Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7

Self-spreading npm worm ChainDrop poisons over 1,300 package versions in hours

A self-propagating worm named ChainDrop tore through the npm registry on August 4, poisoning packages that huge parts of the software world depend on. It began by hijacking the GitHub account behind keyv, a caching library pulled in about 150 million times a week, then spread to sibling and downstream packages, reaching over 1,300 poisoned versions with billions of monthly downloads within hours. A preinstall script harvests credentials from developer and continuous integration environments, including AI agent tokens, cloud keys, and self-hosted CI secrets, then uses stolen npm publishing access to poison more packages. A descendant of the earlier Shai-Hulud worm, it even forged valid-looking build provenance.

Check
Compare lockfiles and resolved versions against the published affected-package list, and treat any machine that installed a poisoned version as compromised, but remove the malware's token watcher before rotating anything.
Affected
Developers and CI systems that installed a poisoned version during the attack window; the worm steals repository, registry, cloud, AI agent, and private-key credentials, then self-spreads through npm publishing access.
Fix
Rotate all reachable credentials after removing the token watcher, install with scripts disabled, pin and delay adoption of new versions, and check for injected hooks in developer tooling and continuous integration configuration.

Critical cPanel flaw lets a hosting customer gain database administrator access

cPanel patched a critical flaw that lets an ordinary hosting customer escalate to full database administrator access, running SQL as the database root user. Tracked as CVE-2026-58048 with a score of 9.4, the bug is significant on shared hosting, where many customers use one database server: administrator access there can expose or alter other tenants' data, and depending on the operating system and database configuration, cPanel warns it may extend to operating-system-level compromise. cPanel is one of the most widely deployed web hosting control panels, so the flaw affects a large number of shared and reseller hosting environments. Fixes shipped across several release tiers.

Check
Update cPanel to a patched build for your release tier, prioritizing shared and reseller servers, and if you host with a provider, confirm they have applied the fix.
Affected
Providers and customers on unpatched cPanel servers (CVE-2026-58048); a hosting customer can gain database root access, reaching other tenants' data and potentially the underlying operating system on shared infrastructure.
Fix
Apply cPanel's patched builds, apply the vendor's interim mitigation where immediate updating is not possible, review database accounts and logs for unauthorized administrator use, and segment tenants where feasible.

Google removes AI agent workflows after a GitHub issue could hijack a privileged agent

Pillar Security showed that Google's Agent Development Kit repository could be turned against itself through a poisoned pull request or issue. The public repository ran a low-privileged triage agent that responded to outside contributions, and a higher-privileged agent reserved for maintainers. Because the triage agent posted through a bot account that counted as a repository collaborator, a prompt injection could make it post a command that satisfied the privileged workflow's trust check, invoking the maintainer-level agent. That crossed into a job holding a long-lived access token, a Google API key, and a cloud service-account credential, enabling code execution on the runner and secret theft. Google deleted the affected workflows.

Check
Review any AI agent workflows that act on untrusted pull requests or issues, and check whether a low-privileged agent can trigger a higher-privileged one through a shared bot identity.
Affected
Teams running tiered AI agent workflows in code repositories; untrusted issue or pull-request content can prompt-inject a public agent into invoking a privileged one, exposing continuous integration secrets and code execution.
Fix
Give agents scoped, non-collaborator identities, keep untrusted content from reaching privileged workflows, require human approval for sensitive agent actions, and minimize the tokens and credentials an agent job can access.

TP-Link patches 15 Omada provisioning flaws that chain into network takeover

TP-Link patched 15 vulnerabilities in the zero-touch provisioning system of its Omada business networking line, which lets IT teams and managed service providers configure switches, access points, gateways, and routers remotely. Forescout's Vedere Labs, which presented the findings at Black Hat, reported hardcoded cryptographic keys and certificates, insecure credential transmission, weak certificate validation enabling interception, a race condition in cloud device adoption, and default credentials. Chained with two previously disclosed command-injection flaws, they let an attacker break the provisioning chain of trust and infiltrate networks. Eleven received CVEs, and some issues also affect TP-Link cameras and smart-home devices. Forescout found over 1,800 exposed controllers.

