109 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.
THU 10 SEP 2026
Two rclone advisories disclosed after First Watch show its S3 and RC auth-proxy checks can be bypassed outright, escalating a day that already had an unauthenticated RCE in OmniRoute and two new MikroTik KEV entries.
4 critical
12 high
1 medium
0 context
WED 09 SEP 2026
CISA's twin KEV adds for Citrix NetScaler and Cisco's firewall manager — both under three-day patch clocks — remain tonight's top priority, even after a late-evening batch of nine high-severity GHSA disclosures, including an MCP-server RCE and a LAN-exposed ESPHome dashboard, pushed the day's high count past every other evening this series has logged.
4 critical
22 high
15 medium
0 context
TUE 08 SEP 2026
Next.js and Astro's shared libheif AVIF RCE anchored the day, but CISA's evening KEV add of a pre-auth RCE in N-able N-central — MSP tooling with Kaseya-class blast radius — is the story that matters most before you log off.
9 critical
5 high
0 medium
1 context
MON 07 SEP 2026
A 111-day-dormant Shai-Hulud payload walked straight past npm's malware scanner today, the same day Adobe's unpatched Magento zero-day was confirmed dropping a disguised Rust backdoor on live stores.
2 critical
0 high
0 medium
3 context
SUN 06 SEP 2026
A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.
0 critical
0 high
1 medium
1 context
SAT 05 SEP 2026
A live, unauthenticated, patch-less Magento zero-day landed the same afternoon a Switchvox KEV hit its remediation deadline — one bug you can still fix, one you can only shield.
2 critical
0 high
0 medium
0 context
FRI 04 SEP 2026
A last-minute KEV add stole the night from the AI-agent story — CISA confirmed active exploitation of a Chromium V8 type-confusion bug just as GPT-6 Astra and eight CodeWhale approval-bypass CVEs showed agents landing on both sides of the supply chain today.
3 critical
5 high
1 medium
0 context
THU 03 SEP 2026
SiYuan's publish-mode disclosures kept escalating after First Watch and capped the night with an unauthenticated, stored SQL injection reachable from a saved document title.
4 critical
5 high
2 medium
0 context
WED 02 SEP 2026
A late four-CVE OpenChoreo disclosure — headlined by an unauthenticated cluster-gateway bypass — landed alongside a second Omnigent guardrail failure, turning today's AI-agent execution-layer story into a platform-trust story before midnight.
9 critical
39 high
36 medium
1 context
TUE 01 SEP 2026
A grind of a disclosure day — pnpm, browserslist, MLflow, and Filament all shipped fixes for install- and load-time supply-chain primitives, but no new active campaign or CISA KEV entry landed to go with them.
1 critical
11 high
7 medium
2 context
MON 31 AUG 2026
A pre-auth PaperCut RCE chain still owns tonight's operational priority, but a Kirby CMS security release landing after First Watch — two high-severity fixes for an auth'd storage-exhaustion bug and an encoded-slash path traversal — escalated the day's disclosure count late.
1 critical
4 high
3 medium
2 context
SUN 30 AUG 2026
The registries went quiet today, but the same commodity infostealers behind this month's ClickFix wave turned up draining Claude session cookies instead of crypto wallets.
0 critical
0 high
0 medium
2 context
SAT 29 AUG 2026
Spoofable client headers undo access control in three unrelated projects today, while Plone takes the day's only critical slot with a matched pair of import-triggered SSRF/DoS/XSS bugs.
1 critical
10 high
7 medium
0 context
FRI 28 AUG 2026
A Shai-Hulud-style npm worm hit a widely-used TanStack Query codegen package with valid provenance attestations, Pimcore shipped five same-day advisories chaining editor access to server RCE, and a late GHSA batch added a RestrictedPython sandbox-guard bypass and a SeaweedFS bucket-isolation break.
2 critical
9 high
5 medium
5 context
THU 27 AUG 2026
Today's fault lines run through the machinery meant to guarantee package integrity — a signature-verification bypass in Crossplane and a path-traversal KEV add in JFrog Artifactory — even as Australian police close the book on March's scanner-compromise campaign.
