๐จ ACTIVE EXPLOITATION
- Supply-chain worm hits TanStack Query code generator
A supply-chain worm compromised the TanStack Query code generator @7nohe/openapi-react-query-codegen.- Users of @7nohe/openapi-react-query-codegen and maintainers of npm packages are affected.
- The worm steals credentials from victims.
- It spreads to every package maintained by an infected victim.
๐ Coverage: aikido.dev ยท ๐ via aikido.dev (discovered)
๐ฅ BREACHES & INCIDENTS
-
McKesson discloses breach after ShinyHunters claims patient data theft
McKesson disclosed unauthorized access to third-party applications and data exfiltration.- McKesson, its healthcare customers and partners, and their patients are potentially affected.
- ShinyHunters claims it stole 284 million records linked to tens of millions of patients.
- The alleged data includes names, addresses, dates of birth, contact details, Social Security numbers, medical records, prescriptions and diagnoses.
- McKesson said the incident involved unauthorized access to third-party applications and data exfiltration; its investigation is ongoing.
๐ Coverage: cyberinsider.com ยท ๐ via BleepingComputer
-
Berlin Rejects Extortion Demand After State Network Data Theft
Berlin's state government is facing extortion after hackers stole data from its network.- Berlin's state government and Senate departments for mobility, transport, climate, and the environment were affected.
- Attackers claimed to have stolen 5.79 TB of data, including contracts, emails, passwords, and personal information.
- The leak occurred between August 7 and 12, 2026, before affected departments were isolated on August 14.
- Rhysida claimed the attack and offered the data for auction with a starting price of 30 bitcoin.
- The initial access method has not been disclosed.
๐ Source: berlin.de ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ต๏ธ RESEARCH & DEEP DIVES
- Perturbation probing finds LLM safety refusal concentrated in few neurons
Unit 42 found that aligned LLM refusal behavior can depend on a small number of neurons.- The finding applies to aligned large language models, including Qwen3-4B and Qwen3.5-2B.
- On Qwen3-4B, 50 of 350,208 feed-forward neurons controlled the safety refusal template.
- Removing those neurons changed response formats on 80% of 520 harmful-prompt benchmark tests.
- On Qwen3.5-2B, disabling 20 neurons eliminated false agreement across 30 multi-turn questions.
- A two-forward-pass perturbation-probing method identifies the neurons, while the FFN/Skip ratio predicted 81% of safety-fragility variance across 13 models.
๐ Source: arxiv.org ยท ๐ Coverage: unit42.paloaltonetworks.com ยท ๐ via Palo Alto Unit 42
๐ ADVISORIES
- ๐ Source for Critical JFrog Artifactory Authentication Bypass Enables Admin Access โ docs.jfrog.com
๐ CVEs & KEV
-
CVE-2026-19295 โ CVSS 9.9 โ Langflow is affected by multiple remote code execution vulnerabilities due to...
-
CVE-2026-18527 โ CVSS 9.9 โ IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin...
-
CVE-2026-19286 โ CVSS 9.8 โ Langflow is affected by multiple remote code execution vulnerabilities due to...
-
CVE-2026-3627 โ CVSS 9.1 โ Multiple Vulnerabilities in IBM Concert SoftwareIBM Concert 1.0.0 through 2.3...
-
CVE-2026-18729 โ CVSS 8.8 โ Langflow is affected by multiple remote code execution vulnerabilities due to...
-
CVE-2026-82017 โ CVSS 8.6 โ IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration ...
-
CVE-2026-18904 โ CVSS 8.2 โ Langflow is affected by multiple authentication bypass, path traversal, autho...
-
CVE-2026-18891 โ CVSS 8.2 โ Langflow is affected by multiple authentication bypass, path traversal, autho...
-
CVE-2026-18899 โ CVSS 7.5 โ Langflow is affected by multiple authentication bypass, path traversal, autho...
-
CVE-2026-17203 โ CVSS 7.5 โ IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin...
-
CVE-2026-16821 โ CVSS 7.0 โ Vulnerabilities in IBM AIX and PowerVM VIOSIBM AIX 7.2, and 7.3 and IBM Power...
-
CVE-2026-82018 โ CVSS 6.8 โ IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf FileIGEL OS 12 befo...
-
CVE-2026-19294 โ CVSS 6.4 โ Langflow is affected by multiple authentication bypass, path traversal, autho...