IncidentImageMagick Zero-Days Hit Node.js Apps
Overview of the Vulnerability Multiple severe vulnerabilities in ImageMagick have been disclosed and are being actively exploited. The imagemagick npm package , which integrates ImageMagick for Node.j
Expert perspectives on application security, compliance, and emerging threats
IncidentOverview of the Vulnerability Multiple severe vulnerabilities in ImageMagick have been disclosed and are being actively exploited. The imagemagick npm package , which integrates ImageMagick for Node.j
IncidentOn January 11th, the Snyk security research team disclosed XML External Entity (XXE) vulnerabilities in Nokogiri, a widely-used Ruby XML parsing library. Versions prior to 1.5.4 were vulnerable by def
IncidentUnderstanding the Vulnerability Snyk s security team has disclosed a path traversal vulnerability affecting archive extraction libraries across multiple ecosystems. Known as Zip Slip, this vulnerabili
IncidentOn March 15, 2025, security researchers detected active exploitation of CVE-2026-33017, a critical remote code execution vulnerability in Langflow, a popular low-code framework for building AI workflo
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn November 26, 2018, security researchers discovered that event-stream —a widely-used npm package downloaded roughly 2 million times per week—had been compromised. The malicious code, hidden in a dep
IncidentWhat Happened In early 2018, Snyk s security research team discovered a directory traversal vulnerability in archive extraction code affecting thousands of projects across multiple ecosystems. The vul
IncidentWhat Happened Between 2016 and 2017, the number of published vulnerabilities across tracked open-source ecosystems jumped 83 percent. The npm and Maven Central repositories — essential for JavaScript
IncidentWhat Happened In September 2018, the maintainer of event-stream —an npm package downloaded 2 million times per week—transferred ownership to a new contributor after months of social engineering. Withi
IncidentWhat Happened In 2024, the National Institute of Standards and Technology (NIST) s National Vulnerability Database (NVD) reduced its CVE enrichment operations, analyzing fewer vulnerabilities in depth
IncidentWhat Happened Attackers are exploiting CVE-2026-45659 , a remote code execution vulnerability in Microsoft SharePoint. This flaw allows an authenticated user with low privileges to execute arbitrary c
IncidentWhat Happened On December 3, 2018, the Kubernetes security team disclosed CVE-2018-1002105 , a critical vulnerability that allowed any authenticated user to escalate privileges and execute arbitrary c
IncidentWhat Happened Microsoft SharePoint Server contains a deserialization vulnerability (CVE-2026-45659, CVSS 8.8) that allows authenticated attackers to execute arbitrary code remotely. CISA added this vu
IncidentWhat Happened Between late 2024 and early 2025, Anthropic s Claude Mythos Preview AI system identified 1,596 verified vulnerabilities in open-source projects through OSS-Fuzz over a nine-week period.
IncidentWhat Happened Threat actors have exploited publicly accessible AI endpoints that lacked authentication controls. These endpoints—serving large language models, image generation systems, and other AI c
IncidentWhat Happened In June 2026, attackers compromised the Mastra AI framework s npm publishing workflow. This breach allowed adversaries to control the package distribution mechanism, affecting the pipeli
IncidentWhat Happened Cato AI Labs discovered two critical vulnerabilities in Cursor, the AI code editor used by more than half the Fortune 500. Both flaws—CVE-2026-50548 and CVE-2026-50549, each rated 9.8 ou