3 critical
3 high
4 medium
1 context
WED 26 AUG 2026
A live PyPI credential-stealer campaign and an unauthenticated LIMS RCE land the same day the MCP-tooling ecosystem's trust-boundary bug spreads to a seventh project.
3 critical
21 high
5 medium
6 context
TUE 25 AUG 2026
The MCP server ecosystem had its worst disclosure day yet: a dozen-plus agent-tooling projects — PraisonAI, Chainlit, mcp-shell, utcp, qwed-mcp, and more — dropped auth-bypass, SSRF, or RCE advisories within hours of each other.
7 critical
15 high
2 medium
2 context
MON 24 AUG 2026
CISA's KEV add for an actively-exploited Oracle proxy flaw anchored a day otherwise defined by broken authorization logic — cached-state bypasses, missing ownership checks, and unconfined admin inputs — across CMS, LMS, and proxy-panel software.
1 critical
4 high
7 medium
2 context
SUN 23 AUG 2026
A dark board: three passes, three feeds, zero items that cleared the bar.
0 critical
0 high
0 medium
0 context
SAT 22 AUG 2026
A day light on new disclosures narrowed to a single story: a BADBOX-linked group turned automotive Android head-unit firmware into a residential proxy botnet.
0 critical
1 high
0 medium
0 context
FRI 21 AUG 2026
A late-evening dump of four unrelated critical RCEs — JSONata, Xinference, Phalcon, and GeoTools — landed alongside a fresh npm backdoor campaign and a newly-KEV'd Zimbra pre-auth command injection.
7 critical
9 high
8 medium
0 context
THU 20 AUG 2026
A compromised crates.io maintainer account slipped a build-time payload into three widely used Rust crates — the same postinstall-dropper playbook that's hit npm repeatedly this year, now proven out in Cargo.
3 critical
18 high
8 medium
1 context
WED 19 AUG 2026
Six MCP-server disclosures in one hour turned the AI-agent tooling layer into today's supply-chain story, while CISA confirmed active exploitation of an MLflow SSRF flaw.
2 critical
13 high
10 medium
1 context
TUE 18 AUG 2026
A four-vendor CISA KEV cluster — Microsoft twice, VMware, and Apple — lands the same day RubyGems' StubMaker typosquat campaign resurfaces, capped by a late LibreNMS SSRF-to-stored-XSS disclosure batch.
5 critical
5 high
3 medium
0 context
MON 17 AUG 2026
vm2 — the Node.js sandbox library agent tooling still leans on to run untrusted code — took five new disclosures in one batch, three of them full escapes that bypass its own documented defenses.
8 critical
17 high
18 medium
2 context
SUN 16 AUG 2026
A rare quiet day on the supply chain front — the only new signal was a macOS infostealer bolting live browser-session hijacking onto its ClickFix playbook.
0 critical
0 high
0 medium
1 context
SAT 15 AUG 2026
A quiet Saturday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds since Tuesday.
0 critical
0 high
0 medium
0 context
FRI 14 AUG 2026
Three separate advisories landed against MCP server implementations today — a shell-injection RCE and an unauthenticated path traversal in the same npm MCP tool, plus a DNS-rebinding SSRF bypass in an MCP gateway.
0 critical
7 high
5 medium
0 context
THU 13 AUG 2026
The AI-agent stack disclosed four unrelated bugs in one day, and a backfilled Metabase KEV entry hits its federal patch deadline tomorrow.
3 critical
6 high
7 medium
0 context
TUE 11 AUG 2026
1 critical
2 high
0 medium
1 context
MON 10 AUG 2026
Two unrelated ecosystems — VS Code extensions and WordPress plugins — got hit by the same trick today: poison the trusted side-channel a package polls, not the package itself.
2 critical
0 high
0 medium
0 context
SUN 09 AUG 2026
A rare quiet Sunday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds in the last six hours.
