ZDI's monthly breakdown is the fastest way to triage which of the 421 Microsoft bugs actually matter, with the exploited WinSock flaw and the QUIC RCE flagged up front.
JFrog's team caught the campaign early and keeps their post updated with the current package list and IOCs — the fastest way to check whether anything you depend on is affected.
A credential-stealing worm that started with keyv has torn through the npm ecosystem, with counts now past 800 packages and over two billion monthly installs.
CISA added a critical Langflow RCE, a Tomcat cluster flaw, and another N-central bypass to its exploited-vulnerabilities catalog, with a federal deadline of August 7.
The August rollup is enormous at 421 CVEs, but the one that matters is CVE-2026-68820 — a WinSock use-after-free attackers are already riding to SYSTEM.
CISA added a critical Langflow RCE, a Tomcat cluster flaw, and another N-central bypass to its exploited-vulnerabilities catalog, with a federal deadline of August 7.
CISA added CVE-2026-45659 — a CVSS 8.8 SharePoint Server deserialization RCE exploitable by any authenticated Site Member — to the KEV catalog on July 1, with FCEB agencies required to patch by July 4.
FCEB agencies hit their June 26 patch deadline today for CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 — path traversal and command injection bugs in Ubiquiti UniFi OS that CISA added to KEV on June 23.
Federal agencies hit their June 21 remediation deadline for CVE-2026-20253, a missing-authentication flaw in Splunk Enterprise that lets unauthenticated attackers create or truncate files via a PostgreSQL sidecar endpoint.
CISA confirmed active exploitation of CVE-2026-20253 in the Widget Factory Joomla Content Editor, adding it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21.
CISA added a critical Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog on June 12, enabling unauthenticated remote attackers to execute commands as root.
CVE-2026-50751, an IKEv1 VPN vulnerability confirmed as actively exploited by Check Point, drew a Dutch NCSC warning about imminent large-scale attacks and a CISA KEV deadline.
CISA formally listed CVE-2026-20245 in its Known Exploited Vulnerabilities catalog on June 9, giving federal agencies until June 23 to remediate — even though Cisco has yet to ship a fix.
CISA added CVE-2026-7473, an incomplete comparison flaw in Arista Extensible Operating System, to the Known Exploited Vulnerabilities catalog on June 9 with a remediation deadline of June 23, 2026.
CVE-2026-41091 lets a local attacker escalate to SYSTEM through Defender's Malware Protection Engine, while CVE-2026-45498 kills definition updates — patched together, federal deadline June 3.
CISA flagged CVE-2025-34291 (Langflow origin validation error) and CVE-2026-34926 (Trend Micro Apex One directory traversal) as actively exploited, requiring federal agencies to patch under BOD 22-01.
Seven vulnerabilities joined the KEV catalog on May 20, mixing two fresh Microsoft Defender CVEs with five bugs from 2008-2010 that are, apparently, still being weaponized.
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited in the wild, with CISA mandating federal agency remediation by May 17, 2026 and no complete workaround available short of upgrading.
CISA's May 10 remediation deadline for an Ivanti Endpoint Manager Mobile improper-input-validation bug enabling authenticated-admin RCE has now lapsed, increasing exposure for federal and enterprise deployments.
Ivanti Endpoint Manager Mobile carries a CVSS 7.2 RCE flaw under active exploitation, and CISA ordered Federal Civilian Executive Branch agencies to apply patches by May 10, 2026.
The CISA May 9 remediation deadline for the actively exploited Palo Alto PAN-OS root-level RCE (CVE-2026-0300) has arrived with official patches still not available, requiring agencies to apply interim mitigations immediately.
A credential-stealing worm that started with keyv has torn through the npm ecosystem, with counts now past 800 packages and over two billion monthly installs.
As of early August, npm granular access tokens set to skip 2FA can no longer manage other tokens, maintainers, or account settings — and direct publishing is next to go, in early 2027.
Attackers gained access to a trusted developer's account and inserted a backdoor into the Injective blockchain SDK, targeting cryptocurrency wallet keys and seed phrases.
npm v12, arriving July 2026, blocks install scripts, Git dependencies, and remote sources by default — a breaking change driven by a year of North Korean supply chain attacks on the ecosystem.
The fourth wave of the TeamPCP supply chain campaign now affects 170+ npm and PyPI packages, with fresh reporting confirming the malware harvests credentials post-install and uses them to poison other packages the victim controls.
CISA updated its long-running Volt Typhoon advisory this week, folding in sharper detection guidance as the PRC-linked group keeps its foothold in US critical-infrastructure networks.
Anthropic opened a HackerOne bug bounty for Fable 5 jailbreaks and published a draft AI Jailbreak Severity Framework co-developed with AWS, Microsoft, and Google.
GitHub resumes enforcement of minimum runner version requirements starting June 29, with brownouts from 11 AM–3 PM ET on github.com and full enforcement across GitHub Enterprise Cloud by July 31.
CISA's May 12 patching deadline for CVE-2026-32202 — an APT28-exploited Windows Shell spoofing flaw enabling zero-click NTLMv2 hash theft — arrives today, requiring the April 2026 cumulative update KB5083769.