Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

PyTorch Lightning Attack: Supply Chain Risk Revealed
Discover the details of the PyTorch Lightning supply chain attack: malicious versions, npm propagation, and AI impersonation. Here's w…

Linux Copy Fail Risk: The Invisible 4-Byte Root Exploit
The Linux Copy Fail vulnerability allows root escalation in 4 bytes, corrupting only RAM. Discover the impact on Kubernetes and how to…

Qinglong RCE Vulnerability: Express.js Bypass Revealed
RCE authentication bypass discovered in Qinglong: how Express.js routing differences enabled the attack and why payload filtering fail…

SAP npm Supply Chain Attack: Malware Targets CAP Packages
The Mini Shai-Hulud campaign compromises SAP npm packages, stealing credentials and establishing persistence via AI agents. Learn how…

NPM Supply Chain Attack: Malware Found in Claude Code and VS Code Extensions
A new SAP npm package supply chain attack targets AI coding agent configurations. Discover how mini Shai-Hulud steals credentials and…

PromptMink Malware: First Malicious Commit Co-Authored by Anthropic's Claude Opus
The Famous Chollima campaign marks the first instance of a malicious commit co-authored by an AI model, affecting over 1,700 software…

Vercel Breach: The Risks of Shadow AI OAuth Exposed
The Vercel breach highlights the danger of Shadow AI integrations: how a forgotten OAuth token opened corporate doors. Here is what yo…

CVE-2026-25874: Unpatched Critical RCE Found in Hugging Face LeRobot
A critical CVSS 9.3 flaw hits Hugging Face's LeRobot. Learn about the RCE risks and the month-long patch delay following initial discl…

PyPI: Package with 1.1 Million Downloads Hacked to Distribute Infostealer
A PyPI package with 1.1 million monthly downloads was compromised to distribute an infostealer. Analysis of the software supply chain…

GlassWorm v2: 73 Fake VS Code Extensions Discovered on Open VSX
A cluster of 73 malicious extensions linked to GlassWorm v2 discovered on Open VSX. Attackers use sleeper packages to evade security c…

Pack2TheRoot: Critical Linux Passwordless Root Vulnerability
Pack2TheRoot (CVE-2026-41651) affects Linux PackageKit for 12 years. CVSS 8.8, local passwordless root access. Patches available: here…