120 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.
MON 21 SEP 2026
A fake LastPass installer, a $10.71M North Korean crypto campaign, and a runtime-evasive npm dropper all point the same direction: developer trust is this week's attack surface.
2 critical
5 high
2 medium
2 context
SUN 20 SEP 2026
A single npm campaign, 'indexed-btree', confirms attackers have moved malicious payloads out of install scripts and into runtime code to dodge the defenses built for the last wave.
1 critical
0 high
0 medium
0 context
SAT 19 SEP 2026
MCP's trust-the-localhost design flaw hit five projects in one day — and on the KEV list, LiteLLM's version of the bug is already being exploited in the wild.
5 critical
16 high
4 medium
10 context
FRI 18 SEP 2026
CISA catalogs a third actively-exploited Linux kernel bug in one day as three unrelated npm stealer campaigns and a five-advisory wave of MCP-tooling disclosures round out a packed Friday.
5 critical
7 high
1 medium
2 context
THU 17 SEP 2026
One stolen Cloudflare key weaponized Brevo's own widgets against 100,000+ customer sites, while Grav CMS absorbed a single-day, twenty-one-CVE disclosure spanning zip-upload RCE to leaked 2FA secrets.
7 critical
34 high
28 medium
6 context
WED 16 SEP 2026
Late escalation: djust's auth-boundary collapse grew from eight CVEs to twelve after First Watch locked the day's shape, the worst a WebSocket/SSE mount path that lets an unauthenticated client force the server to import and run any Python module by name — RCE-by-proxy — while rmcp, the Rust MCP SDK, separately disclosed an unauthenticated session-leak DoS and an OAuth flaw that lets a malicious MCP server steal access tokens.
9 critical
24 high
9 medium
1 context
TUE 15 SEP 2026
A same-day GHSA publish run hit two very different corners of the stack at once: an MCP server used for agent-assisted GitLab access got a token-stealing SSRF pair, and http4s's Ember backend took its second HTTP-smuggling/DoS batch in three weeks.
4 critical
1 high
1 medium
1 context
MON 14 SEP 2026
Authentication, not package registries, was today's weak link: CISA gave Cisco's Secure Email Gateway a three-day patch deadline while ESPHome's dashboard silently lost its login on upgrade and ZITADEL shipped two identity-platform fixes of its own.
2 critical
1 high
1 medium
6 context
SUN 13 SEP 2026
A genuinely quiet evening — the only two items are a Microsoft disclosure about trusted-infrastructure phishing and a CVE catching up to an already-known China-linked backdoor campaign, with nothing new hitting npm, PyPI, or CISA's KEV list today.
0 critical
0 high
0 medium
2 context
SAT 12 SEP 2026
An active Artifactory-to-backdoor campaign and a fresh Chromium KEV entry set today's operational bar, while Shopper's “fixed” authorization bug keeps spawning siblings and RubyGems' spring campaign turns out to have been run by an AI agent swarm.
2 critical
5 high
4 medium
0 context
FRI 11 SEP 2026
CISA confirms the JFrog Artifactory campaign and adds ConnectWise ScreenConnect and GitLab CE/EE to KEV, a CVSS-10 MCP server bug and a hardcoded Central Dogma secret round out the evening, and a late CVSS-9.1 prototype-pollution bug in npm's yayson pushes the day past bedtime.
7 critical
3 high
1 medium
1 context
THU 10 SEP 2026
Two rclone advisories disclosed after First Watch show its S3 and RC auth-proxy checks can be bypassed outright, escalating a day that already had an unauthenticated RCE in OmniRoute and two new MikroTik KEV entries.
4 critical
12 high
1 medium
0 context
WED 09 SEP 2026
CISA's twin KEV adds for Citrix NetScaler and Cisco's firewall manager — both under three-day patch clocks — remain tonight's top priority, even after a late-evening batch of nine high-severity GHSA disclosures, including an MCP-server RCE and a LAN-exposed ESPHome dashboard, pushed the day's high count past every other evening this series has logged.
