Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

Copy Fail CVE-2026-31431: Root Escalation in 732 Bytes on Linux
CVE-2026-31431 lets a local user gain root on Linux in seconds with a 732-byte script. CISA confirms active exploitation.

WordPress: Backdoors in Essential Plugins, Supply Chain Collapses on Flippa
A buyer purchased 31 WordPress plugins on Flippa, injected PHP backdoors, and activated cloaked SEO spam for Googlebot after eight mon…

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions
CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers
Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

MIT CSAIL: Interrupt Injection Bypasses Spectre v2 on Intel and AMD CPUs
MIT CSAIL researchers demonstrated that an unprivileged Linux program can inject precisely timed hardware interrupts to bypass Spectre…

Gitea: Critical File Read via Org-mode, RCE Risk with CVSS 9.8
CVE-2026-59774 affects Gitea 1.22.1 through 1.27.0: an unauthenticated attack exploits Org-mode markup to read arbitrary files and pot…

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available
Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8
JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Arch Linux Halts AUR Package Adoptions: Third Supply-Chain Attack in Two Months
On July 30, 2026, Arch Linux suspended package adoptions in the Arch User Repository to stop an active supply-chain campaign. It is th…

QLNX: The Linux RAT Targeting Software Supply Chain Keys
Trend Micro discovered QLNX, a previously undocumented Linux RAT that combines a dual-tier rootkit, PAM backdoor, and P2P network to s…

Exploitarium Turns Zero-Day Disclosure into Permanent Infrastructure
The Exploitarium repository has published 204 zero-day exploits for open-source projects without vendor notification. CVE-2026-55200 a…

GhostLock: The Exploit That Unlocks Linux in 5 Seconds — 15 Years in the Shadows
On July 7, 2026, Nebula Security disclosed GhostLock, a working exploit for CVE-2026-43499, a use-after-free in the Linux kernel's fut…