TL;Der — Security

tlder@devSecurity
tlder@dev:~$

Filtered to Security. 92 items. covering May 1 → Aug 15

└─worth-opening/(25 items)

ZDI's monthly breakdown is the fastest way to triage which of the 421 Microsoft bugs actually matter, with the exploited WinSock flaw and the QUIC RCE flagged up front.
└─·security
JFrog's team caught the campaign early and keeps their post updated with the current package list and IOCs — the fastest way to check whether anything you depend on is affected.
└─·security,backend,devtools

└─cross-cutting/(49 items)

A credential-stealing worm that started with keyv has torn through the npm ecosystem, with counts now past 800 packages and over two billion monthly installs.
└─·security,backend,devtools·Wiz
CISA added a critical Langflow RCE, a Tomcat cluster flaw, and another N-central bypass to its exploited-vulnerabilities catalog, with a federal deadline of August 7.
└─·security,ai-ml,platform·CISA
Aug 11
Aug 11·cat news/20260811-cves-ms-patch-tuesday-421
cat news/20260811-cves-ms-patch-tuesday-421
Microsoft's 421-CVE Patch Tuesday leads with a WinSock zero-day under active attack
The August rollup is enormous at 421 CVEs, but the one that matters is CVE-2026-68820 — a WinSock use-after-free attackers are already riding to SYSTEM.
└─Qualys
Aug 11
Aug 11·cat news/20260811-cves-sap-patch-day-august
cat news/20260811-cves-sap-patch-day-august
SAP's August patch day headlines a 9.9 in NetWeaver ABAP
On the same Tuesday, SAP shipped 28 security notes — three critical, led by a 9.9-rated flaw in NetWeaver Application Server ABAP.
└─SAP
Aug 11
Aug 11·cat news/20260811-cves-adobe-commerce-aem-rce
cat news/20260811-cves-adobe-commerce-aem-rce
Adobe's August fixes include an unauthenticated RCE in Commerce
Adobe closed four critical holes across Commerce and Experience Manager, including one that runs code with no user interaction at all.
└─Action1
Aug 7
Aug 7·cat news/20260807-cves-cisa-langflow-tomcat-ncentral-kev
cat news/20260807-cves-cisa-langflow-tomcat-ncentral-kev
Patch Langflow, Tomcat, and N-central by Friday — CISA says all three are under active attack
CISA added a critical Langflow RCE, a Tomcat cluster flaw, and another N-central bypass to its exploited-vulnerabilities catalog, with a federal deadline of August 7.
└─CISA
Aug 3
Aug 3·cat news/20260803-cves-ncentral-auth-bypass
cat news/20260803-cves-ncentral-auth-bypass
N-able patches N-central again after its first auth-bypass fix left a way in
N-able shipped N-central 2026.3.1.7 over the weekend after attackers kept bypassing authentication through a gap its earlier fix left open.
└─Help Net Security
Jul 4
Jul 4·cat news/20260704-cves-sharepoint-rce-cve-2026-45659
cat news/20260704-cves-sharepoint-rce-cve-2026-45659
Patch by July 4: SharePoint RCE CVE-2026-45659 Under Active Exploitation
CISA added CVE-2026-45659 — a CVSS 8.8 SharePoint Server deserialization RCE exploitable by any authenticated Site Member — to the KEV catalog on July 1, with FCEB agencies required to patch by July 4.
└─The Hacker News
Jun 26
Jun 26·cat news/20260626-cves-unifi-os-cisa-kev-deadline
cat news/20260626-cves-unifi-os-cisa-kev-deadline
CISA KEV Patch Deadline Today for Three Ubiquiti UniFi OS CVEs
FCEB agencies hit their June 26 patch deadline today for CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 — path traversal and command injection bugs in Ubiquiti UniFi OS that CISA added to KEV on June 23.
└─CISA
Jun 21
Jun 21·cat news/20260621-cves-splunk-cve2026-20253-kev
cat news/20260621-cves-splunk-cve2026-20253-kev
CISA KEV Deadline Passes for Splunk Enterprise Unauthenticated File Truncation Bug
Federal agencies hit their June 21 remediation deadline for CVE-2026-20253, a missing-authentication flaw in Splunk Enterprise that lets unauthenticated attackers create or truncate files via a PostgreSQL sidecar endpoint.
└─CISA
Jun 18
Jun 18·cat news/20260618-cves-cisa-kev-joomla-cve-2026-20253
cat news/20260618-cves-cisa-kev-joomla-cve-2026-20253
CISA Adds Actively Exploited Joomla Widget Factory Flaw to KEV Catalog
CISA confirmed active exploitation of CVE-2026-20253 in the Widget Factory Joomla Content Editor, adding it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21.
└─CISA
Jun 12
Jun 12·cat news/20260612-cves-advisories-ivanti-sentry-kev-rce
cat news/20260612-cves-advisories-ivanti-sentry-kev-rce