0 critical
0 high
0 medium
0 context
SAT 08 AUG 2026
Six coordinated GitPython option-injection RCEs and a four-bug CodeIgniter batch dropped the same day Coinspect confirmed a six-year-old crypto-js weak-RNG bug has been silently seeding real wallets.
3 critical
11 high
14 medium
2 context
FRI 07 AUG 2026
A near-800-package npm dropper campaign lands the same day CodeIgniter ships two critical RCE-class bugs and CISA fast-tracks a LoadMaster command-injection KEV add.
4 critical
12 high
8 medium
4 context
THU 06 AUG 2026
Traefik's auth-bypass batch and Craft CMS's password-reset-to-RCE chain anchored the day, then a late PHP_CodeSniffer CI command injection and a pdf.js scripting bug closed it out.
2 critical
5 high
2 medium
1 context
WED 05 AUG 2026
A KEV-listed TeamCity RCE and a critical unauthenticated Nuxt DevTools RCE bookend a day otherwise dominated by GHSA clearing a massive disclosure backlog across Ghost, Electron, Nuxt, and rclone.
2 critical
5 high
3 medium
1 context
TUE 04 AUG 2026
A self-propagating npm worm tore through the keyv and cacheable namespaces the same day GHSA published Flowise's entire disclosure backlog — 23 CVEs — plus a fresh six-bug Open WebUI batch, making it open season on AI-agent tooling.
14 critical
20 high
2 medium
1 context
MON 03 AUG 2026
A three-month-old, still-live RAT campaign targeting Alibaba's internal npm tooling surfaced the same day two dozen disclosures landed across Python, PHP, JavaScript, and Rust — three of them the same host-parsing bug independently rediscovered in Guzzle, ip-address, and fast-uri.
3 critical
14 high
15 medium
1 context
SUN 02 AUG 2026
All three passes today came back empty — no new CISA KEV entries, no in-scope GHSA disclosures, and nothing from the active-campaign feeds — a hard stop after yesterday's ApostropheCMS authorization-bypass bug.
0 critical
0 high
0 medium
0 context
SAT 01 AUG 2026
A single prototype-pollution bug in ApostropheCMS quietly disables every authorization check on the platform — the sharpest edge in an otherwise broad day of input-trust failures across CMS, payment, and infrastructure tooling.
1 critical
8 high
12 medium
2 context
FRI 31 JUL 2026
A live ad-script supply chain attack is siphoning cryptocurrency from every site running Adform's tags, landing the same day as five critical disclosures — a CMS, a low-code platform, a Kubernetes admission webhook, a game-hosting daemon, and AWS Amplify — plus a late-arriving second and third Apostrophe advisory showing the CMS's trust-boundary problem wasn't a one-off.
6 critical
6 high
6 medium
2 context
THU 30 JUL 2026
A default-config Rails RCE and a six-CVE meltdown in an AI workflow framework landed the same day Amazon confirmed North Korea authored last year's record npm hijack.
3 critical
12 high
8 medium
10 context
WED 29 JUL 2026
swagger-typescript-api became today's spec-to-RCE story: six advisories show a hostile OpenAPI document can inject code into its own generated client, echoing yesterday's datamodel-code-generator pile-up almost exactly one day later.
3 critical
12 high
7 medium
2 context
TUE 28 JUL 2026
The day's headline event stayed datamodel-code-generator's eleven-advisory pile-up, but a late batch after First Watch pushed goshs to five separate advisories in one day and added an unrelated critical SQL injection in @hypequery/clickhouse — 21:00 didn't mean the day was done.
7 critical
31 high
14 medium
5 context
MON 27 JUL 2026
0 critical
1 high
0 medium
0 context
SUN 26 JUL 2026
The only story of the day was a defensive one — GitHub and PyPI shipped a built-in cooldown window for Dependabot, and nothing else moved.
0 critical
0 high
1 medium
0 context
SAT 25 JUL 2026
The day's shape is the partial fix — GitPython and Pheditor both got hit again by the same bug class a prior patch was supposed to have closed, while six other platforms dropped chained multi-CVE batches in a single shot.
