Deadlinesnpm Dependency Security Checklist
Your application inherits the security posture of every package in your dependency tree. With over 500 malicious packages released into npm earlier this year and 80% of npm vulnerabilities surfacing t
Expert perspectives on application security, compliance, and emerging threats
DeadlinesYour application inherits the security posture of every package in your dependency tree. With over 500 malicious packages released into npm earlier this year and 80% of npm vulnerabilities surfacing t
IncidentWhat Happened Snyk s security research team discovered over 200 malicious packages in the npm registry, exploiting dependency confusion attacks to deliver Cobalt Strike payloads. These packages used i
IncidentWhat Happened CVE-2022-33980 allowed attackers to execute arbitrary code through Apache Commons Configuration s string interpolation feature. The vulnerability affected versions 2.4 through 2.7 and st
IncidentWhat Happened Between April 13 and April 15, attackers exploited CVE-2026-3300 , a critical vulnerability in the Everest Forms Pro WordPress plugin, to create rogue administrator accounts on vulnerabl
Get weekly security insights and compliance updates delivered to your inbox.
IncidentA developer on your team merges a routine dependency update. The diff shows a few version bumps in Gemfile.lock . Your CI passes. The code deploys. Three days later, your build server is mining crypto
IncidentWhat Happened In mid-2026, the Miasma worm—a variant of Mini Shai-Hulud—compromised 73 Microsoft GitHub repositories. This attack didn t exploit a traditional vulnerability but instead manipulated the
ResearchYour security team approved an OAuth app six months ago. The publisher s domain is now parked. The app still has read access to your company s Google Drive. This isn t a hypothetical. An OhAuth audit
IncidentWhat Happened On September 29, 2022, Snyk disclosed CVE-2022-40764, a command injection vulnerability in their CLI tool that allowed arbitrary code execution. This flaw affected all versions before 1.
IncidentWhat Happened OpenAI didn t suffer a data breach. Instead, they acknowledged a fundamental architectural risk: ChatGPT s features create multiple pathways for prompt injection attacks to exfiltrate da
IncidentIMPORTANT NOTICE : This teardown analyzes a hypothetical scenario based on researcher predictions about AI worm capabilities. As of this writing, no documented enterprise breach by an autonomous AI wo
ResearchReliaQuest has identified a threat cluster named OP-512 deploying custom web shell frameworks against Microsoft IIS servers, with moderate to high confidence attribution to China-based actors. The fra
IncidentMicrosoft recently expanded its agentic AI security taxonomy with seven new failure modes. These patterns emerged from incidents involving deployed AI systems. If you re running AI agents in productio
IncidentWhat Happened Between March 18 and today, attackers launched over 29,300 attempts to exploit WordPress sites using Everest Forms Pro, a premium form builder plugin. The vulnerability, tracked as CVE-2
IncidentA remote code execution vulnerability in Apache Commons Text surfaced in October 2022, affecting versions 1.5.x through 1.9.x. While not as widespread as Log4Shell, CVE-2022-42889 highlights how trans
IncidentWhat Happened On October 25, 2022, the OpenSSL project announced a critical vulnerability in OpenSSL 3.0.x. The patch was released on November 1, 2022, providing organizations exactly seven days to pr
IncidentA malicious GitHub issue could hijack your entire repository. Security researcher RyotaK demonstrated this by finding a critical flaw in Anthropic s Claude Code GitHub Action, identifying around 50 wa