TL;Der — Security

tlder@devSecurity
tlder@dev:~$

Filtered to Security. 60 items. covering May 1 → Jun 21

└─worth-opening/(7 items)

The canonical advisory with the version numbers and CVEs as they drop — bookmark it and check before you redeploy any Node service this week.
└─·backend,security
Seven Critical use-after-free bugs in one batch — check you're on 149.0.7827.155 or later before the week ends.
└─·security,web

└─cross-cutting/(28 items)

Node.js shipped June 2026 security releases across all maintained lines on June 18, patching two HIGH-severity CVEs: a WebCrypto AES integer overflow and a TLS wildcard authentication bypass.
└─·backend,security,mobile·nodejs.org
Google shipped Chrome 149.0.7827.155 on June 16 with 33 security fixes, seven Critical, targeting use-after-free bugs across WebShare, WebView, Digital Credentials, and Web Authentication.
└─·security,web·Chrome Releases Blog
Jun 20
Jun 20·cat news/20260620-supply-chain-node-gyp-bindinggyp-worm
cat news/20260620-supply-chain-node-gyp-bindinggyp-worm
node-gyp Supply Chain Worm Abuses binding.gyp to Evade Lifecycle Script Monitoring
A novel npm supply chain campaign embeds malicious code inside binding.gyp files to trigger execution via node-gyp during install — bypassing the preinstall/postinstall hooks that most security tooling watches.
└─Snyk
Jun 1
Jun 1·cat news/20260601-supply-chain-miasma-redhat-npm-teampc
cat news/20260601-supply-chain-miasma-redhat-npm-teampc
Miasma Supply Chain Attack Hits 32 Red Hat npm Packages via Compromised CI/CD Pipeline
TeamPCP's latest Mini Shai-Hulud variant compromised 96 versions across 32 @redhat-cloud-services npm packages — the fifth time this actor has pulled the same playbook in six weeks, and their first confirmed pivot to GitHub Actions OIDC tokens instead of individual developer credentials.
└─Wiz Research
May 31
May 31·cat news/20260531-supply-chain-triple-registry-npm-pypi-docker
cat news/20260531-supply-chain-triple-registry-npm-pypi-docker
Three Simultaneous Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours
Three separate credential-stealing campaigns targeted npm, PyPI, and Docker Hub within the same 48-hour window — the Docker Hub incident involved a trojanized Trivy image and picked up CVE-2026-33634.
└─GitGuardian
May 28
May 28·cat news/20260528-supply-chain-openssf-python-secure-coding
cat news/20260528-supply-chain-openssf-python-secure-coding
OpenSSF cuts its first Python Secure Coding Guide to v1.0.0
Among the OpenSSF Community Day North America roundup, the headline artifact is a 1.0.0 Python secure-coding guide developers can actually pin against.
└─OpenSSF
Jun 29
Jun 29·cat news/20260629-platform-security-gh-actions-runner-min-ver
cat news/20260629-platform-security-gh-actions-runner-min-ver
GitHub Actions Begins Brownouts June 29 for Self-Hosted Runners Below Minimum Version
GitHub resumes enforcement of minimum runner version requirements starting June 29, with brownouts from 11 AM–3 PM ET on github.com and full enforcement across GitHub Enterprise Cloud by July 31.
└─GitHub Changelog
Jun 12
Jun 12·cat news/20260612-platform-security-fable-mythos-export-ctrl
cat news/20260612-platform-security-fable-mythos-export-ctrl
US Export Controls Force Anthropic to Suspend Claude Fable 5 and Mythos 5 Access Over Alleged AI Jailbreak
The US government invoked export controls on June 12 to suspend access to Claude Fable 5 and Mythos 5, citing a potential jailbreak with cybersecurity implications.
└─Anthropic
May 28
May 28·cat news/20260528-platform-security-microshift-grpc-patch
cat news/20260528-platform-security-microshift-grpc-patch
Red Hat patches gRPC auth-bypass in MicroShift 4.16.63
RHSA-2026:20436 lands the gRPC-Go fix for CVE-2026-33186 in MicroShift, closing an authorization bypass triggered by a non-canonical request path.
└─Red Hat
May 12
May 12·cat news/20260512-platform-security-cve-2026-32202-cisa-kev
cat news/20260512-platform-security-cve-2026-32202-cisa-kev
CISA KEV Deadline: Federal Agencies Must Patch Windows Shell CVE-2026-32202 by May 12
CISA's May 12 patching deadline for CVE-2026-32202 — an APT28-exploited Windows Shell spoofing flaw enabling zero-click NTLMv2 hash theft — arrives today, requiring the April 2026 cumulative update KB5083769.
└─CISA / The Hacker News
Jun 18
Jun 18·cat news/20260618-cves-cisa-kev-joomla-cve-2026-20253
cat news/20260618-cves-cisa-kev-joomla-cve-2026-20253
CISA Adds Actively Exploited Joomla Widget Factory Flaw to KEV Catalog
CISA confirmed active exploitation of CVE-2026-20253 in the Widget Factory Joomla Content Editor, adding it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21.
└─CISA
Jun 18
Jun 18·cat news/20260618-cves-nodejs-june-2026-security-releases
cat news/20260618-cves-nodejs-june-2026-security-releases
Node.js June 2026 Security Releases Ship — Two HIGH-Severity CVEs Across All Maintained Lines
Node.js shipped v22.23.0, v24.17.0, and v26.3.1 on June 18, patching 13 CVEs including a WebCrypto integer overflow and a TLS wildcard-depth authentication bypass, both rated HIGH.
└─Node.js
Jun 16
Jun 16·cat news/20260616-cves-chrome-149-june16-33fixes
cat news/20260616-cves-chrome-149-june16-33fixes
Chrome 149 patches 33 vulnerabilities in one drop — seven rated Critical
Google shipped Chrome 149.0.7827.155 on June 16 with 33 security fixes, seven Critical, targeting use-after-free bugs across WebShare, WebView, Digital Credentials, and Web Authentication.
└─Chrome Releases Blog
Jun 12
Jun 12·cat news/20260612-cves-advisories-ivanti-sentry-kev-rce
cat news/20260612-cves-advisories-ivanti-sentry-kev-rce
CISA Adds Ivanti Sentry OS Command Injection to KEV — Unauthenticated Root RCE
CISA added a critical Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog on June 12, enabling unauthenticated remote attackers to execute commands as root.
└─CISA KEV Catalog
Jun 12
Jun 12·cat news/20260612-cves-advisories-ikev1-vpn-cve-2026-50751
cat news/20260612-cves-advisories-ikev1-vpn-cve-2026-50751
Check Point Confirms Active Exploitation of IKEv1 VPN Flaw CVE-2026-50751, Dutch NCSC Warns of Large-Scale Abuse
CVE-2026-50751, an IKEv1 VPN vulnerability confirmed as actively exploited by Check Point, drew a Dutch NCSC warning about imminent large-scale attacks and a CISA KEV deadline.
└─CISA KEV Catalog
Jun 9
Jun 9·cat news/20260609-cves-advisories-cisco-sdwan-mgr-kev
cat news/20260609-cves-advisories-cisco-sdwan-mgr-kev
CISA Adds Cisco Catalyst SD-WAN Manager to KEV With June 23 Deadline — Still No Patch
CISA formally listed CVE-2026-20245 in its Known Exploited Vulnerabilities catalog on June 9, giving federal agencies until June 23 to remediate — even though Cisco has yet to ship a fix.
└─CISA
Jun 9
Jun 9·cat news/20260609-cves-advisories-arista-eos-cve-2026-7473
cat news/20260609-cves-advisories-arista-eos-cve-2026-7473
Arista EOS CVE-2026-7473 Added to CISA KEV — Action Due June 23
CISA added CVE-2026-7473, an incomplete comparison flaw in Arista Extensible Operating System, to the Known Exploited Vulnerabilities catalog on June 9 with a remediation deadline of June 23, 2026.
└─CISA
Jun 9
Jun 9·cat news/20260609-cves-advisories-chrome-cve-2026-11645
cat news/20260609-cves-advisories-chrome-cve-2026-11645
Google Patches Fifth 2026 Chrome Zero-Day — Actively Exploited V8 Out-of-Bounds Bug CVE-2026-11645
