Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

Samsung rlottie: RCE via Integer Truncation, Open-Source Patch Available
A short-vs-int type error in Samsung's rlottie graphics library enables remote code execution through a malicious animation file. A pa…

Atril RCE via EPUB: Patch Available Nine Days Before Disclosure
ZDI-26-360: A heap buffer overflow in the MATE Desktop's Atril document viewer enables remote code execution through malicious EPUB fi…

iOS AI Apps: 282 Exposed, Only 28% Fixed
Wake Forest study finds 282 of 444 analyzed iOS LLM apps leak API credentials. After 90 days of responsible disclosure, just 28% remed…

systemd 261: Software TPM and Native Installer Rewrite the Rules
systemd 261 expands the project's scope well beyond its traditional init system role, introducing a software TPM based on IBM swtpm, a…

Microsoft Attributes Mastra Supply-Chain Attack to North Korean Sapphire Sleet
Microsoft assesses with high confidence that the supply-chain compromise of more than 140 @mastra npm packages was carried out by the…

Attack Surface 2026: 42% of Companies Have Databases Exposed to the Internet
Intruder's report on 3,000 organizations reveals the midmarket paradox: growing companies with enterprise-scale attack surfaces and SM…

X.Org Server UAF CVE-2026-34001: Local Root Escalation on Linux
ZDI-26-335 discloses a use-after-free in X.Org Server's SyncTriggerList: CVSS 7.8, local attack with no user interaction, X.Org patch…

Klue Breach: Dormant OAuth Credential Opens Multi-Victim Door to Salesforce
The Icarus extortion group exfiltrated CRM data from Klue customers by abusing stolen OAuth tokens. Cybersecurity vendor Huntress conf…

The 'robase' Malware Empties Entire Roblox Games: From Hat Theft to Digital Business Seizure
A malware campaign using the Python package 'robase' steals authenticated session tokens from Roblox developers via Discord social eng…

vbdec Disassembler Becomes Local AI Server via COM/ROT
Cisco Talos demonstrates how exposing vbdec's object model to the Windows Running Object Table enables local agentic automation withou…

MySQL Exposed at 26%: The 2026 Top 10 Attack Surface Exposures
Intruder's 2026 ASM Index reveals exposed databases and admin panels as primary vectors. Time-to-exploit has collapsed to a single day…

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads
A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…