Check
Apply TP-Link's Omada firmware and controller updates, take controller management interfaces off the public internet, and change any default device credentials still in use.
Affected
Organizations, and the managed service providers serving them, running TP-Link Omada devices; the provisioning flaws enable interception, device hijacking, and, chained with prior command-injection bugs, remote code execution and network infiltration.
Fix
Update affected Omada controllers and devices, restrict controller exposure, replace default credentials and certificates, monitor for rogue device adoption, and extend checks to affected TP-Link cameras and smart-home products.

77 malicious Open VSX extensions posed as dev tools to harvest developer data

Manifold Security found 77 malicious extensions on Open VSX, the open marketplace that editors like VSCodium, Cursor, and Windsurf pull extensions from, impersonating legitimate developer tools. Detected between July 26 and August 1, all 77 were linked through a shared exfiltration domain and common code. Fifty-eight sent only basic system information, while the other 19 performed deeper reconnaissance, exfiltrating developer, Git repository, and continuous integration metadata. Manifold found no access to source code, credentials, tokens, or SSH material and did not determine the campaign's goal. The extensions were pulled from Open VSX by August 3, but must still be removed manually from affected machines.

Check
Check developer machines and workspace configuration files for the extension identifiers in Manifold's report, remove any that appear, and block the campaign's exfiltration domain, mangorbit dot com.
Affected
Developers who installed the evil-twin extensions from Open VSX through editors like VSCodium, Cursor, or Windsurf; the extensions leaked system, Git repository, and continuous integration metadata about their environments.
Fix
Vet extensions and publishers before installing, prefer verified sources, inventory installed extensions across developer machines, block the known exfiltration domain, and monitor for extensions contacting unexpected external hosts.

XCSSET returns to infect Macs when developers build poisoned Xcode projects

Palo Alto Networks Unit 42 detailed a rebuilt version of XCSSET, macOS malware that spreads through Xcode developer projects. The actors compromise Git repositories and inject a downloader into ordinary files inside a project, so that when a developer builds the cloned project, a hidden loader runs under their own account with no permission prompt. It then infects every other Xcode project on the machine and propagates through shared code. Version 40 hides its logic in memory, generates polymorphic payloads, and adds a Chrome hijacker that drives the browser through its debugging protocol plus a component that trojanizes Telegram. Seventeen modules handle credential, keystroke, clipboard, and browser theft.

Check
Inspect Xcode projects, especially shared or cloned ones, for unexpected build scripts or run phases before building them, and watch developer machines for Chrome launched with debugging enabled.
Affected
macOS developers who build Xcode projects cloned from Git repositories; a hidden loader runs at build time under the developer's account, spreads to other local projects, and steals credentials and browser data.
Fix
Review third-party Xcode projects before building, build untrusted ones in isolated environments, keep macOS and tools patched, and monitor for browsers launched with remote debugging and unexpected outbound connections.

Attackers exploit N-able RMM auth bypass, and the first fix did not hold

N-able is warning that attackers exploited an authentication bypass in N-central, the remote monitoring and management platform used by managed service providers and IT teams to administer customer endpoints. The flaw, CVE-2026-18556, allows unauthenticated administrative account takeover, and N-able's initial fix in one release proved incomplete: it found another way to exploit the same weakness, tracked as CVE-2026-18577, that widened the affected range. After taking over a server, attackers used its remote-control feature to reach managed endpoints and installed Cloudflare tunnels as services, which kept access alive even after the route through the N-central server was cut. Build 2026.3.1.7 is the first unaffected version.

