
Miasma Supply Chain Malware Jumps to Go and GitHub Actions
Miasma malware expands from npm to Go and GitHub Actions. CVE-2026-12569 Windchill RCE hits KEV. CL-STA-1062 espionage targets SE Asia governments.
Posts

Miasma malware expands from npm to Go and GitHub Actions. CVE-2026-12569 Windchill RCE hits KEV. CL-STA-1062 espionage targets SE Asia governments.

CVE-2026-20245 gave attackers root on Cisco SD-WAN routers for two months pre-patch. Plus CVSS 9.8 Lantronix OT flaw and 27M credentials recovered.

CVE-2026-20230 SSRF in Cisco Unified CM exploited days after PoC. Mistic RAT feeds six ransomware gangs. Klue supply chain breach hits LastPass.
Six months into 2026 and the breach scoreboard is brutal: 22 million Aflac records, 30 million students locked out during finals, the FBI's own surveillance sys

Russian IAB behind FortiBleed siphoned 110M VPN credentials since February. FFmpeg PixelSmash RCE hits media servers. Squidbleed leaks cleartext creds.

AryStinger botnet turns 4,300 legacy routers into recon proxies. Gravity SMTP plugin exploit harvests WordPress API keys.

CVE-2026-20253 Splunk RCE exploited in the wild with a Sunday CISA deadline. Accenture buys Dragos for $4.1B. FortiBleed hits 86K devices.

FortiBleed leaks VPN credentials for 73,000 FortiGate devices. F5 patches critical NGINX RCE flaws. Cisco ISE root exploit patched.

144 Mastra AI npm packages compromised via hijacked contributor account. CVE-2026-48907 Joomla JCE CVSS 10.0 actively exploited.

Right now, somewhere, an adversary is copying your encrypted VPN traffic. They can't read it today. They're saving it — for the day a quantum computer can crack