5 critical
28 high
16 medium
1 context
FRI 24 JUL 2026
A fourth critical landed after First Watch — npm shell-escaping library Shescape ships its own shell-injection bypass on Windows CMD — capping a day that already saw seven criticals across Budibase and OpenAM/OpenDJ.
8 critical
18 high
5 medium
3 context
THU 23 JUL 2026
Two Auth.js advisories that can silently disable authentication anchor a day otherwise dominated by open redirects and memory-exhaustion bugs — React Router's four-advisory redirect-hardening batch, a paired pypdf infinite-loop fix, and a fresh PHPSpreadsheet SSRF bypass — with nothing yet confirmed under active attack.
2 critical
8 high
9 medium
2 context
WED 22 JUL 2026
Late escalation at 21:00 ET: a fourth disclosure wave — 50 more advisories spanning a second n8n batch plus first-time appearances from Next.js, Eclipse Jetty, JupyterLab, and LiteLLM — landed within 75 minutes of the day's 18:00 synthesis, pushing the day's total past 135 items and its high-severity count past 55.
5 critical
56 high
62 medium
1 context
TUE 21 JUL 2026
A single coordinated disclosure dropped 21 Gitea advisories in about two hours — four critical, including a Docker image default that hands any network attacker admin — on top of a KEV day already carrying a live WordPress SQLi-to-RCE chain.
8 critical
26 high
12 medium
5 context
MON 20 JUL 2026
A same-day GHSA wave that ran from 6pm to past 9pm ET eventually reached 90 advisories, overshadowing SleeperGem's quiet RubyGems hijack — headlined by a critical node-tar bug reachable through every npm install, a Composer bug that lets a malicious transitive dependency write files outside vendor/, and a second, equally large round of Pillow, Axios, and .NET disclosures that landed after First Watch had already gone to print.
4 critical
38 high
44 medium
7 context
SUN 19 JUL 2026
SleeperGem's dormant-maintainer-account hijack on RubyGems was the day's lone confirmed supply-chain hit, on an otherwise quiet Sunday.
1 critical
0 high
0 medium
1 context
SAT 18 JUL 2026
The only development on an otherwise silent Saturday was ACR Stealer's ClickFix campaign graduating from a researcher writeup to a vendor-confirmed, enterprise-scale surge.
0 critical
1 high
0 medium
0 context
FRI 17 JUL 2026
A blockchain-controlled npm campaign returns as ViteVenom, while five unrelated projects each shipped a patch that admitted its first fix missed the vulnerability's sibling path.
2 critical
22 high
22 medium
5 context
THU 16 JUL 2026
A trojanized-installer campaign, a self-propagating npm worm, and two same-day CISA KEV adds converged today — each one weaponizing a channel defenders trust by default.
4 critical
6 high
0 medium
3 context
WED 15 JUL 2026
MantisBT's zero-password admin takeover held the day's top story, but a 9pm wave of 22 GHSA advisories — a six-language Datadog tracer DoS, a Rails ViewComponent XSS bypass, and a django-haystack eval() RCE — pushed the day's high-severity count past 30.
3 critical
32 high
25 medium
6 context
TUE 14 JUL 2026
A pile-up day: four new FacturaScripts advisories, three same-root-cause Anyquery RCE-class bugs, and three separate MCP-server disclosures landed alongside two live GitHub/npm impersonation campaigns and four newly-confirmed CISA KEV exploits.
12 critical
22 high
17 medium
0 context
MON 13 JUL 2026
A late 21:00 ET wave adds two more confirmed-exploitable criticals — a hardcoded Docker default secret enabling Kimai account takeover and a brute-forceable FacturaScripts 2FA bypass — on top of a day that already carried a newly-exploited legacy Cisco IOS bug, DIRAC's double eval()-to-RCE disclosure, and day three of the unresolved jscrambler npm infostealer.