CISA Adds Ivanti Sentry OS Command Injection to KEV — Unauthenticated Root RCE
CISA added a critical Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog on June 12, enabling unauthenticated remote attackers to execute commands as root.
└─CISA KEV Catalog
Jun 12
Jun 12·cat news/20260612-cves-advisories-ikev1-vpn-cve-2026-50751
cat news/20260612-cves-advisories-ikev1-vpn-cve-2026-50751
Check Point Confirms Active Exploitation of IKEv1 VPN Flaw CVE-2026-50751, Dutch NCSC Warns of Large-Scale Abuse
CVE-2026-50751, an IKEv1 VPN vulnerability confirmed as actively exploited by Check Point, drew a Dutch NCSC warning about imminent large-scale attacks and a CISA KEV deadline.
└─CISA KEV Catalog
Jun 9
Jun 9·cat news/20260609-cves-advisories-cisco-sdwan-mgr-kev
cat news/20260609-cves-advisories-cisco-sdwan-mgr-kev
CISA Adds Cisco Catalyst SD-WAN Manager to KEV With June 23 Deadline — Still No Patch
CISA formally listed CVE-2026-20245 in its Known Exploited Vulnerabilities catalog on June 9, giving federal agencies until June 23 to remediate — even though Cisco has yet to ship a fix.
└─CISA
Jun 9
Jun 9·cat news/20260609-cves-advisories-arista-eos-cve-2026-7473
cat news/20260609-cves-advisories-arista-eos-cve-2026-7473
Arista EOS CVE-2026-7473 Added to CISA KEV — Action Due June 23
CISA added CVE-2026-7473, an incomplete comparison flaw in Arista Extensible Operating System, to the Known Exploited Vulnerabilities catalog on June 9 with a remediation deadline of June 23, 2026.
└─CISA
May 20
May 20·cat news/20260603-cves-advisories-defender-kev-june3-deadl
cat news/20260603-cves-advisories-defender-kev-june3-deadl
CISA Sets June 3 Deadline for Two Exploited Microsoft Defender Zero-Days
CVE-2026-41091 lets a local attacker escalate to SYSTEM through Defender's Malware Protection Engine, while CVE-2026-45498 kills definition updates — patched together, federal deadline June 3.
└─WinBuzzer / The Hacker News
May 21
May 21·cat news/20260521-cves-advisories-cisa-kev-langflow-trendmicro
cat news/20260521-cves-advisories-cisa-kev-langflow-trendmicro
CISA Adds Langflow and Trend Micro Apex One to KEV Catalog
CISA flagged CVE-2025-34291 (Langflow origin validation error) and CVE-2026-34926 (Trend Micro Apex One directory traversal) as actively exploited, requiring federal agencies to patch under BOD 22-01.
└─CISA
May 20
May 20·cat news/20260520-cves-advisories-cisa-kev-may20-seven-cves
cat news/20260520-cves-advisories-cisa-kev-may20-seven-cves
CISA KEV Adds Seven CVEs Including Two 2026 Microsoft Defender Flaws and Five Legacy Exploits
Seven vulnerabilities joined the KEV catalog on May 20, mixing two fresh Microsoft Defender CVEs with five bugs from 2008-2010 that are, apparently, still being weaponized.
└─CISA
May 17
May 17·cat news/20260517-cves-advisories-cisco-sdwan-cve-2026-20182
cat news/20260517-cves-advisories-cisco-sdwan-cve-2026-20182
CISA Orders Federal Agencies to Patch Cisco Catalyst SD-WAN Auth Bypass CVE-2026-20182 by May 17
A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited in the wild, with CISA mandating federal agency remediation by May 17, 2026 and no complete workaround available short of upgrading.
└─BleepingComputer
May 10
May 10·cat news/20260510-cves-advisories-ivanti-epmm-cisa
cat news/20260510-cves-advisories-ivanti-epmm-cisa
CISA May 10 Deadline Passes for Ivanti EPMM Remote Code Execution Flaw
CISA's May 10 remediation deadline for an Ivanti Endpoint Manager Mobile improper-input-validation bug enabling authenticated-admin RCE has now lapsed, increasing exposure for federal and enterprise deployments.
└─CISA
May 10
May 10·cat news/20260510-cves-advisories-ivanti-epmm-cve6973
cat news/20260510-cves-advisories-ivanti-epmm-cve6973
CISA Adds Ivanti EPMM CVE-2026-6973 to KEV; Federal Patch Deadline Is Today
Ivanti Endpoint Manager Mobile carries a CVSS 7.2 RCE flaw under active exploitation, and CISA ordered Federal Civilian Executive Branch agencies to apply patches by May 10, 2026.
└─The Hacker News
May 9
May 9·cat news/20260509-cves-advisories-cve-2026-0300-deadline
cat news/20260509-cves-advisories-cve-2026-0300-deadline
CISA Deadline Passes for PAN-OS CVE-2026-0300 as Patches Remain Unavailable Until May 13
The CISA May 9 remediation deadline for the actively exploited Palo Alto PAN-OS root-level RCE (CVE-2026-0300) has arrived with official patches still not available, requiring agencies to apply interim mitigations immediately.
