FR
live
tag

#supply-chain

A leaked GitLab work-item email lets anyone open merge requests in your name

On September 24, 2026, Aikido revealed that GitLab’s “Email work item to this project” addresses, generated with a long-lived token and accidentally published in READMEs, let an attacker open merge requests or push code as the token owner. Search your repositories for these addresses and reset the exposed tokens.

A documentation placeholder domain now serves a ClickFix lure to Windows users

On September 24, 2026, Manifold Security revealed that third-party.com, a documentation placeholder used as an example for years, had been registered by a third party and now serves a ClickFix lure to Windows browsers. Audit your repositories and stop letting a non-reserved domain stand in as an example.

North Korea’s WaterPlum campaign infected 30,000 devices and stole $10.7 million through fake job interviews

On September 18, 2026, a joint advisory from the FBI, Japan’s police, and several agencies revealed that WaterPlum, a North Korean group, infected more than 30,000 devices across 100-plus countries and siphoned $10.7 million in cryptocurrency through fake job interviews and poisoned repositories. Verify contractor identities and limit their access to source code and credentials.

JFrog Artifactory piles up two exploited authentication flaws, and your binary registry is the next link

On September 11, 2026, CISA added two JFrog Artifactory flaws to the KEV catalog: CVE-2026-42016, which validates a token’s signature without checking its scope, and CVE-2026-42018, which leaks an anonymous token even when anonymous access is disabled. Upgrade to 7.133.11, revoke the affected tokens and audit anonymous access before a poisoned artifact ships to production.

GitLab patches a CVSS 10 arbitrary file-read flaw, exploited within 24 hours

On September 11, 2026, GitLab shipped an out-of-band release for CVE-2026-85706, a CVSS 10 path traversal that reads server files with no authentication via the commits API. The flaw is already being probed in the wild — patch self-managed instances before an attacker reads secrets.yml.

A backdoor compiled into HAProxy intercepts traffic and vanishes from the load balancer’s counters

Rapid7 Labs documents “ted”, an implant compiled directly into HAProxy 2.8.12 at two South Korean companies that intercepts web traffic and erases its own connections from the load balancer’s counters. It requires a prior compromise of the host — verify the integrity of your edge binaries and watch connection counters instead of waiting for an HAProxy patch.

GitHub CLI’s signing key expires September 5, breaking Linux package installs

On Saturday, September 5, 2026, the PGP key that signs GitHub CLI’s APT and RPM repositories expires, and any gh install done before April 8 without a keyring update will start failing. Check your local keyring before the deadline and add the replacement key 7F38BBB59D064DBCB3D84D725612B36462313325.

A poisoned .git/config runs code when Claude Code, Codex or Cursor opens a repository

Manifold Security disclosed on 2 September 2026 eight flaws across seven CLI coding agents: a repository delivered as an archive can trigger a local command on open, outside the sandbox and without approval, via Git’s core.fsmonitor setting. Disable core.fsmonitor by default and inspect .git/config before opening a received folder with an agent.

Gitoxide patches five parsing flaws that leak credentials and traverse directories

On August 30, 2026, the gitoxide project — the pure-Rust implementation of Git — shipped a bundled fix for five parsing vulnerabilities, including an HTTP credential leak and several submodule-based path traversals. The lesson for anyone pulling Rust libraries: memory safety is no substitute for input validation.

Trojanized npm packages ship RedC2 4.0, a Linux backdoor with an AI-assisted C2

On August 20, 2026, Trend Micro disclosed fourteen functional npm packages that drop RedShell, the Linux beacon of the RedC2 4.0 C2 framework, with no install hook and no exported function call. Audit your transitive dependencies and recent package additions before a single import compromises your servers.

Docker makes its Verified Publisher program self-serve

On August 20, 2026, Docker opened Verified Publisher applications to self-serve submission from Docker Hub, while keeping a manual review of every application. For teams that consume images, the badge remains a link in the trust chain — not a CVE guarantee.

A GitHub issue with zero repo privileges can run code on Anthropic and Google CI runners — Black Hat 2026 tears apart coding agent trust

On August 5, 2026, Novee Security demonstrated at Black Hat USA that a GitHub issue opened by an account with no write access was enough to execute arbitrary code on the CI runners behind Claude Code, Gemini CLI, and OpenAI Codex repositories. If your CI/CD pipeline executes code from GitHub issues without sandboxing, treat this as a CVE with no patch — yet.

ChainDrop infects 1,300 npm packages and 2 billion monthly downloads

A self-propagating supply-chain attack named ChainDrop compromised over 1,300 packages on the npm registry on August 4, 2026. The infected packages accounted for 2 billion monthly downloads and reached organizations including Deliveroo, Qlik, and ServiceTitan. Audit your dependencies now.

The Cyber Resilience Act Takes Effect — Every Software Dependency Must Be Documented, Signed, and Traceable Within 36 Months

EU Regulation 2024/2847, the Cyber Resilience Act, enters phased application starting in 2026. It requires every software vendor selling in the EU to produce a complete SBOM, fix known vulnerabilities within five business days, and notify critical incidents to ENISA within 24 hours. Here's what your organization must do before the first binding deadline.

Hugging Face Is the New npm — With the Same Supply Chain Vulnerabilities

Three attack waves in eighteen months — nullifAI, ShadowPickle, and a fake OpenAI repository — demonstrate that the AI supply chain is now the weakest link in production deployments. The fixes exist, but they require treating every downloaded model as an untrusted binary.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss