Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript
The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks
The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

Next.js: Two Critical RCE Patches Expose the Managed vs. Self-Hosted Protection Gap
Vercel released critical patches for two unauthenticated RCE vulnerabilities in Next.js on August 25, 2026. The disparity in protectio…

VCS Blind Spot: Wiz CIRT Publishes DFIR Matrix for GitHub and GitLab
The Wiz CIRT DFIR poster maps VCS audit logs to MITRE ATT&CK but exposes critical gaps: 88% of customers use SaaS with 7-day retention…

Satanic Exposes 1,033 Stripe API Keys: The Vector Isn't an Infostealer
Threat actor Satanic released data from 669 Stripe vendors with live API keys. Analysis rules out infostealer infections and points to…

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered
CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing
ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

libwebsockets: RCE via HTTP/2 HPACK, Single-Line Patch Available
ZDI-26-590 discloses an unauthenticated remote code execution vulnerability in libwebsockets. A missing bounds check in the HTTP/2 HPA…

TeamPCP Exploits AI Supply Chain to Steal One Terabyte of Credentials
The TeamPCP campaign compromised GitHub Actions and PyPI packages between March and April 2026. Over 2,500 organizations potentially e…

Exploitarium: The 'Recruitment by Chaos' That Shatters the CVD Model
Pseudonymous researcher 'bikini' dumped over 30 zero-day PoC exploits on GitHub on June 27, 2026, without any vendor coordination. CVE…

Trivy and LiteLLM Compromised: 2,100+ Organizations Exposed via Security Tools
TeamPCP compromised the CI/CD pipelines of Trivy and LiteLLM between March 19 and March 24, 2026. Six confirmed breaches hit European…

Stripe: 1,033 Vendor API Keys Exposed, Satanic Claims ~20,000 Total
Threat actor Satanic published data from 669 Stripe vendors containing over 1,000 live API keys. Hudson Rock found no infostealer infe…