4 critical
22 high
15 medium
0 context
TUE 08 SEP 2026
Next.js and Astro's shared libheif AVIF RCE anchored the day, but CISA's evening KEV add of a pre-auth RCE in N-able N-central — MSP tooling with Kaseya-class blast radius — is the story that matters most before you log off.
9 critical
5 high
0 medium
1 context
MON 07 SEP 2026
A 111-day-dormant Shai-Hulud payload walked straight past npm's malware scanner today, the same day Adobe's unpatched Magento zero-day was confirmed dropping a disguised Rust backdoor on live stores.
2 critical
0 high
0 medium
3 context
SUN 06 SEP 2026
A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.
0 critical
0 high
1 medium
1 context
SAT 05 SEP 2026
A live, unauthenticated, patch-less Magento zero-day landed the same afternoon a Switchvox KEV hit its remediation deadline — one bug you can still fix, one you can only shield.
2 critical
0 high
0 medium
0 context
FRI 04 SEP 2026
A last-minute KEV add stole the night from the AI-agent story — CISA confirmed active exploitation of a Chromium V8 type-confusion bug just as GPT-6 Astra and eight CodeWhale approval-bypass CVEs showed agents landing on both sides of the supply chain today.
3 critical
5 high
1 medium
0 context
THU 03 SEP 2026
SiYuan's publish-mode disclosures kept escalating after First Watch and capped the night with an unauthenticated, stored SQL injection reachable from a saved document title.
4 critical
5 high
2 medium
0 context
WED 02 SEP 2026
A late four-CVE OpenChoreo disclosure — headlined by an unauthenticated cluster-gateway bypass — landed alongside a second Omnigent guardrail failure, turning today's AI-agent execution-layer story into a platform-trust story before midnight.
9 critical
39 high
36 medium
1 context
TUE 01 SEP 2026
A grind of a disclosure day — pnpm, browserslist, MLflow, and Filament all shipped fixes for install- and load-time supply-chain primitives, but no new active campaign or CISA KEV entry landed to go with them.
1 critical
11 high
7 medium
2 context
MON 31 AUG 2026
A pre-auth PaperCut RCE chain still owns tonight's operational priority, but a Kirby CMS security release landing after First Watch — two high-severity fixes for an auth'd storage-exhaustion bug and an encoded-slash path traversal — escalated the day's disclosure count late.
1 critical
4 high
3 medium
2 context
SUN 30 AUG 2026
The registries went quiet today, but the same commodity infostealers behind this month's ClickFix wave turned up draining Claude session cookies instead of crypto wallets.
0 critical
0 high
0 medium
2 context
SAT 29 AUG 2026
Spoofable client headers undo access control in three unrelated projects today, while Plone takes the day's only critical slot with a matched pair of import-triggered SSRF/DoS/XSS bugs.
1 critical
10 high
7 medium
0 context
FRI 28 AUG 2026
A Shai-Hulud-style npm worm hit a widely-used TanStack Query codegen package with valid provenance attestations, Pimcore shipped five same-day advisories chaining editor access to server RCE, and a late GHSA batch added a RestrictedPython sandbox-guard bypass and a SeaweedFS bucket-isolation break.
2 critical
9 high
5 medium
5 context
THU 27 AUG 2026
Today's fault lines run through the machinery meant to guarantee package integrity — a signature-verification bypass in Crossplane and a path-traversal KEV add in JFrog Artifactory — even as Australian police close the book on March's scanner-compromise campaign.
3 critical
3 high
4 medium
1 context
WED 26 AUG 2026
A live PyPI credential-stealer campaign and an unauthenticated LIMS RCE land the same day the MCP-tooling ecosystem's trust-boundary bug spreads to a seventh project.
