Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

Dirty Frag LPE Chain: Deterministic Linux Root Access via Single Command
Dirty Frag exploits two Linux kernel vulnerabilities to achieve deterministic local privilege escalation to root. With a public PoC av…

Exim 'Dead.Letter' Vulnerability: Unauthenticated RCE Threatens GnuTLS-Based Mail Servers
A critical use-after-free vulnerability in Exim’s BDAT parser (CVE-2026-45185) allows for unauthenticated remote code execution on ser…

Google Disrupts AI-Generated Zero-Day: 2FA Bypass Found in Open-Source Tool
The Google Threat Intelligence Group (GTIG) has neutralized an AI-generated zero-day exploit targeting 2FA in a system administration…

Mini Shai-Hulud Worm: 170+ Packages Compromised as SLSA Protections Bypassed
The Mini Shai-Hulud worm has compromised over 170 npm and PyPI packages by exploiting GitHub Actions to generate valid SLSA attestatio…

Bleeding Llama: Why "On-Premises" Doesn't Mean "Safe" — CVE-2026-7482 and the 300,000 Exposed Servers
CVE-2026-7482 allows unauthenticated remote attackers to leak Ollama process memory via crafted GGUF files, exposing sensitive API key…

Dirty Frag: Linux Kernel Vulnerability Chain Exploited in the Wild for Root Access
Dirty Frag chains two Linux kernel flaws to achieve deterministic local privilege escalation. With a public PoC available and active e…

CVE-2026-3854: Critical RCE Vulnerability in GitHub Triggered via Single ‘git push’
A specifically crafted git push command can execute remote code on GitHub.com and GitHub Enterprise Server. While the cloud environmen…

CVE-2026-31431: CISA Mandates Container Patch — Actively Exploited in the Wild
CISA has confirmed active exploitation of CVE-2026-31431, a critical Linux kernel vulnerability dubbed "Copy Fail." With a 732-byte Po…

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere
Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence
At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

Linux ‘Copy Fail’ Under Active Attack: CISA Sets May 15 Patch Deadline
CISA has added CVE-2026-31431, known as 'Copy Fail,' to its KEV catalog following reports of active exploitation. The stealthy 732-byt…

Ruby and Go Supply Chain Attack: Discover the Sleeper Risk
A new supply chain attack targets Ruby and Go using sleeper packages and fake wrappers. Learn how to protect CI/CD pipelines and corpo…