Incident8 Million Downloads of Compromised Code
On November 26, 2018, security researchers discovered that event-stream —a widely-used npm package downloaded roughly 2 million times per week—had been compromised. The malicious code, hidden in a dep
Expert perspectives on application security, compliance, and emerging threats
IncidentOn November 26, 2018, security researchers discovered that event-stream —a widely-used npm package downloaded roughly 2 million times per week—had been compromised. The malicious code, hidden in a dep
IncidentWhat Happened In early 2018, Snyk s security research team discovered a directory traversal vulnerability in archive extraction code affecting thousands of projects across multiple ecosystems. The vul
IncidentWhat Happened Between 2016 and 2017, the number of published vulnerabilities across tracked open-source ecosystems jumped 83 percent. The npm and Maven Central repositories — essential for JavaScript
IncidentWhat Happened In September 2018, the maintainer of event-stream —an npm package downloaded 2 million times per week—transferred ownership to a new contributor after months of social engineering. Withi
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened In 2024, the National Institute of Standards and Technology (NIST) s National Vulnerability Database (NVD) reduced its CVE enrichment operations, analyzing fewer vulnerabilities in depth
IncidentWhat Happened Attackers are exploiting CVE-2026-45659 , a remote code execution vulnerability in Microsoft SharePoint. This flaw allows an authenticated user with low privileges to execute arbitrary c
IncidentWhat Happened On December 3, 2018, the Kubernetes security team disclosed CVE-2018-1002105 , a critical vulnerability that allowed any authenticated user to escalate privileges and execute arbitrary c
IncidentWhat Happened Microsoft SharePoint Server contains a deserialization vulnerability (CVE-2026-45659, CVSS 8.8) that allows authenticated attackers to execute arbitrary code remotely. CISA added this vu
IncidentWhat Happened Security researchers at Synacktiv have disclosed a vulnerability in Argo CD s repo-server component that allows code execution and deployment manipulation within Kubernetes clusters. As
IncidentWhat Happened Between late 2024 and early 2025, Anthropic s Claude Mythos Preview AI system identified 1,596 verified vulnerabilities in open-source projects through OSS-Fuzz over a nine-week period.
IncidentWhat Happened Threat actors have exploited publicly accessible AI endpoints that lacked authentication controls. These endpoints—serving large language models, image generation systems, and other AI c
IncidentWhat Happened In June 2026, attackers compromised the Mastra AI framework s npm publishing workflow. This breach allowed adversaries to control the package distribution mechanism, affecting the pipeli
IncidentWhat Happened Cato AI Labs discovered two critical vulnerabilities in Cursor, the AI code editor used by more than half the Fortune 500. Both flaws—CVE-2026-50548 and CVE-2026-50549, each rated 9.8 ou
IncidentWhat Happened In early 2021, an attacker modified a single line in Codecov s Bash Uploader script. This change caused the script to exfiltrate environment variables to an external server before execut
IncidentWhat Happened Adobe released emergency patches for seven vulnerabilities with CVSS scores of 10.0 across ColdFusion and Campaign Classic. These flaws, including CVE-2026-48286, represent the maximum s
IncidentOverview of the Vulnerabilities Adobe has released patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic. These vulnerabilities enable remote code execution through att