3 critical
21 high
5 medium
6 context
TUE 25 AUG 2026
The MCP server ecosystem had its worst disclosure day yet: a dozen-plus agent-tooling projects — PraisonAI, Chainlit, mcp-shell, utcp, qwed-mcp, and more — dropped auth-bypass, SSRF, or RCE advisories within hours of each other.
7 critical
15 high
2 medium
2 context
MON 24 AUG 2026
CISA's KEV add for an actively-exploited Oracle proxy flaw anchored a day otherwise defined by broken authorization logic — cached-state bypasses, missing ownership checks, and unconfined admin inputs — across CMS, LMS, and proxy-panel software.
1 critical
4 high
7 medium
2 context
SUN 23 AUG 2026
A dark board: three passes, three feeds, zero items that cleared the bar.
0 critical
0 high
0 medium
0 context
SAT 22 AUG 2026
A day light on new disclosures narrowed to a single story: a BADBOX-linked group turned automotive Android head-unit firmware into a residential proxy botnet.
0 critical
1 high
0 medium
0 context
FRI 21 AUG 2026
A late-evening dump of four unrelated critical RCEs — JSONata, Xinference, Phalcon, and GeoTools — landed alongside a fresh npm backdoor campaign and a newly-KEV'd Zimbra pre-auth command injection.
7 critical
9 high
8 medium
0 context
THU 20 AUG 2026
A compromised crates.io maintainer account slipped a build-time payload into three widely used Rust crates — the same postinstall-dropper playbook that's hit npm repeatedly this year, now proven out in Cargo.
3 critical
18 high
8 medium
1 context
WED 19 AUG 2026
Six MCP-server disclosures in one hour turned the AI-agent tooling layer into today's supply-chain story, while CISA confirmed active exploitation of an MLflow SSRF flaw.
2 critical
13 high
10 medium
1 context
TUE 18 AUG 2026
A four-vendor CISA KEV cluster — Microsoft twice, VMware, and Apple — lands the same day RubyGems' StubMaker typosquat campaign resurfaces, capped by a late LibreNMS SSRF-to-stored-XSS disclosure batch.
5 critical
5 high
3 medium
0 context
MON 17 AUG 2026
vm2 — the Node.js sandbox library agent tooling still leans on to run untrusted code — took five new disclosures in one batch, three of them full escapes that bypass its own documented defenses.
8 critical
17 high
18 medium
2 context
SUN 16 AUG 2026
A rare quiet day on the supply chain front — the only new signal was a macOS infostealer bolting live browser-session hijacking onto its ClickFix playbook.
0 critical
0 high
0 medium
1 context
SAT 15 AUG 2026
A quiet Saturday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds since Tuesday.
0 critical
0 high
0 medium
0 context
FRI 14 AUG 2026
Three separate advisories landed against MCP server implementations today — a shell-injection RCE and an unauthenticated path traversal in the same npm MCP tool, plus a DNS-rebinding SSRF bypass in an MCP gateway.
0 critical
7 high
5 medium
0 context
THU 13 AUG 2026
The AI-agent stack disclosed four unrelated bugs in one day, and a backfilled Metabase KEV entry hits its federal patch deadline tomorrow.
3 critical
6 high
7 medium
0 context
TUE 11 AUG 2026
1 critical
2 high
0 medium
1 context
MON 10 AUG 2026
Two unrelated ecosystems — VS Code extensions and WordPress plugins — got hit by the same trick today: poison the trusted side-channel a package polls, not the package itself.
2 critical
0 high
0 medium
0 context
SUN 09 AUG 2026
A rare quiet Sunday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds in the last six hours.
0 critical
0 high
0 medium
0 context
SAT 08 AUG 2026
Six coordinated GitPython option-injection RCEs and a four-bug CodeIgniter batch dropped the same day Coinspect confirmed a six-year-old crypto-js weak-RNG bug has been silently seeding real wallets.
3 critical
11 high
14 medium
2 context
FRI 07 AUG 2026
A near-800-package npm dropper campaign lands the same day CodeIgniter ships two critical RCE-class bugs and CISA fast-tracks a LoadMaster command-injection KEV add.