└─The Hacker News
Aug 6
Aug 6·cat news/20260806-supply-chain-shai-hulud-keyv-npm-worm
cat news/20260806-supply-chain-shai-hulud-keyv-npm-worm
Shai-Hulud is back: a self-spreading worm has poisoned hundreds of npm packages
A credential-stealing worm that started with keyv has torn through the npm ecosystem, with counts now past 800 packages and over two billion monthly installs.
└─Wiz
Aug 2
Aug 2·cat news/20260803-supply-chain-npm-bypass-2fa
cat news/20260803-supply-chain-npm-bypass-2fa
npm starts stripping account powers from its 2FA-bypass tokens
As of early August, npm granular access tokens set to skip 2FA can no longer manage other tokens, maintainers, or account settings — and direct publishing is next to go, in early 2027.
└─GitHub Changelog
Jul 8
Jul 8·cat news/20260708-supply-chain-injective-sdk-backdoor
cat news/20260708-supply-chain-injective-sdk-backdoor
Injective SDK Backdoored via Compromised Developer Account to Steal Wallet Keys
Attackers gained access to a trusted developer's account and inserted a backdoor into the Injective blockchain SDK, targeting cryptocurrency wallet keys and seed phrases.
└─CySecurity News
Jul 8
Jul 8·cat news/20260708-supply-chain-npm-v12-install-script
cat news/20260708-supply-chain-npm-v12-install-script
npm v12 Ships This Month, Blocking Install Scripts by Default
npm v12, arriving July 2026, blocks install scripts, Git dependencies, and remote sources by default — a breaking change driven by a year of North Korean supply chain attacks on the ecosystem.
└─Cybernews
Jul 1
Jul 1·cat news/20260701-supply-chain-mini-shai-hulud-170pkgs
cat news/20260701-supply-chain-mini-shai-hulud-170pkgs
Mini Shai-Hulud Expands to 170+ Packages as Worm-Style Propagation Confirmed
The fourth wave of the TeamPCP supply chain campaign now affects 170+ npm and PyPI packages, with fresh reporting confirming the malware harvests credentials post-install and uses them to poison other packages the victim controls.
└─SecurityWeek
Jul 23
Jul 23·cat news/20260723-platform-security-cisa-volt-typhoon-refresh
cat news/20260723-platform-security-cisa-volt-typhoon-refresh
CISA refreshes its Volt Typhoon guidance for critical-infrastructure defenders
CISA updated its long-running Volt Typhoon advisory this week, folding in sharper detection guidance as the PRC-linked group keeps its foothold in US critical-infrastructure networks.
└─CISA
Jul 14
Jul 14·cat news/20260714-platform-security-record-patch-tuesday
cat news/20260714-platform-security-record-patch-tuesday
The biggest Patch Tuesday ever lands with two zero-days already exploited
Microsoft shipped fixes for a record ~570 flaws on Tuesday, and two of the three zero-days in the batch are already being used in the wild.
└─BleepingComputer
Jul 4
Jul 4·cat news/20260704-platsec-fable5-bounty-jailbreak-fw
cat news/20260704-platsec-fable5-bounty-jailbreak-fw
Anthropic Launches Fable 5 Bug Bounty and AI Jailbreak Severity Framework
Anthropic opened a HackerOne bug bounty for Fable 5 jailbreaks and published a draft AI Jailbreak Severity Framework co-developed with AWS, Microsoft, and Google.
└─Anthropic
Jul 1
Jul 1·cat news/20260701-platsec-jamf-beacon-ai-governance
cat news/20260701-platsec-jamf-beacon-ai-governance
Jamf's Beacon brings dedicated threat hunting to enterprise Macs
Jamf made Beacon, a macOS-focused threat hunting service staffed by its Threat Labs team, generally available for enterprise Mac fleets.
└─9to5Mac
Jun 29
Jun 29·cat news/20260629-platform-security-gh-actions-runner-min-ver
cat news/20260629-platform-security-gh-actions-runner-min-ver
GitHub Actions Begins Brownouts June 29 for Self-Hosted Runners Below Minimum Version
GitHub resumes enforcement of minimum runner version requirements starting June 29, with brownouts from 11 AM–3 PM ET on github.com and full enforcement across GitHub Enterprise Cloud by July 31.
└─GitHub Changelog
May 12
May 12·cat news/20260512-platform-security-cve-2026-32202-cisa-kev
cat news/20260512-platform-security-cve-2026-32202-cisa-kev
CISA KEV Deadline: Federal Agencies Must Patch Windows Shell CVE-2026-32202 by May 12
CISA's May 12 patching deadline for CVE-2026-32202 — an APT28-exploited Windows Shell spoofing flaw enabling zero-click NTLMv2 hash theft — arrives today, requiring the April 2026 cumulative update KB5083769.
└─CISA / The Hacker News
May 1 → Aug 15Security92 entries