5 critical
4 high
2 medium
8 context
SUN 12 JUL 2026
A rare all-quiet stretch: three straight passes today turned up nothing new, leaving yesterday's jscrambler MCP-credential infostealer as the only thread still worth chasing.
0 critical
0 high
0 medium
0 context
SAT 11 JUL 2026
A compromised jscrambler npm release spent three hours mutating past its own install-hook detection while its Rust infostealer went straight for Claude Desktop, Cursor, and other MCP server credentials.
1 critical
0 high
0 medium
0 context
FRI 10 JUL 2026
A second coordinated multi-CVE batch — seven SiYuan advisories with three independent RCE chains — landed hours after this morning's YesWiki disclosure, while a compromised Injective Labs GitHub repo pushed a wallet-draining npm package into the wild.
15 critical
25 high
26 medium
2 context
THU 09 JUL 2026
Late escalation at 21:00 ET: a fresh GHSA batch lands three more high-severity disclosures — header-leak and memory-exhaustion bugs across Elixir's two workhorse HTTP clients, Tesla and Mint — on top of a day already shaped by a three-ecosystem wallet/payment-credential wave and a 13-advisory YesWiki teardown.
6 critical
13 high
14 medium
0 context
WED 08 JUL 2026
Five unrelated AI-agent and MCP-adjacent tools — Langflow, Open WebUI, ha-mcp, ckan-mcp-server, and Serena — disclosed authorization or authentication gaps on the same day, the clearest sign yet that agentic tooling is shipping with the auth debt web frameworks paid off a decade ago.
8 critical
9 high
13 medium
3 context
TUE 07 JUL 2026
2 critical
7 high
5 medium
3 context
MON 06 JUL 2026
Zebra disclosed a CVSS-9.3 soundness bug in Zcash's Orchard shielded-pool circuit at 21:00 ET, a late critical escalation onto a day that had already produced four separate critical dev-and-agent-tooling disclosures.
4 critical
5 high
0 medium
0 context
SUN 05 JUL 2026
Nothing broke: no new CISA KEV entries, no GHSA advisories in scope, and no active-campaign writeups from Socket, Phylum, Hacker News, BleepingComputer, or Aikido across all three passes today.
0 critical
0 high
0 medium
0 context
SAT 04 JUL 2026
The DPRK-linked PolinRider campaign is now up to 108 malicious packages and browser extensions across four ecosystems, and it's the only story of the day — KEV, GHSA, and the rest of the RSS feeds stayed quiet.
1 critical
0 high
0 medium
0 context
FRI 03 JUL 2026
Six unrelated open-source projects each shipped a coordinated multi-CVE batch today, from Steeltoe's seven advisories to Zebra's twelve, while the MCP-gateway trust-boundary bug count for the week climbed to four.
9 critical
15 high
2 medium
1 context
THU 02 JUL 2026
Six unrelated MCP and agent-gateway projects disclosed authorization or credential-handling bugs in the same 24 hours, making the agent-tooling trust boundary — not any single campaign — today's story.
8 critical
13 high
5 medium
2 context
WED 01 JUL 2026
A North Korea-linked campaign expanded to a fourth ecosystem and Rancher, SurrealDB, and Sigstore all dropped mass-disclosure batches — then, in the final hour before bed, two more high-severity credential-leak bugs landed in an Apify MCP server and a Postgres SCRAM client.
5 critical
12 high
5 medium
1 context
TUE 30 JUN 2026
A live PyPI backdoor campaign, a coordinated node-escape pileup in Fission's serverless platform, and an SSRF in Sigstore's signing CA hit every layer from registry to trust root on the same day.
2 critical
4 high
2 medium
2 context
MON 29 JUN 2026
Infostealers keep arriving through trusted channels — hijacked npm/Go packages, a KEV-listed SimpleHelp auth bypass, and a late wave of clipboard-stealing browser extensions — while OpenAM and Dgraph patch server-side identity and injection flaws.