4 critical
12 high
8 medium
4 context
THU 06 AUG 2026
Traefik's auth-bypass batch and Craft CMS's password-reset-to-RCE chain anchored the day, then a late PHP_CodeSniffer CI command injection and a pdf.js scripting bug closed it out.
2 critical
5 high
2 medium
1 context
WED 05 AUG 2026
A KEV-listed TeamCity RCE and a critical unauthenticated Nuxt DevTools RCE bookend a day otherwise dominated by GHSA clearing a massive disclosure backlog across Ghost, Electron, Nuxt, and rclone.
2 critical
5 high
3 medium
1 context
TUE 04 AUG 2026
A self-propagating npm worm tore through the keyv and cacheable namespaces the same day GHSA published Flowise's entire disclosure backlog — 23 CVEs — plus a fresh six-bug Open WebUI batch, making it open season on AI-agent tooling.
14 critical
20 high
2 medium
1 context
MON 03 AUG 2026
A three-month-old, still-live RAT campaign targeting Alibaba's internal npm tooling surfaced the same day two dozen disclosures landed across Python, PHP, JavaScript, and Rust — three of them the same host-parsing bug independently rediscovered in Guzzle, ip-address, and fast-uri.
3 critical
14 high
15 medium
1 context
SUN 02 AUG 2026
All three passes today came back empty — no new CISA KEV entries, no in-scope GHSA disclosures, and nothing from the active-campaign feeds — a hard stop after yesterday's ApostropheCMS authorization-bypass bug.
0 critical
0 high
0 medium
0 context
SAT 01 AUG 2026
A single prototype-pollution bug in ApostropheCMS quietly disables every authorization check on the platform — the sharpest edge in an otherwise broad day of input-trust failures across CMS, payment, and infrastructure tooling.
1 critical
8 high
12 medium
2 context
FRI 31 JUL 2026
A live ad-script supply chain attack is siphoning cryptocurrency from every site running Adform's tags, landing the same day as five critical disclosures — a CMS, a low-code platform, a Kubernetes admission webhook, a game-hosting daemon, and AWS Amplify — plus a late-arriving second and third Apostrophe advisory showing the CMS's trust-boundary problem wasn't a one-off.
6 critical
6 high
6 medium
2 context
THU 30 JUL 2026
A default-config Rails RCE and a six-CVE meltdown in an AI workflow framework landed the same day Amazon confirmed North Korea authored last year's record npm hijack.
3 critical
12 high
8 medium
10 context
WED 29 JUL 2026
swagger-typescript-api became today's spec-to-RCE story: six advisories show a hostile OpenAPI document can inject code into its own generated client, echoing yesterday's datamodel-code-generator pile-up almost exactly one day later.
3 critical
12 high
7 medium
2 context
TUE 28 JUL 2026
The day's headline event stayed datamodel-code-generator's eleven-advisory pile-up, but a late batch after First Watch pushed goshs to five separate advisories in one day and added an unrelated critical SQL injection in @hypequery/clickhouse — 21:00 didn't mean the day was done.
7 critical
31 high
14 medium
5 context
MON 27 JUL 2026
0 critical
1 high
0 medium
0 context
SUN 26 JUL 2026
The only story of the day was a defensive one — GitHub and PyPI shipped a built-in cooldown window for Dependabot, and nothing else moved.
0 critical
0 high
1 medium
0 context
SAT 25 JUL 2026
The day's shape is the partial fix — GitPython and Pheditor both got hit again by the same bug class a prior patch was supposed to have closed, while six other platforms dropped chained multi-CVE batches in a single shot.
5 critical
28 high
16 medium
1 context
FRI 24 JUL 2026
A fourth critical landed after First Watch — npm shell-escaping library Shescape ships its own shell-injection bypass on Windows CMD — capping a day that already saw seven criticals across Budibase and OpenAM/OpenDJ.
