All Posts
Get ready for all the horrors and thrills you can handle.
Megalodon: 5,561 Repos Swallowed in Six Hours
TLDR and details on the Megalodon supply chain attack mass-backdooring GitHub repositories via malicious CI/CD workflow commits.
Chromium: The Tab That Never Really Closed
TLDR and details on a Chromium vulnerability allowing attackers to run JavaScript in the background even after the browser is closed.
BIND 9: Three Cracks in the Resolver Wall
TLDR and affected version summary for three BIND 9 DNS resolver vulnerabilities causing denial of service via high CPU usage.
Drupal: The Postgres Backdoor Query
TLDR and affected version summary for CVE-2026-9082, a SQL injection vulnerability in Drupal affecting PostgreSQL deployments.
GitHub: The Extension That Opened the Vault
TLDR and impact summary for the GitHub internal repository breach caused by a malicious VS Code extension installed by a GitHub developer.
Composer: Tokens Spilled on the CI Stage
TLDR and affected version summary for CVE-2026-45793, a Composer vulnerability that may expose GitHub authentication tokens in CI logs.
NGINX njs: One Overflow to Crash Them All
TLDR and affected version summary for CVE-2026-8711, a heap buffer overflow in NGINX JavaScript (njs) that can crash workers and may allow RCE.
Mini Shai-Hulud: 639 Packages Deep and Still Burrowing
TLDR and affected package summary for the latest wave of the Mini Shai-Hulud npm supply-chain campaign targeting antv and echarts-for-react.