Security news.
Today's security landscape is heavily influenced by supply chain attacks, with multiple reports detailing malicious activity targeting developer tools and package managers. Additionally, new and actively exploited vulnerabilities in network devices and critical infrastructure are being addressed, alongside ongoing concerns about AI's role in advancing cyberattacks and defensive strategies.
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named 'ChainDrop' has compromised over 1,300 packages with 2 billion monthly downloads on the npm registry.
Keyv-Linked npm Worm Poisons Hundreds of Packages
A credential-stealing npm worm, initially found in [email protected], has spread to hundreds of packages across multiple organizations.
New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
77 Open VSX extensions found harvesting developer info
Over seventy extensions on the Open VSX marketplace were found impersonating legitimate developer tools and transmitting system and development environment information.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added CVE-2026-9198 (IBM Langflow), CVE-2026-18556 (N-able N-central), and CVE-2026-34486 (Apache Tomcat) to its KEV Catalog, citing active exploitation.
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched CVE-2026-58048 (CVSS 9.4), a critical flaw allowing authenticated hosting customers to execute SQL in the database's root context.
TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover
Forescout researchers discovered 15 new vulnerabilities in the TP-Link Omada networking ecosystem that can be chained for a full network takeover.
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Researchers have found three attacks enabling malware on compromised Windows devices to abuse Google Password Manager's synced passkeys for account takeover and private key extraction.