8 critical
18 high
5 medium
3 context
THU 23 JUL 2026
Two Auth.js advisories that can silently disable authentication anchor a day otherwise dominated by open redirects and memory-exhaustion bugs — React Router's four-advisory redirect-hardening batch, a paired pypdf infinite-loop fix, and a fresh PHPSpreadsheet SSRF bypass — with nothing yet confirmed under active attack.
2 critical
8 high
9 medium
2 context
WED 22 JUL 2026
Late escalation at 21:00 ET: a fourth disclosure wave — 50 more advisories spanning a second n8n batch plus first-time appearances from Next.js, Eclipse Jetty, JupyterLab, and LiteLLM — landed within 75 minutes of the day's 18:00 synthesis, pushing the day's total past 135 items and its high-severity count past 55.
5 critical
56 high
62 medium
1 context
TUE 21 JUL 2026
A single coordinated disclosure dropped 21 Gitea advisories in about two hours — four critical, including a Docker image default that hands any network attacker admin — on top of a KEV day already carrying a live WordPress SQLi-to-RCE chain.
8 critical
26 high
12 medium
5 context
MON 20 JUL 2026
A same-day GHSA wave that ran from 6pm to past 9pm ET eventually reached 90 advisories, overshadowing SleeperGem's quiet RubyGems hijack — headlined by a critical node-tar bug reachable through every npm install, a Composer bug that lets a malicious transitive dependency write files outside vendor/, and a second, equally large round of Pillow, Axios, and .NET disclosures that landed after First Watch had already gone to print.
4 critical
38 high
44 medium
7 context
SUN 19 JUL 2026
SleeperGem's dormant-maintainer-account hijack on RubyGems was the day's lone confirmed supply-chain hit, on an otherwise quiet Sunday.
1 critical
0 high
0 medium
1 context
SAT 18 JUL 2026
The only development on an otherwise silent Saturday was ACR Stealer's ClickFix campaign graduating from a researcher writeup to a vendor-confirmed, enterprise-scale surge.
0 critical
1 high
0 medium
0 context
FRI 17 JUL 2026
A blockchain-controlled npm campaign returns as ViteVenom, while five unrelated projects each shipped a patch that admitted its first fix missed the vulnerability's sibling path.
2 critical
22 high
22 medium
5 context
THU 16 JUL 2026
A trojanized-installer campaign, a self-propagating npm worm, and two same-day CISA KEV adds converged today — each one weaponizing a channel defenders trust by default.
4 critical
6 high
0 medium
3 context
WED 15 JUL 2026
MantisBT's zero-password admin takeover held the day's top story, but a 9pm wave of 22 GHSA advisories — a six-language Datadog tracer DoS, a Rails ViewComponent XSS bypass, and a django-haystack eval() RCE — pushed the day's high-severity count past 30.
3 critical
32 high
25 medium
6 context
TUE 14 JUL 2026
A pile-up day: four new FacturaScripts advisories, three same-root-cause Anyquery RCE-class bugs, and three separate MCP-server disclosures landed alongside two live GitHub/npm impersonation campaigns and four newly-confirmed CISA KEV exploits.
12 critical
22 high
17 medium
0 context
MON 13 JUL 2026
A late 21:00 ET wave adds two more confirmed-exploitable criticals — a hardcoded Docker default secret enabling Kimai account takeover and a brute-forceable FacturaScripts 2FA bypass — on top of a day that already carried a newly-exploited legacy Cisco IOS bug, DIRAC's double eval()-to-RCE disclosure, and day three of the unresolved jscrambler npm infostealer.
5 critical
4 high
2 medium
8 context
SUN 12 JUL 2026
A rare all-quiet stretch: three straight passes today turned up nothing new, leaving yesterday's jscrambler MCP-credential infostealer as the only thread still worth chasing.