Chrome 149.0.7827.102/.103 lands an emergency fix for CVE-2026-11645, an out-of-bounds read/write in V8 that is being exploited in the wild — the fifth Chrome zero-day patched this year.
└─Help Net Security
May 20
May 20·cat news/20260603-cves-advisories-defender-kev-june3-deadl
cat news/20260603-cves-advisories-defender-kev-june3-deadl
CISA Sets June 3 Deadline for Two Exploited Microsoft Defender Zero-Days
CVE-2026-41091 lets a local attacker escalate to SYSTEM through Defender's Malware Protection Engine, while CVE-2026-45498 kills definition updates — patched together, federal deadline June 3.
└─WinBuzzer / The Hacker News
Jun 2
Jun 2·cat news/20260602-cves-advisories-cisa-kev-cve-2022-0492-linux
cat news/20260602-cves-advisories-cisa-kev-cve-2022-0492-linux
CISA Adds 2022 Linux Kernel CVE-2022-0492 to KEV, Confirming Active Exploitation
CISA added CVE-2022-0492, a Linux Kernel improper authentication flaw first disclosed in 2022, to the Known Exploited Vulnerabilities catalog on June 2 — meaning it is now confirmed to be actively exploited in the wild.
└─CISA
May 21
May 21·cat news/20260521-cves-advisories-cisa-kev-langflow-trendmicro
cat news/20260521-cves-advisories-cisa-kev-langflow-trendmicro
CISA Adds Langflow and Trend Micro Apex One to KEV Catalog
CISA flagged CVE-2025-34291 (Langflow origin validation error) and CVE-2026-34926 (Trend Micro Apex One directory traversal) as actively exploited, requiring federal agencies to patch under BOD 22-01.
└─CISA
May 20
May 20·cat news/20260520-cves-advisories-cisa-kev-may20-seven-cves
cat news/20260520-cves-advisories-cisa-kev-may20-seven-cves
CISA KEV Adds Seven CVEs Including Two 2026 Microsoft Defender Flaws and Five Legacy Exploits
Seven vulnerabilities joined the KEV catalog on May 20, mixing two fresh Microsoft Defender CVEs with five bugs from 2008-2010 that are, apparently, still being weaponized.
└─CISA
May 17
May 17·cat news/20260517-cves-advisories-cisco-sdwan-cve-2026-20182
cat news/20260517-cves-advisories-cisco-sdwan-cve-2026-20182
CISA Orders Federal Agencies to Patch Cisco Catalyst SD-WAN Auth Bypass CVE-2026-20182 by May 17
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited in the wild, with CISA mandating federal agency remediation by May 17, 2026 and no complete workaround available short of upgrading.
└─BleepingComputer
May 10
May 10·cat news/20260510-cves-advisories-ivanti-epmm-cisa
cat news/20260510-cves-advisories-ivanti-epmm-cisa
CISA May 10 Deadline Passes for Ivanti EPMM Remote Code Execution Flaw
CISA's May 10 remediation deadline for an Ivanti Endpoint Manager Mobile improper-input-validation bug enabling authenticated-admin RCE has now lapsed, increasing exposure for federal and enterprise deployments.
└─CISA
May 10
May 10·cat news/20260510-cves-advisories-ivanti-epmm-cve6973
cat news/20260510-cves-advisories-ivanti-epmm-cve6973
CISA Adds Ivanti EPMM CVE-2026-6973 to KEV; Federal Patch Deadline Is Today
Ivanti Endpoint Manager Mobile carries a CVSS 7.2 RCE flaw under active exploitation, and CISA ordered Federal Civilian Executive Branch agencies to apply patches by May 10, 2026.
└─The Hacker News
May 9
May 9·cat news/20260509-cves-advisories-cve-2026-0300-deadline
cat news/20260509-cves-advisories-cve-2026-0300-deadline
CISA Deadline Passes for PAN-OS CVE-2026-0300 as Patches Remain Unavailable Until May 13
The CISA May 9 remediation deadline for the actively exploited Palo Alto PAN-OS root-level RCE (CVE-2026-0300) has arrived with official patches still not available, requiring agencies to apply interim mitigations immediately.
└─The Hacker News
May 1 → Jun 21Security60 entries