IncidentMastra Poisoned via npm Typosquat
On June 17, 2026, Sonatype researchers identified a supply chain attack targeting the Mastra AI framework. The attacker published a malicious npm package named easy-day-js , designed to mimic the popu
Expert perspectives on application security, compliance, and emerging threats
IncidentOn June 17, 2026, Sonatype researchers identified a supply chain attack targeting the Mastra AI framework. The attacker published a malicious npm package named easy-day-js , designed to mimic the popu
IncidentWhat Happened A mid-sized SaaS company discovered a critical remote code execution (RCE) vulnerability in their customer-facing API on day 14 of its exposure. The vulnerability came from an outdated d
IncidentThe Breach: A Summary In early 2020, attackers infiltrated SolarWinds build environment, embedding malicious code into the Orion platform update process. When SolarWinds released the compromised updat
StandardsThese questions come from compliance teams I ve talked to over the past six months. The new PCI DSS v4.0.1 requirements around payment-page scripts caught many organizations off guard. Requirement 6.4
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened A Java application using snakeyaml before version 1.26 processed a malicious YAML file, triggering a Denial of Service vulnerability. The attack exploited YAML s entity expansion feature
IncidentA vulnerability in the Google Cloud Vertex AI SDK allowed attackers to replace legitimate machine learning models with malicious ones—without needing credentials. Discovered by Palo Alto Networks Unit
IncidentWhat Happened Google s Vertex AI SDK for Python versions 1.139.0 and 1.140.0 had a design flaw allowing attackers to execute arbitrary code. The issue arose from predictable cloud storage bucket namin
IncidentWhat Happened In 2019, a former AWS employee exploited a server-side request forgery (SSRF) vulnerability in Capital One s web application firewall configuration to access the EC2 instance metadata se
IncidentOn June 17, 2026, an attacker accessed a dormant npm account belonging to a former Mastra contributor. Within hours, they republished every package in the @mastra scope with a malicious dependency tha
IncidentImmediate Action Required for Federal Agencies The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48907 to its Known Exploited Vulnerabilities Catalog, mandating federal ag
IncidentOn June 3, 2026, the Joomla project released version 2.9.99.5 of its Content Editor (JCE) to patch CVE-2026-48907 , a vulnerability allowing arbitrary PHP code execution. CISA added this flaw to its K
IncidentWhat Happened On June 17, 2026, an attacker compromised a contributor account in the Mastra namespace and published 144 malicious npm packages within 88 minutes. Each package included a dependency on
ResearchYour team s JetBrains environment is now an attack vector. Since October 2025, malicious plugins posing as AI coding assistants have been stealing API keys from developer workstations. Two such plugin
IncidentOn January 14, 2025, security researchers disclosed SearchLeak, a three-stage prompt injection attack that exploited Microsoft Copilot s web search integration to exfiltrate user data through a single
GeneralYour team just implemented a 72-hour cooldown on all npm package updates. You feel safer. You shouldn t. Cooldowns offer a simple, measurable control in security: set a number, enforce it, check a box
IncidentOn June 13, Sansec disclosed a coordinated attack against three WordPress plugins owned by Awesome Motive: PushEngage, OptinMonster, and TrustPulse. Attackers modified JavaScript files served through