0 critical
0 high
0 medium
0 context
SAT 11 JUL 2026
A compromised jscrambler npm release spent three hours mutating past its own install-hook detection while its Rust infostealer went straight for Claude Desktop, Cursor, and other MCP server credentials.
1 critical
0 high
0 medium
0 context
FRI 10 JUL 2026
A second coordinated multi-CVE batch — seven SiYuan advisories with three independent RCE chains — landed hours after this morning's YesWiki disclosure, while a compromised Injective Labs GitHub repo pushed a wallet-draining npm package into the wild.
15 critical
25 high
26 medium
2 context
THU 09 JUL 2026
Late escalation at 21:00 ET: a fresh GHSA batch lands three more high-severity disclosures — header-leak and memory-exhaustion bugs across Elixir's two workhorse HTTP clients, Tesla and Mint — on top of a day already shaped by a three-ecosystem wallet/payment-credential wave and a 13-advisory YesWiki teardown.
6 critical
13 high
14 medium
0 context
WED 08 JUL 2026
Five unrelated AI-agent and MCP-adjacent tools — Langflow, Open WebUI, ha-mcp, ckan-mcp-server, and Serena — disclosed authorization or authentication gaps on the same day, the clearest sign yet that agentic tooling is shipping with the auth debt web frameworks paid off a decade ago.
8 critical
9 high
13 medium
3 context
TUE 07 JUL 2026
2 critical
7 high
5 medium
3 context
MON 06 JUL 2026
Zebra disclosed a CVSS-9.3 soundness bug in Zcash's Orchard shielded-pool circuit at 21:00 ET, a late critical escalation onto a day that had already produced four separate critical dev-and-agent-tooling disclosures.
4 critical
5 high
0 medium
0 context
SUN 05 JUL 2026
Nothing broke: no new CISA KEV entries, no GHSA advisories in scope, and no active-campaign writeups from Socket, Phylum, Hacker News, BleepingComputer, or Aikido across all three passes today.
0 critical
0 high
0 medium
0 context
SAT 04 JUL 2026
The DPRK-linked PolinRider campaign is now up to 108 malicious packages and browser extensions across four ecosystems, and it's the only story of the day — KEV, GHSA, and the rest of the RSS feeds stayed quiet.
1 critical
0 high
0 medium
0 context
FRI 03 JUL 2026
Six unrelated open-source projects each shipped a coordinated multi-CVE batch today, from Steeltoe's seven advisories to Zebra's twelve, while the MCP-gateway trust-boundary bug count for the week climbed to four.
9 critical
15 high
2 medium
1 context
THU 02 JUL 2026
Six unrelated MCP and agent-gateway projects disclosed authorization or credential-handling bugs in the same 24 hours, making the agent-tooling trust boundary — not any single campaign — today's story.
8 critical
13 high
5 medium
2 context
WED 01 JUL 2026
A North Korea-linked campaign expanded to a fourth ecosystem and Rancher, SurrealDB, and Sigstore all dropped mass-disclosure batches — then, in the final hour before bed, two more high-severity credential-leak bugs landed in an Apify MCP server and a Postgres SCRAM client.
5 critical
12 high
5 medium
1 context
TUE 30 JUN 2026
A live PyPI backdoor campaign, a coordinated node-escape pileup in Fission's serverless platform, and an SSRF in Sigstore's signing CA hit every layer from registry to trust root on the same day.
2 critical
4 high
2 medium
2 context
MON 29 JUN 2026
Infostealers keep arriving through trusted channels — hijacked npm/Go packages, a KEV-listed SimpleHelp auth bypass, and a late wave of clipboard-stealing browser extensions — while OpenAM and Dgraph patch server-side identity and injection flaws.
2 critical
5 high
1 medium
1 context
SUN 28 JUN 2026
A quiet day on the registries threw the week's real shift into relief: both of today's disclosures weaponize the AI coding agent's auto-trusted setup surface — repo configs and MCP definitions — rather than any poisoned package.
