
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware

The ChainDrop npm worm, a new Shai-Hulud variant, poisoned over 440 registry packages and uses stolen tokens to republish malware

A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others’ meeting data and potentially join calls,

Threat actors poisoned Xanadu’s mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research

ExfilSquad leaked contact data of over 100,000 UK police and staff in a Police National Legal Database breach, enabling phishing

A cyberattack accessed Liechtenstein’s beneficial-ownership register, exposing data on about 31,000 people behind companies and foundations, officials said.

UK Government Investments admitted an employee left a file with 51 government officials’ names and work email addresses publicly accessible

Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.

Attackers tampered with Adform’s trackpoint script, rewriting crypto wallet addresses across customer pages to divert payments to attacker-controlled wallets.

Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant

Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor’s credentials.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.