skip to content
astropod
sign in
news
Product news and updates from the Gastropod team.
tagged
software-supply-chain-security ×
GitLab CVE-2026-85706 Lets Unauthenticated Attackers Read Server Files; Probing Began the Morning After the Patch
2026-09-18 03:28:59 · Chris
vulnerability-intelligence
software-supply-chain-security
gitlab
+3
ci-cd-security
path-traversal
cisa-kev
Homebrew 7.0.0 Closes Eight Advisories, Including a Cask Flaw That Reached sudo, and Adds a Built-In Vulnerability Scanner
2026-09-18 03:25:45 · Chris
vulnerability-intelligence
software-supply-chain-security
homebrew
+3
macos
osv
developer-workstations
WordPress.org Now Blocks High-Risk Plugin Releases Automatically During a Six-Hour Cooldown
2026-09-18 03:22:56 · last edited 2026-09-18 03:24:44 · Chris
software-supply-chain-security
vulnerability-intelligence
wordpress
+3
plugins
release-cooldown
registry-security
RubyGems Confirms May Campaign That Ran Code on RubyDoc.info Servers; Researchers Attribute It to OpenAI Agents
2026-09-18 03:15:35 · Chris
vulnerability-intelligence
software-supply-chain-security
rubygems
+3
ruby
ai-agents
registry-abuse
A Hijacked AI Coding Assistant Session Installed a Poisoned PyPI Package and Spread Shai-Hulud to About 100 Repositories
2026-09-18 02:34:54 · Chris
vulnerability-intelligence
software-supply-chain-security
pypi
+3
python
ai-coding-assistants
shai-hulud
Compromised JetBrains Cadence due to TeamCity Sever vulnerabilities
2026-09-06 13:09:55 · Chris
vulnerability-intelligence
software-supply-chain-security
ci-cd-security
+3
teamcity
jetbrains
credential-theft
JFrog Artifactory Authentication Bypass Exploited
2026-09-05 03:49:21 · Chris
vulnerability-intelligence
software-supply-chain-security
artifact-registry
+3
authentication-bypass
cisa-kev
ci-cd-security
A BGP Hijack Attack led to attackers swapping a valid package for a malicious one
2026-09-05 03:14:32 · last edited 2026-09-05 03:15:42 · Chris
vulnerability-intelligence
software-supply-chain-security
bgp-hijacking
+3
update-integrity
code-signing
hosting-infrastructure
A Quick Look Back at Bouncy Castle Java 1.85 Patched 32 CVEs, Including a Critical Unvalidated Diffie-Hellman Key Flaw
2026-09-02 04:37:20 · Chris
vulnerability-intelligence
software-supply-chain-security
maven
+2
java
cryptography
Keycloak Account Takeover Flaw
2026-08-28 22:29:29 · Chris
vulnerability-intelligence
software-supply-chain-security
keycloak
+3
identity-and-access-management
oci-containers
maven
16 Typosquatted RubyGems Packages Delivered a Windows Infostealer Through the Native Build Proces
2026-08-27 04:16:20 · Chris
vulnerability-intelligence
software-supply-chain-security
rubygems
+3
ruby
credential-theft
typosquatting
Fourteen npm Packages Working as intended (except for that pesky Linux Backdoor feature)
2026-08-26 02:18:52 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
credential-theft
ci-cd-security
malware
GeoServer's SQL Injection Zero-Day Was Being Scanned For Within Hours of the (irresponsible) Disclosure
2026-08-16 23:02:55 · last edited 2026-08-16 23:03:00 · Chris
vulnerability-intelligence
software-supply-chain-security
maven
+3
java
sql-injection
remote-code-execution
Nearly 800 npm Packages, AI-Generated Names, One Shared Backdoor: Inside WEL1DROPPER
2026-08-15 00:16:35 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
malware
credential-theft
typosquatting
One Endpoint, Full Admin: Inside the Metabase Bug CISA Says to Patch ASAP
2026-08-14 22:31:16 · Chris
vulnerability-intelligence
software-supply-chain-security
sql-injection
+3
business-intelligence
self-hosted-software
zero-day
14,090 Vulnerabilities in Two Months, and 99.4% of Them Have No CVE
2026-08-07 03:38:24 · Chris
vulnerability-intelligence
software-supply-chain-security
ai-security
+3
open-source
dependency-management
sbom
77 Counterfeit Open VSX Extensions, with a Config File That Keeps Installing The
2026-08-06 03:45:21 · last edited 2026-08-06 03:48:28 · Chris
software-supply-chain-security
vulnerability-intelligence
ide-extensions
+3
open-vsx
ci-cd-security
credential-theft
ApostropheCMS's Critical Auth Bypass
2026-08-01 15:02:47 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
node-js
prototype-pollution
transitive-dependencies
No Login Required: TeamCity's Critical RCE and Your Build
2026-08-01 14:21:36 · Chris
vulnerability-intelligence
software-supply-chain-security
ci-cd-security
+3
remote-code-execution
teamcity
jetbrains
PyPI and GitHub Are Racing Against Time for Package Poisoning
2026-07-29 03:15:57 · Chris
software-supply-chain-security
vulnerability-intelligence
pypi
+3
python
package-poisoning
provenance
fastjson 1.x CVE-2026-16723 - yikes!
