Incidentvm2 Sandbox Escapes: A Teardown
What Happened The vm2 library, a widely-used Node.js sandbox for executing untrusted JavaScript code, suffered multiple critical vulnerabilities that allowed attackers to break out of the sandbox and
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened The vm2 library, a widely-used Node.js sandbox for executing untrusted JavaScript code, suffered multiple critical vulnerabilities that allowed attackers to break out of the sandbox and
IncidentWhat Happened Security researchers have disclosed CVE-2026-26956, a critical vulnerability in vm2 , a Node.js library used to execute untrusted JavaScript code in isolated environments. This flaw allo
IncidentWhat Happened An SQL injection vulnerability (CVE-2026-2413) in the Elementor Ally WordPress plugin exposed over 250,000 sites to unauthorized database access. The flaw stemmed from improper handling
IncidentOn April 30, a malicious version of PyTorch Lightning appeared on the Python Package Index (PyPI). This compromised package included a credential-stealing payload targeting .env files, API keys, secre
Get weekly security insights and compliance updates delivered to your inbox.
ResearchUniversity of Massachusetts Dartmouth researchers have introduced VulStyle, a model that detects vulnerabilities by analyzing coding style rather than just syntax or semantics. Pre-trained on approxim
IncidentBetween January 31 and March 9, 2026, attackers deployed 72 malicious extensions on the Open VSX marketplace, affecting 151 GitHub repositories. The campaign, known as GlassWorm, used a two-stage atta
IncidentWhat Happened In early 2025, CISA and four international cybersecurity agencies issued a joint advisory warning about a specific failure mode: agentic AI systems operating with excessive permissions a
GeneralYour AI agents can execute code, access sensitive data, and communicate externally. One in four MCP servers already combines these capabilities. The question isn t whether you re monitoring them—it s
IncidentIncident Overview On March 8, 2026, attackers exploited stolen GitHub personal access tokens to force-push malicious code into legitimate Python repositories. This campaign, known as GlassWorm/ForceMe
IncidentBetween August 2025 and now, PhantomRaven published 126 malicious packages to the npm registry. These packages used slopsquatting—intentional misspellings of popular libraries—to trick JavaScript deve
IncidentWhat Happened On March 5, 2025, CISA added CVE-2025-68613 to its Known Exploited Vulnerabilities catalog. This vulnerability affects n8n, a workflow automation platform used to connect APIs and automa
IncidentYour AI infrastructure just became an exfiltration pipeline. Recent disclosures reveal how Amazon Bedrock, LangSmith, and SGLang each failed fundamental security controls—and how those failures map di
IncidentWhat Happened Between late 2024 and early 2025, attackers compromised 433 code repositories and packages across GitHub, npm, and OpenVSX marketplaces. The malware, known as GlassWorm, infiltrated thes
IncidentWhat Happened On April 29, TeamPCP executed a supply chain attack that compromised over 1,800 developer repositories across PyPI, NPM, and PHP ecosystems. The attackers published malicious versions of
IncidentOn a recent weekend, attackers rewrote nearly every version tag in the aquasecurity/trivy-action repository. Within hours, CI/CD pipelines across hundreds of organizations were executing malicious cod
ResearchThe Problem: Hidden Threats in VS Code Extensions Recently, Socket researchers found 72 malicious Open VSX extensions impersonating popular tools like ESLint and Prettier. The GlassWorm campaign explo