๐ต๏ธ RESEARCH & DEEP DIVES
- Attackers Target CI/CD Pipelines and Developer Tools in SDLC Supply Chains
Attackers are targeting CI/CD pipelines and developer tools in software supply chains.- Software development teams using modern SDLCs and CI/CD pipelines are affected.
- The targeted attack surface includes developer tools, build systems, and software dependencies.
- Attackers focus on overlooked SDLC components instead of directly compromising application code.
๐ Source: linuxfoundation.org ยท ๐ Coverage: unit42.paloaltonetworks.com ยท ๐ via Palo Alto Unit 42
๐ CVEs & KEV
-
CVE-2026-53528 โ CVSS 8.8 โ FileWiki has path traversal in RenameAsset via unsanitized oldFilename parame...
-
CVE-2026-53527 โ CVSS 8.8 โ LeafWiki Vulnerable to Privilege Escalation via User Self-Service UpdateLeafW...
-
CVE-2026-33240 โ CVSS 8.8 โ Combodo iTop: Reflected XSS in foreign key search criteriaCombodo iTop is a w...
-
CVE-2026-31936 โ CVSS 8.8 โ Combodo iTop: Unauthorized access to object information via search operationC...
-
CVE-2026-34741 โ CVSS 8.6 โ Combodo iTop: Authentication bypass in exec.php allows PHP file executionComb...
-
CVE-2026-34836 โ CVSS 6.5 โ Combodo iTop: Improper access control in ajax.render.php and ajax.document.ph...
-
CVE-2026-77811 โ CVSS 6.2 โ OpenSearch Dashboards Plugin XSS (CVE-2026-77811)