Check
Upgrade N-central to build 2026.3.1.7 immediately, then hunt managed endpoints for unexpected Cloudflare tunnel services and other persistence, since patching the server does not remove footholds already placed.
Affected
Managed service providers and IT teams running N-able N-central before build 2026.3.1.7 (CVE-2026-18556, CVE-2026-18577); an unauthenticated attacker can take over the server and pivot to every managed customer endpoint.
Fix
Apply the hotfix, review N-central and endpoint logs for unauthorized access and tunnel installs, revoke and rebuild trust where compromise is found, and restrict management platform exposure to the internet.

Hugging Face Diffusers flaws turn loading a model into running attacker code

Researchers at Zafran disclosed three flaws, collectively named FaceHugger, in Hugging Face's widely used Diffusers library that let a crafted model repository run arbitrary code on any machine that loads it. All three bypass trust_remote_code, the safeguard meant to stop unreviewed code from executing, by exploiting a timing gap: the trust check runs against the first of two separate download requests, so anything that makes the loader see custom code the check did not slips through. One variant abuses a default None.py filename, another a race condition, and a third cross-repository pipeline loading. Because Diffusers runs inside production pipelines, CI/CD, and container images, one poisoned model load can mean deep initial access.

Check
Upgrade the Diffusers library to 0.38.0 or later across development, CI/CD, and container images, and check the transformers library, which has a related flaw, is current too.
Affected
Anyone loading Hugging Face models with Diffusers before 0.38.0 (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513); a malicious model repository executes code on load, bypassing the trust_remote_code safeguard and reaching CI/CD and production.
Fix
Update Diffusers and transformers, treat model repositories as untrusted code rather than data, load untrusted models only in isolated sandboxes, and apply egress controls and credential hygiene around machine learning pipelines.

Alleged Żabka leak advertises source code, Jira data, and a reused GitLab token

A data-leak forum listing is advertising an alleged dataset from Polish convenience-store chain Żabka for 5,000 euros, claiming roughly 541,000 Jira issues, about 230,000 IT service-desk tickets, and source code from 89 GitLab repositories. The post names real internal systems, including the chain's point-of-sale platform and SAP environment, and more than 20 outside vendors. A reviewer of the sample archive found the counts internally consistent and noted that a single GitLab access token appears across all 89 repository dumps, pointing to reused credentials rather than a code flaw. Żabka has not confirmed the breach, and the seller's account has no trading history.

Check
Treat the claim as unverified, but use it as a prompt to check whether single tokens or credentials in your own environment grant access across many repositories or systems.
Affected
Żabka and its listed vendors if the data is genuine; the pattern, one reused access token unlocking 89 repositories, is the same stolen-credential route behind many recent source-code and project-tracker thefts.
Fix
Scope access tokens narrowly per repository, rotate and expire them regularly, enforce phishing-resistant MFA on developer accounts, and watch for bulk exports from source and project-tracking systems that signal credential abuse.

Pass-ta-key attacks let malware on a PC steal and export Google-synced passkeys

Palo Alto Networks Unit 42 described three techniques, collectively Pass-ta-key, in which malware already running on a compromised Windows PC abuses Google Password Manager's synced passkeys. None break the underlying cryptography; they target how Chrome stores device keys, re-enrolls a device, and whether a site verifies that a person was present. The techniques can silently obtain a valid login assertion without any unlock prompt, register an attacker-controlled verification key that defeats user-verification checks, or extract the secret that decrypts all of a user's synced passkeys for reuse elsewhere. Passkeys still resist phishing, but a fully compromised endpoint undermines the synced-passkey model.

Check
Recognize that endpoint compromise, not phishing, is the threat to synced passkeys, and confirm your important services actually require and validate the user-verification flag on passkey logins.
Affected
Users of Google Password Manager synced passkeys in Chrome on Windows whose device is infected; malware can forge logins, bypass user verification, and export all synced passkeys, even for strict accounts.
Fix
Prioritize endpoint security since these attacks need local malware, require and strictly validate user verification on sensitive accounts, and consider hardware-bound passkeys or security keys rather than synced ones for high-value access.