CD pipeline that ran trivy-action or setup-trivy during the compromise window may have had cloud credentials, API tokens, and SSH keys exfiltrated.</description><pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate><category>trivy</category><category>github-actions</category><category>supply-chain</category><category>cicd</category><category>credential-theft</category><category>teampcp</category><category>cve-2026-33634</category><category>aqua-security</category><category>devops</category></item><item><title>Google Patches Two Actively Exploited Chrome Zero-Days — CISA Orders Federal Agencies to Update by 27 March</title><link>https://cipherwatch.io/articles/2026-03-22-chrome-zero-days-cve-2026-3909-3910-cisa-kev/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-22-chrome-zero-days-cve-2026-3909-3910-cisa-kev/</guid><description>Google released an emergency Chrome update on 13 March addressing two zero-day vulnerabilities — an out-of-bounds write in Skia and a V8 sandbox escape — both confirmed as exploited in the wild. CISA added both to the Known Exploited Vulnerabilities catalogue the same day with a 27 March federal remediation deadline.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>chrome</category><category>browser-security</category><category>cisa-kev</category><category>actively-exploited</category><category>google</category><category>skia</category><category>v8</category></item></channel></rss>