0 critical
2 high
1 medium
1 context
SAT 27 JUN 2026
The Miasma worm crossed from npm into Backstage's GitLab and LDAP auth plugins, Polymarket lost roughly $3M to a poisoned frontend, and a wave of disclosures — Nezha, pnpm, Hackney, ex_aws_sns — all rhymed on one flaw: trusting attacker-controlled input as authorization.
4 critical
8 high
5 medium
1 context
FRI 26 JUN 2026
A self-replicating npm worm jumped to its third package set and a poisoned PyPI wheel harvested the same credentials by other means — then a late coordinated pnpm disclosure turned the package manager itself into the attack surface.
5 critical
10 high
6 medium
3 context
THU 25 JUN 2026
A late coordinated disclosure cracks the golang.org/x/crypto/ssh stack open — a CVSS-10 public-key auth bypass and five more critical SSH/agent flaws — onto a day already defined by Shai-Hulud crossing into Go and OpenAM's five-way collapse.
7 critical
9 high
3 medium
4 context
WED 24 JUN 2026
Three CVSS-10 RCEs opened the day; a chainable pair of pre-auth OpenAM criticals closed it, making the identity stack the story two days running.
5 critical
9 high
3 medium
1 context
TUE 23 JUN 2026
Identity infrastructure took the brunt — pre-auth RCE in OpenDJ, pre-auth XSS and LDAP injection in OpenAM, and LastPass breached through stolen OAuth tokens — while npm typosquats dropped a Windows RAT, CISA logged four exploited appliance flaws, and a late Snipe-IT disclosure batch added a cross-tenant data injection after the bell.
4 critical
7 high
2 medium
1 context
MON 22 JUN 2026
The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.
3 critical
4 high
0 medium
1 context
SUN 21 JUN 2026
A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.
0 critical
0 high
1 medium
0 context
SAT 20 JUN 2026
Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.
2 critical
7 high
10 medium
4 context
FRI 19 JUN 2026
The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.
5 critical
21 high
14 medium
0 context
THU 18 JUN 2026
AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.
15 critical
13 high
39 medium
2 context
WED 17 JUN 2026
The AI development toolchain became the supply chain: two live npm and IDE credential-theft campaigns landed alongside a flood of fresh advisories against the self-hosted LLM stack.
3 critical
23 high
1 medium
2 context
TUE 16 JUN 2026
The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.
10 critical
22 high
5 medium
4 context
MON 15 JUN 2026
A live CDN supply-chain attack on three widely-deployed WordPress plugins headlines a day of dev-tooling RCE and fresh CISA KEV adds.
4 critical
5 high
0 medium
1 context
SUN 14 JUN 2026
A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.
0 critical
0 high
0 medium
1 context
SAT 13 JUN 2026
The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.
0 critical
12 high
22 medium
1 context
FRI 12 JUN 2026
Four hundred-plus Arch AUR packages are poisoned with an infostealer and eBPF rootkit on the same day Budibase, TYPO3 and File Browser ship coordinated emergency mass-patches.
4 critical
26 high
26 medium
2 context
THU 11 JUN 2026
npm moves to disarm install scripts on the same day a supply-chain worm's source code leaks and PDM lands its second code-execution flaw — the install-time attack surface is the whole story.
6 critical
13 high
3 medium
3 context
WED 10 JUN 2026
CISA KEV deadlines for TanStack and Nx Console land today as Miasma's source code briefly leaks on GitHub and a new supply-chain vector — malicious MCP server config in pull requests — puts Claude Code Action CI pipelines at risk of secret exfiltration.
4 critical
12 high
12 medium
5 context
TUE 09 JUN 2026
A late GHSA wave after 18:00 ET delivered unauthenticated RCE in PhoenixStorybook and a connector-ACL bypass in Dex, extending a day already shaped by the Shai-Hulud PyPI worm campaign and five CISA KEV additions.
