The Mini Shai-Hulud campaign compromised more than 170 reported npm and PyPI packages, exposing how trusted publishing and provenance can still be abused when CI/CD environments are compromised.
Latest news
Latest cybersecurity dispatches
Fresh reporting on active vulnerabilities, security patches, incident response, and threat research for defenders.
Mini Shai-Hulud Worm Exposes Limits of Trusted Publishing After 170+ npm and PyPI Packages Hit
NGINX “Rift” Rewrite Module Flaw Confirmed as CVE-2026-42945
CVE-2026-42945 is now tracked as a heap-based buffer overflow in NGINX's rewrite module, affecting NGINX Open Source and NGINX Plus under specific rewrite-rule conditions.
Microsoft Confirms Exploited Exchange OWA Vulnerability as CVE-2026-42897
Microsoft has disclosed CVE-2026-42897, a high-severity Exchange Server Outlook Web Access vulnerability affecting on-premises deployments, with mitigation available while a permanent fix is pending.
Cisco Patches Critical SD-WAN Zero-Day Exploited by Sophisticated Threat Actor
Cisco patched CVE-2026-20182, a critical Catalyst SD-WAN Controller and Manager zero-day that can let remote attackers bypass authentication and manipulate SD-WAN fabric configuration.