🚨 BREAKING: More than 400 Arch Linux User Repository packages have been compromised with infostealer malware and a rootkit.
Attacker posed as a trusted maintainer and "adopted" orphaned packages.
Arch maintainers are purging infected packages now. Audit your AUR installs.
🚨 CVE-2026-0257, a PAN-OS and Prisma Access authentication bypass flaw, is under active exploitation.
The CVSS 7.8 bug can enable unauthorized VPN access and, in some observed cases, access to internal networks.
Patch immediately or apply mitigations.
Details: https://t.co/BlECtBGWR1
UPDATE: So far we've identified 639 compromised npm package versions across 323 unique packages in tonight’s Mini Shai-Hulud wave.
That includes 558 versions across 279 unique @antv packages. Most were detected within ~6 minutes of publication.
https://t.co/JXJK1NT4dp
Here is the list of every school district, college, and university impacted by the ShinyHunter's Canvas compromise. It is nearly indeed over 9,000 schools because it includes entire school districts.
Here is a list of every place currently impacted:
https://t.co/E9wCXYGczw
🚨 12 vulnerabilities in the vm2 Node.js library enable sandbox escape and arbitrary code execution.
Flaws (CVSS up to 10.0) affect versions up to 3.11.1; patches released through 3.11.2.
Read the full story: https://t.co/1AIOjXp53f
UNC6692 is impersonating IT helpdesk employees on Microsoft Teams to deploy custom malware.
The SNOW ecosystem (SNOWBELT, SNOWGLAZE, SNOWBASIN) enables deep network penetration and exfiltration. Read the analysis and get indicators of compromise.
➡️ https://t.co/vnHZVuNWi2
🚨 73 VS Code extensions flagged as malicious.
Researchers say some are sleeper packages that later update to steal data and install backdoors across developer tools.
🔗 Full details: https://t.co/ZIEGP2uact
CISA has ordered U.S. federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.
https://t.co/isROAzx5Az