2 critical
5 high
1 medium
1 context
SUN 28 JUN 2026
A quiet day on the registries threw the week's real shift into relief: both of today's disclosures weaponize the AI coding agent's auto-trusted setup surface — repo configs and MCP definitions — rather than any poisoned package.
0 critical
2 high
1 medium
1 context
SAT 27 JUN 2026
The Miasma worm crossed from npm into Backstage's GitLab and LDAP auth plugins, Polymarket lost roughly $3M to a poisoned frontend, and a wave of disclosures — Nezha, pnpm, Hackney, ex_aws_sns — all rhymed on one flaw: trusting attacker-controlled input as authorization.
4 critical
8 high
5 medium
1 context
FRI 26 JUN 2026
A self-replicating npm worm jumped to its third package set and a poisoned PyPI wheel harvested the same credentials by other means — then a late coordinated pnpm disclosure turned the package manager itself into the attack surface.
5 critical
10 high
6 medium
3 context
THU 25 JUN 2026
A late coordinated disclosure cracks the golang.org/x/crypto/ssh stack open — a CVSS-10 public-key auth bypass and five more critical SSH/agent flaws — onto a day already defined by Shai-Hulud crossing into Go and OpenAM's five-way collapse.
7 critical
9 high
3 medium
4 context
WED 24 JUN 2026
Three CVSS-10 RCEs opened the day; a chainable pair of pre-auth OpenAM criticals closed it, making the identity stack the story two days running.
5 critical
9 high
3 medium
1 context
TUE 23 JUN 2026
Identity infrastructure took the brunt — pre-auth RCE in OpenDJ, pre-auth XSS and LDAP injection in OpenAM, and LastPass breached through stolen OAuth tokens — while npm typosquats dropped a Windows RAT, CISA logged four exploited appliance flaws, and a late Snipe-IT disclosure batch added a cross-tenant data injection after the bell.
4 critical
7 high
2 medium
1 context
MON 22 JUN 2026
The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.
3 critical
4 high
0 medium
1 context
SUN 21 JUN 2026
A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.
0 critical
0 high
1 medium
0 context
SAT 20 JUN 2026
Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.
2 critical
7 high
10 medium
4 context
FRI 19 JUN 2026
The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.
5 critical
21 high
14 medium
0 context
THU 18 JUN 2026
AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.
15 critical
13 high
39 medium
2 context
WED 17 JUN 2026
The AI development toolchain became the supply chain: two live npm and IDE credential-theft campaigns landed alongside a flood of fresh advisories against the self-hosted LLM stack.
3 critical
23 high
1 medium
2 context
TUE 16 JUN 2026
The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.
10 critical
22 high
5 medium
4 context
MON 15 JUN 2026
A live CDN supply-chain attack on three widely-deployed WordPress plugins headlines a day of dev-tooling RCE and fresh CISA KEV adds.
4 critical
5 high
0 medium
1 context
SUN 14 JUN 2026
A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.
0 critical
0 high
0 medium
1 context
SAT 13 JUN 2026
The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.
0 critical
12 high
22 medium
1 context
FRI 12 JUN 2026
Four hundred-plus Arch AUR packages are poisoned with an infostealer and eBPF rootkit on the same day Budibase, TYPO3 and File Browser ship coordinated emergency mass-patches.
4 critical
26 high
26 medium
2 context
THU 11 JUN 2026
npm moves to disarm install scripts on the same day a supply-chain worm's source code leaks and PDM lands its second code-execution flaw — the install-time attack surface is the whole story.
6 critical
13 high
3 medium
3 context
WED 10 JUN 2026
CISA KEV deadlines for TanStack and Nx Console land today as Miasma's source code briefly leaks on GitHub and a new supply-chain vector — malicious MCP server config in pull requests — puts Claude Code Action CI pipelines at risk of secret exfiltration.
4 critical
12 high
12 medium
5 context
TUE 09 JUN 2026
A late GHSA wave after 18:00 ET delivered unauthenticated RCE in PhoenixStorybook and a connector-ACL bypass in Dex, extending a day already shaped by the Shai-Hulud PyPI worm campaign and five CISA KEV additions.
