
Compromised jscrambler npm Package Drops Rust Infostealer on Devs
An attacker compromised jscrambler’s npm credentials and published five malicious versions dropping a Rust infostealer targeting cloud and AI credentials.

An attacker compromised jscrambler’s npm credentials and published five malicious versions dropping a Rust infostealer targeting cloud and AI credentials.

Binarly disclosed six flaws in U-Boot’s FIT signature verification subsystem, including two RCEs that bypass Secure Boot across more than

Google’s Threat Analysis Group found a critical stored XSS flaw in the Zimbra Classic Web Client that allows mailbox takeover

Australia’s Signals Directorate warned of an active global campaign scanning for 17 known CVEs across WordPress, Joomla, and other public-facing

Microsoft silently patched CVE-2026-50656 RoguePlanet via a Defender engine update, ending over three weeks of confirmed active SYSTEM privilege exploitation.

Wiz Research’s GhostApproval attack uses symlinks in cloned repositories to trick six AI coding agents into writing attacker SSH keys

Elastic Security Labs found REF6045 deploying SCMBANKER, an AI-written PowerShell toolkit that lets operators control Mexican banking sessions live and

China’s CNVDB directed developers to uninstall three months of Claude Code versions, citing unauthorized data collection. Alibaba banned the tool

Socket found 17 malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs that stole AWS keys and payment

Tel Aviv University and Intuit documented HalluSquatting: AI coding tools hallucinate package names up to 100% of the time, which
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.