Cybersecurity
264 articles RSS
PostgreSQL Ships Coordinated Release Fixing 28 CVEs Across Five Versions, Debuts 19 Beta 3
PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 landed August 13 alongside 19 Beta 3, patching 28 security flaws and over 110 bugs, with PostgreSQL 14 set to lose support in November.
Marimo Patches CVE-2026-75149, an 8.7-Severity Code-Injection Flaw Triggered by a Notebook's MCP Configuration
A crafted marimo notebook could run an attacker's command as a local subprocess the moment it was opened in edit mode, via a fake MCP server entry in its configuration.
New Study Finds RAG and Self-Refine Are the Only Defenses That Hold Up Against Adversarial AI Package Hallucination Attacks
A new paper testing seven defenses against AI-hallucinated software packages finds only RAG and Self-Refine hold up under adversarial prompting; Ruby stays the most vulnerable language.
Trojanized npm Packages Deliver AI-Assisted RedC2 4.0 Linux Backdoor, Trend Micro Finds
TrendAI found 14 npm packages disguised as calendar utilities quietly installing RedShell, a Linux implant tied to the AI-assisted RedC2 4.0 command-and-control framework.
Flux Mirror Plugin Turns Container Registries Into a 'Supply-Chain Diode' for Gitless GitOps
Flux's new CLI plugin mirrors images, Helm charts, and OCI artifacts into registries teams control, holding back newly signed artifacts to blunt fast-moving supply-chain attacks.
Socket Launches Firefox Extension Scanning After Uncovering 77-Extension Crypto Wallet-Theft Network
Socket added Firefox extension scanning for enterprise customers days after its researchers uncovered 40 malicious extensions stealing crypto wallet secrets.
Rust Security Team Locks Compromised arrayref Crate After Malicious proc-macro1 Package Reaches Crates.io
Rust's security team removed a malicious proc-macro1 crate and the arrayref, internment, and append-only-vec crates it compromised, each pulled from crates.io within about 90 minutes.
Critical Type Confusion Flaw in isolated-vm Node.js Sandbox Let Guest Code Escape to the Host
A type confusion bug in isolated-vm's ExternalCopy let sandboxed JavaScript corrupt host memory, up to control-flow hijack; patched in 7.0.1 and 6.2.0.
StubMaker Malware Campaign Hit RubyGems and npm With the Same Windows Infostealer
Researchers found one threat actor ran typosquatting campaigns on RubyGems and npm days apart, sharing an identical Rust loader and Go infostealer.
GitHub Extends Malware Advisory Detection Beyond npm to Eight Package Ecosystems, Absorbing OpenSSF's Malicious-Packages Database
GitHub now feeds Dependabot malware alerts from OpenSSF's malicious-packages data across npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer.
Critical Metabase SQL Injection Zero-Day Hits CISA's KEV Catalog After Breaching Framework and n8n
A maximum-severity SQL injection zero-day in Metabase, CVE-2026-72898, gave attackers admin access and was used to breach Framework, n8n, and other customers before landing on CISA's KEV catalog.
GitLab Finds Critical Template-Injection Flaw in Serena, an MCP Coding Agent, Bypassing Its Untrusted-Project Safeguard
A critical Jinja2 template-injection bug let attacker-controlled repository files execute code in the Serena coding agent, bypassing its own trust gate.