Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

Megalodon: 5,561 GitHub Repositories Compromised in 6 Hours
The Megalodon campaign injected malicious workflows into thousands of GitHub repositories, exfiltrating CI/CD tokens. The Tiledesk cas…

Notepad++: Institutional Alert Arrives Four Months After the Fix
Singapore's Cyber Security Agency published an advisory on CVE-2026-3008, a string injection flaw in Notepad++ 8.9.3 with a CVSS 6.6 s…

TeamPCP/UNC6780: Six Enterprise Breaches From Trivy to LiteLLM
The TeamPCP/UNC6780 campaign compromised Trivy to poison LiteLLM on PyPI. According to Hudson Rock, six enterprise breaches resulted w…

Shai-Hulud Hits npm: 440+ Packages Compromised with Valid Provenance
The Shai-Hulud campaign has infected over 440 npm packages with 2+ billion monthly downloads. The worm exploits signed GitHub Actions…

Copy Fail: The 732-Byte Linux Kernel Bug That Slept Since 2017
An unprivileged local user gains root deterministically. The exploit weighs 732 bytes. The bug had been in the kernel since 2017. This…

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

CVE-2026-19478: GitLab Patches Critical GraphQL Flaw CVSS 9.4 for Self-Managed Instances
GitLab issued an out-of-cycle patch on August 17, 2026 for CVE-2026-19478, a GraphQL vulnerability rated CVSS 9.4 that allows an unaut…

GhostLock: Public Exploit Grants Root in 5 Seconds on Linux Since 2011
CVE-2026-43499 has existed in the Linux kernel for 15 years. The public proof-of-concept requires only a local user to obtain root in…

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3
A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation
A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

GeoServer Zero-Day Under Attack: The Regression Exposing Cracks in the Secure Development Lifecycle
Threat actors began probing a SQL injection zero-day in GeoServer within hours of its public disclosure on August 12, 2026. The vulner…

TONTOU: The Attack That Nullifies Spectre v2 Mitigations and Leaks Linux Passwords
MIT CSAIL researchers demonstrated a bypass of Spectre v2 mitigations on Linux at Black Hat USA 2026. TONTOU extracts password hashes…