Microsoft has identified a npm supply chain compromise impacting 90+ redhat-cloud-services/* packages, including patch-client 4.0.4, insights-client 4.0.4, rbac-client 9.0.3, host-inventory-client 5.0.3, frontend-components 7.7.2, and others. The payload is a self-propagating worm that infects other npm packages and self-publishes.
Each compromised package adds a malicious preinstall hook, embedding an index.js script in the package.json that silently executes “node index.js” during installation, downloads Bun, and runs a payload that steals secrets from npm, GitHub, Amazon Web Services (AWS), and Secure Shell (SSH). The added code bloats index.js from ~8KB to ~4.3MB, acting as a heavily obfuscated ROT-9 eval loader.
If any of the compromised packages are installed, users and organizations should assume compromise, rotate credentials, revert to a previously trusted version, and block compromised packages. Identified compromised npm packages have been taken down, and we continue to work with the npm team. Microsoft continues to investigate this attack and will publish updates as more information is available.
Found a cool bug at Meta.
From misconfigured Grafana instance to R/W access on 507 private Meta repositories.
Wrote up the full chain here:
https://t.co/LYQ0prc68d
$157k bounty awarded by @metabugbounty
We just released a new article on how we made more than 50,000$ in #BugBounty by doing a really cool Software Supply Chain Attack🔥
🔗 https://t.co/wDYdgWYbut
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. https://t.co/RSrRtIhgaV
Hello @Burp_Suite, after this new update, why does Burp show these pop-ups every time I open it?
I know I'm using the Community Edition, and I want to keep using the Community Edition. Please don't force users to buy the Professional version.
Thanks
Next.js v16.2.5 fixes a bunch of vulnerabilities reported by @HacktronAI.
Patch ASAP, especially if you’re running self-hosted Next.js that SSRF might affect you
CVE-2026-44574: Middleware / Proxy bypass via dynamic route parameter injection
CVE-2026-44578: SSRF in applications using WebSocket upgrades
CVE-2026-44581: XSS in App Router applications using CSP nonces
1 months ago I've discovered a critical vulnerability in @MezoNetwork's AssetsBridge precompile which could have led to a direct theft of $1,753,958.4 ($40m if no ratelimit).
happy to share the security advisory (includes full report + PoC) and mezo post-mortem write-up.
https://t.co/HrwTU95Duj
I'm also planning to post soon an X article about this finding which will include much more context on my journey and this discovery.
Microsoft Defender detected and protected customers against a new software supply chain compromise affecting the "pytorch-lightning" package and immediately reported the issue to the repository maintainers for takedown: https://t.co/yZsFqek0Cr.
At the time the compromised packages were identified and distributed, Microsoft Defender had proactive detections that blocked the malicious files as Trojan:JS/ShaiWorm.DQ!MTB. For protected environments, Microsoft Defender for Endpoint raised the alert "ShaiWorm malware was prevented".
Our assessment indicates that Microsoft continues to provide strong protection coverage and has prevented observed activity indicating attempts to install the modified packages. Microsoft Defender continues to monitor for potential follow-on activity, including suspicious use of potentially exposed cloud credentials across major cloud platforms.
Observed activity remains limited to a small number of devices and appear contained to a narrow set of environments. We are also investigating container-based telemetry and registry-related signals that may indicate potential compromise in some scenarios.
Microsoft continues to monitor and investigate the issue, with layered protections, broad prevention coverage, and ongoing hunting efforts in place. We will share updates as more information becomes available.
Ever wondered how hackers use AI? 🤖
We wrote a guide mapping the current landscape of AI-enhanced hacking.
What else should we cover? 👇: https://t.co/EkY4YHwgXm
to celebrate the release of Copy Fail and the professional way the embargo and disclosure was handled by all involved parties i have sacrificed my lunchbreak to do a quick C port (with aarch64 support and some other small things) of the original PoC
https://t.co/M08QEqVEwo