Cybersecurity
264 articles RSS
Microsoft Expands Bug Bounty Program to Open Source and Third-Party Code, Pays Record $20 Million
Microsoft's bounty program paid over $20 million to 562 researchers this year after expanding scope to cover open-source software and third-party components.
Malicious 'Solidity Pro' VS Code Extensions Steal Crypto Wallets and Developer Credentials via Telegram Exfiltration
Yeeth Security found 'Solidity Pro' VS Code extensions that evolved from a delayed Cloudflare-Worker dropper into a Telegram-based wallet and credential stealer targeting web3 developers.
GitHub Ships an Actions Network Firewall in Technical Preview, Consolidates Months of npm and Actions Supply Chain Hardening
GitHub detailed a technical-preview Actions network firewall and rounded up npm and Actions defaults changed since February, drawing sharp Hacker News debate over delay-based defenses versus package signing.
GitLab Patches 13 Security Flaws, Including CI/CD Pipeline Tampering and a Duo Code Review Prompt-Injection Bug
GitLab's 19.2.1, 19.1.3, and 19.0.5 patch release fixes 13 vulnerabilities, including three high-severity flaws and a prompt-injection bug in Duo Code Review.
Sonatype Tracks 'Flooding Dropper' Campaign Flooding npm With 846 Malicious Packages Across Disposable Accounts
Sonatype is tracking sonatype-2026-005660, a campaign that has published 846 malicious npm packages across throwaway accounts, dropping cross-platform malware with DNS-based fallback delivery.
HashiCorp Patches Critical CVSS 10.0 Cross-Tenant Credential Bug in Terraform MCP Server
A maximum-severity flaw let one user's Terraform token be reused for other users' requests in stateless HTTP mode; two related bugs also patched in version 1.1.0.
Node.js Ships Twice-Delayed July Security Release Patching 11 CVEs as Node 18 and 20 Sit Fully Unpatched
Node.js shipped 11 CVE fixes across three High-severity HTTP/2 and Permission Model bugs on July 29, after two delays, while EOL versions 18 and 20 get nothing upstream.
ChainDrop Worm Compromises Over 1,300 npm Package Versions After keyv Maintainer's GitHub Account Is Breached
A self-propagating worm hijacked keyv and related npm packages on August 4 after a maintainer's GitHub account was breached, spreading to 1,300+ package versions.
Forescout Finds 15 Vulnerabilities in TP-Link's Omada Zero-Touch Provisioning System, Chainable Into Full Network Takeover
Vedere Labs disclosed 15 flaws in TP-Link Omada's zero-touch provisioning system at Black Hat USA, some chainable into root-level network compromise.
CISA Orders Federal Agencies to Patch Actively Exploited N-able N-central Authentication Bypass
CISA gave federal agencies until August 6 to patch CVE-2026-18577, an N-central auth bypass exploited in the wild since July 31 that grants attackers admin access to the RMM console.
Rails Patches Critical Active Storage Flaw That Lets Unauthenticated Attackers Read Secrets and Escalate to RCE
CVE-2026-66066 lets attackers upload a crafted image to steal a Rails app's secret_key_base and escalate to remote code execution.
SQLite's Official Vulnerability Page Brands Six 'Critical' CVEs as AI Hallucinations After NVD Rejects Them
SQLite's own CVE tracker and the National Vulnerability Database both rejected six reports as AI-hallucinated after a JFrog researcher found the underlying code and PoCs didn't exist or didn't work.