10 critical
7 high
3 medium
3 context
MON 08 JUN 2026
A 21:00 ET KEV addition dropped a command-injection RCE in the open-source LiteLLM gateway onto the actively-exploited list — capping a day already shaped by two ransomware-linked developer-toolchain compromises, Nx Console and TanStack.
4 critical
4 high
2 medium
2 context
SUN 07 JUN 2026
The disclosure feeds went silent for the weekend, leaving one story standing: Miasma opened a Python propagation arm — 37 malicious PyPI wheels that execute on interpreter start, no import required.
1 critical
0 high
0 medium
0 context
SAT 06 JUN 2026
The Miasma worm crossed from npm into Microsoft's own GitHub estate — 73 repositories disabled across four organizations — while DbGate disclosed an unauthenticated CVSS-10 RCE.
3 critical
6 high
5 medium
4 context
FRI 05 JUN 2026
IronWorm's npm campaign doubles to 50-plus poisoned packages and picks up a self-spreading worm and a kernel rootkit, while CISA's KEV clock runs out on a Magento RCE tonight.
6 critical
6 high
2 medium
2 context
THU 04 JUN 2026
Two self-propagating npm worms hit the registry the same day a triple-critical SSTI flaw turns Jupyter's Kubernetes gateway into full cluster takeover.
3 critical
9 high
6 medium
2 context
WED 03 JUN 2026
A public VS Code / github.dev one-click token steal and a triple-critical RCE chain in Jupyter Enterprise Gateway land in the same 48-hour window CISA pushes four bugs to the KEV catalog and Wordfence logs hundreds of active hits on Kirki.
7 critical
3 high
2 medium
3 context
TUE 02 JUN 2026
Two Vitest CVEs, six praisonai IDORs, and a conda write-anywhere push developer tooling into the day's attack surface while CISA stacks three KEV adds on top.
5 critical
2 high
1 medium
2 context
MON 01 JUN 2026
Mini Shai-Hulud lands inside Red Hat's official npm scope — the trusted-vendor namespace compromise the ecosystem has been preparing for since last summer.
4 critical
6 high
2 medium
5 context
SUN 31 MAY 2026
DPRK's Contagious Interview crew ports its npm playbook to PHP, dropping malware in a Packagist-listed package on an otherwise quiet KEV-burndown Sunday.
2 critical
2 high
1 medium
2 context
SAT 30 MAY 2026
Developers are the day's target — a Ghost CMS RCE has backdoored 700+ tech and university sites into ClickFix droppers, CISA hands PAN-OS a 72-hour patch clock, and another AI-coding CLI ships with implicit working-directory trust.
2 critical
2 high
5 medium
1 context
FRI 29 MAY 2026
Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.
3 critical
9 high
8 medium
2 context
THU 28 MAY 2026
A Sicoob banking-SDK impersonator on NuGet exfiltrates client certs through Sentry, the Symfony tranche tops twenty advisories, and a late-evening paired Dulwich disclosure revives the NTFS-hostile-tree-entry class on Windows.
4 critical
17 high
8 medium
2 context
WED 27 MAY 2026
CISA closes the day with KEV adds for Nx Console and TanStack — turning the npm credential-stealing wave into a federal-mandate clock — while Yamcs hands aerospace operators two critical mission-control RCEs.
10 critical
19 high
10 medium
1 context
TUE 26 MAY 2026
Late escalation at 21:00 ET adds a Yamcs algorithm-engine RCE, three pre-auth RCEs in FUXA, and a path traversal in the npm `tmp` transitive dep on top of the day's XWiki and LiteSpeed criticals.
5 critical
11 high
4 medium
4 context
MON 25 MAY 2026
Monday after the storm: TrapDoor's narrative spreads while two Defender CVEs land on the KEV list.
0 critical
0 high
2 medium
4 context
SUN 24 MAY 2026
Four concurrent package-poisoning campaigns hit the registries at once.
13 critical
4 high
1 medium
3 context