π΅οΈ RESEARCH & DEEP DIVES
-
Amazon Links North Korean Hackers to Multiple NPM Supply Chain Attacks
Amazon attributes several high-profile NPM supply chain attacks to North Korean hackers.- Targets: Popular Node Package Manager (npm) libraries including typo-crypto, debug, chalk, and axios
- Attack timeline: Started March 2025 with typo-crypto, escalated in September 2025 with debug and chalk, and hit axios in March 2026
- Attack method: Social engineering of package maintainers to publish malicious updates automatically distributed to users
- Attribution: Linked to North Korean threat actor Sapphire Sleet (BlueNoroff, Stardust Chollima) based on tactics, infrastructure, and operational similarities
- Attack trends: Use of multi-stage payloads, environment-aware malware, AI-assisted code generation, and squatting on AI-generated package names
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
North Korean threat actors use fake macOS update screens to deliver crypto-stealing malware.- Targets macOS users via malvertising with fake full-screen update pages
- Attack starts from clicking sponsored search results leading to fake update prompts
- Uses clipboard-pasted Terminal commands (ClickFix technique) to execute Node.js backdoor
- Backdoor fetches C2 server address from Ethereum smart contracts (EtherHiding)
- Steals data from 157 cryptocurrency wallets and installs malicious Chrome extension
π Coverage: thehackernews.com Β· π via The Hacker News
-
Six critical vulnerabilities found in SGLang framework including unauthenticated RCE and data leaks
CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-15977CVE-2026-15978
Multiple unauthenticated vulnerabilities in SGLang enable remote code execution, data exfiltration, and credential leaks.- Applies to SGLang open-source framework for serving large language and multimodal AI models
- Includes unauthenticated remote code execution via crafted pickle payloads and insecure model weight loading
- Server-side request forgery and local file read via unsanitized image URL input in chat completions endpoint
- Credential leakage through /server_info endpoint exposing API keys and SSL keyfile info with admin API key
- Model weight exfiltration possible without API keys by triggering distributed weight broadcasting endpoints
π Coverage: kb.cert.org Β· π Original: github.com Β· π via CERT/CC Vulnerability Notes, CVE ThreatInt (+5)
-
IBM Langflow OSS 1.0.0-1.10.1 vulnerable to RCE, DoS, path traversal, and data exposure
IBM Langflow OSS versions 1.0.0 to 1.10.1 have multiple vulnerabilities allowing unauthorized data access and remote code execution.- Applies to IBM Langflow OSS versions 1.0.0 through 1.10.1
- Vulnerabilities include remote code execution, denial of service, path traversal, and exposed credentials
- Attackers can access other users' private vector documents by matching Chroma persist_directory and collection_name
- Attackers can insert documents into victims' collections, polluting shared namespaces
- Exploits occur via unauthenticated and insufficiently authorized API endpoints
π Coverage: cve.threatint.com Β· π Original: cve.threatint.com Β· π via CVE ThreatInt
-
Critical Arbitrary File Read and RCE in Rails Active Storage via libvips (CVE-2026-66066)
CVE-2026-66066
Rails Active Storage is vulnerable to arbitrary file read and remote code execution via crafted image uploads.- Applies to Rails Active Storage versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1
- Vulnerability allows unauthenticated attackers to read arbitrary files accessible to the Rails process
- Exploits unsafe libvips operations enabled for untrusted image uploads
- Exposure of environment variables and secrets like secret_key_base can lead to remote code execution
- Fixed in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1
π Coverage: cve.threatint.com Β· π Original: cve.threatint.com Β· π via CVE ThreatInt
π ADVISORIES
-
Multiple vulnerabilities in Google Chrome before 151.0.7922.71 allow code execution
Multiple vulnerabilities in Google Chrome allow arbitrary code execution.- Applies to Google Chrome versions prior to 151.0.7922.71/.72 on Windows, Mac, and Linux
- Multiple use-after-free, insufficient validation, and implementation flaws across components like Compositing, Dawn, Views, Skia, V8, ANGLE, and more
- Exploitation could allow arbitrary code execution in the context of the logged-on user
- Attack vector includes drive-by compromise via malicious web content
- No reported exploitation in the wild as of advisory date
π Coverage: cisecurity.org Β· π Original: cisecurity.org Β· π via CIS Advisories
-
email-phishing-spf-dkim-dmarc-bypass β @briankrebs@infosec.exchange
-
CISA issues open-source software security guidance for federal agencies
CISA published security guidance for federal agencies on managing open-source software risks.- Applies to federal agencies using open-source software (OSS)
- Guidance covers OSS risk management, patching, and open-weight AI model security
- Encourages evaluating OSS trustworthiness before approval and tracking OSS assets
- Highlights unique OSS traits like transparency and collaborative maintenance
- Addresses challenges with unverifiable AI models and recent OSS attack trends
π Coverage: cyberscoop.com Β· π via CyberScoop
π CVEs & KEV
- CVE-2026-12943 β CVSS 9.8 β This Power Hardware Management Console update is being released to addressIBM...
- CVE-2026-18245 β CVSS 9.0 β Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codege...
- CVE-2026-18140 β CVSS 7.5 β Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows un...
- CVE-2024-25039 β CVSS 7.5 β IBM Engineering Requirements Management DOORS and DOORS Web Access is affecte...
- CVE-2026-10545 β CVSS 7.5 β IBM Planning Analytics Local is affected by Open RedirectIBM Planning Analyti...
- CVE-2026-12733 β CVSS 7.5 β IBM DataPower Gateway affected by denial of serviceIBM DataPower Gateway coul...
- CVE-2024-40683 β CVSS 6.3 β IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allo...
- CVE-2025-36374 β CVSS 5.5 β IBM DataPower Gateway affected by XML external entity injectionIBM DataPower ...
- CVE-2026-14227 β CVSS 4.9 β Insufficient session expiration in MikroTik RouterOSAn API sessionβmanagement...
- CVE-2026-59881 β CVSS β β AIOHTTP: WebSocket client accepts compressed frames without negotiated permes...