10 critical
7 high
3 medium
3 context
MON 08 JUN 2026
A 21:00 ET KEV addition dropped a command-injection RCE in the open-source LiteLLM gateway onto the actively-exploited list — capping a day already shaped by two ransomware-linked developer-toolchain compromises, Nx Console and TanStack.
4 critical
4 high
2 medium
2 context
SUN 07 JUN 2026
The disclosure feeds went silent for the weekend, leaving one story standing: Miasma opened a Python propagation arm — 37 malicious PyPI wheels that execute on interpreter start, no import required.
1 critical
0 high
0 medium
0 context
SAT 06 JUN 2026
The Miasma worm crossed from npm into Microsoft's own GitHub estate — 73 repositories disabled across four organizations — while DbGate disclosed an unauthenticated CVSS-10 RCE.
3 critical
6 high
5 medium
4 context
FRI 05 JUN 2026
IronWorm's npm campaign doubles to 50-plus poisoned packages and picks up a self-spreading worm and a kernel rootkit, while CISA's KEV clock runs out on a Magento RCE tonight.
6 critical
6 high
2 medium
2 context
THU 04 JUN 2026
Two self-propagating npm worms hit the registry the same day a triple-critical SSTI flaw turns Jupyter's Kubernetes gateway into full cluster takeover.
3 critical
9 high
6 medium
2 context
WED 03 JUN 2026
A public VS Code / github.dev one-click token steal and a triple-critical RCE chain in Jupyter Enterprise Gateway land in the same 48-hour window CISA pushes four bugs to the KEV catalog and Wordfence logs hundreds of active hits on Kirki.
7 critical
3 high
2 medium
3 context
TUE 02 JUN 2026
Two Vitest CVEs, six praisonai IDORs, and a conda write-anywhere push developer tooling into the day's attack surface while CISA stacks three KEV adds on top.
5 critical
2 high
1 medium
2 context
MON 01 JUN 2026
Mini Shai-Hulud lands inside Red Hat's official npm scope — the trusted-vendor namespace compromise the ecosystem has been preparing for since last summer.
4 critical
6 high
2 medium
5 context
SUN 31 MAY 2026
DPRK's Contagious Interview crew ports its npm playbook to PHP, dropping malware in a Packagist-listed package on an otherwise quiet KEV-burndown Sunday.
2 critical
2 high
1 medium
2 context
SAT 30 MAY 2026
Developers are the day's target — a Ghost CMS RCE has backdoored 700+ tech and university sites into ClickFix droppers, CISA hands PAN-OS a 72-hour patch clock, and another AI-coding CLI ships with implicit working-directory trust.
2 critical
2 high
5 medium
1 context
FRI 29 MAY 2026
Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.
3 critical
9 high
8 medium
2 context
THU 28 MAY 2026
A Sicoob banking-SDK impersonator on NuGet exfiltrates client certs through Sentry, the Symfony tranche tops twenty advisories, and a late-evening paired Dulwich disclosure revives the NTFS-hostile-tree-entry class on Windows.
4 critical
17 high
8 medium
2 context
WED 27 MAY 2026
CISA closes the day with KEV adds for Nx Console and TanStack — turning the npm credential-stealing wave into a federal-mandate clock — while Yamcs hands aerospace operators two critical mission-control RCEs.
10 critical
19 high
10 medium
1 context
TUE 26 MAY 2026
Late escalation at 21:00 ET adds a Yamcs algorithm-engine RCE, three pre-auth RCEs in FUXA, and a path traversal in the npm `tmp` transitive dep on top of the day's XWiki and LiteSpeed criticals.
5 critical
11 high
4 medium
4 context
MON 25 MAY 2026
Monday after the storm: TrapDoor's narrative spreads while two Defender CVEs land on the KEV list.
0 critical
0 high
2 medium
4 context
SUN 24 MAY 2026
Four concurrent package-poisoning campaigns hit the registries at once.
13 critical
4 high
1 medium
3 context