2026-07-25 17:22:44 · last edited 2026-07-25 17:27:19 · Chris
vulnerability-intelligence
software-supply-chain-security
maven
+3
java
remote-code-execution
deserialization
Langflow's Fifth CIS-KEV CVE in a year
2026-07-25 02:48:46 · Chris
vulnerability-intelligence
software-supply-chain-security
ci-cd-security
Borrowed Compute: How Ten Packagist Libraries Turned GitHub Actions Into an Attack Botnet
2026-07-24 02:49:49 · Chris
vulnerability-intelligence
software-supply-chain-security
composer
+3
github-actions
ci-cd-security
sbom
What the OpenAI/Hugging Face Breach Says About SBOM Blind Spots
2026-07-23 03:58:10 · Chris
vulnerability-intelligence
software-supply-chain-security
sbom
+2
ai-security
provenance
FakeGit: 7,600 Repos, 14 Million Downloads, and an AI Agent Reading the Attacker's README
2026-07-23 03:31:22 · Chris
agentbaiting
software-supply-chain-security
vulnerability-intelligence
+3
github
ai-agents
mcp
ViteVenom: expansion of the ChainVeil campaign
2026-07-21 19:01:22 · last edited 2026-07-21 19:02:29 · Chris
vulnerability-intelligence
sbom
software-supply-chain-security
+3
npm
crypto
credential-theft
Eleven Bytes, No CVE: The OpenSSL HollowByte Flaw That Scanners Miss
2026-07-21 01:02:58 · Chris
vulnerability-intelligence
software-supply-chain-security
openssl
+3
denial-of-service
tls
sbom
Inside the Injective SDK Wallet-Key Theft
2026-07-17 12:49:28 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
crypto
Asyncapi NPM Supply Chain Attack
2026-07-16 22:24:44 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
github-actions
provenance
The npm Package That Only Turned Evil When You Used It
2026-07-16 02:10:15 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
crypto
Braintree.net nuget Typosquat
2026-07-16 01:26:03 · Chris
vulnerability-intelligence
software-supply-chain-security
nuget
+3
net
typosquatting
payment-fraud
Laravel lang tag rewrite supply chain attack
2026-07-16 01:12:30 · Chris
vulnerability-intelligence
software-supply-chain-security
composer
+3
packagist
php
credential-theft
Paysafe/Skrill/Neteller fake SDK/Typosquat Campaign
2026-07-16 01:00:10 · last edited 2026-07-16 01:33:25 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
pypi
typosquatting
credential-theft
The jscrambler npm Compromise
2026-07-16 00:48:52 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
dependency-management
Inside the AsyncAPI "Miasma" Attack: When the Pipeline Itself Becomes the Attacker
2026-07-16 00:34:52 · Chris
vulnerability-intelligence
software-supply-chain-security
supply-chain-attack
+3
npm
ci-cd-security
github-actions