Development & Open Source
Software development and open source follows supply chain, dependencies, tooling, repositories and code security. The cluster highlights vulnerabilities, updates and useful practices for developers and maintainers.

Dirty Frag: Linux Kernel Vulnerability Chain Exploited in the Wild for Root Access
Dirty Frag chains two Linux kernel flaws to achieve deterministic local privilege escalation. With a public PoC available and active e…

CVE-2026-3854: Critical RCE Vulnerability in GitHub Triggered via Single ‘git push’
A specifically crafted git push command can execute remote code on GitHub.com and GitHub Enterprise Server. While the cloud environmen…

CVE-2026-31431: CISA Mandates Container Patch — Actively Exploited in the Wild
CISA has confirmed active exploitation of CVE-2026-31431, a critical Linux kernel vulnerability dubbed "Copy Fail." With a 732-byte Po…

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere
Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence
At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

Linux ‘Copy Fail’ Under Active Attack: CISA Sets May 15 Patch Deadline
CISA has added CVE-2026-31431, known as 'Copy Fail,' to its KEV catalog following reports of active exploitation. The stealthy 732-byt…

Ruby and Go Supply Chain Attack: Discover the Sleeper Risk
A new supply chain attack targets Ruby and Go using sleeper packages and fake wrappers. Learn how to protect CI/CD pipelines and corpo…