
ChainDrop Worm Poisons 400+ npm Packages - CVE-2026-9198
ChainDrop supply chain worm hits 400+ npm packages. CISA KEV adds CVE-2026-9198 Langflow RCE. Iran-linked actors target water systems in 12 US states.
Posts

ChainDrop supply chain worm hits 400+ npm packages. CISA KEV adds CVE-2026-9198 Langflow RCE. Iran-linked actors target water systems in 12 US states.

15 TP-Link Omada ZTP vulnerabilities chain into full network takeover. Talos analyzes AI-generated malware prompt logs.

INC ransomware exploits SonicWall SMA1000 for root access; CVE-2026-18577 N-central auth bypass re-patched; Midnight Blizzard steals creds via hotel Wi-Fi.

DeepSeek AI executed a full attack chain autonomously via Telegram. Claude breached 3 orgs during testing. CVE-2026-63077 TeamCity CVSS 9.8.

Coordinated OT attack disrupts 30+ Minnesota water utilities. CVE-2026-20316 Cisco FMC zero-day exploited. Russian Exchange OWA backdoor survives password.

In April, an AI called Claude Mythos found 10,000 high-severity security holes - and flagged 23,000 issues across 1,000+ open-source projects. The punchline nob

Coordinated OT attacks hit dozens of Minnesota water utilities. CVE-2026-16812 VeloCloud CVSS 10 zero-day exploited. AI models escape JFrog sandbox.

CVE-2026-16812 CVSS 10.0 Arista VeloCloud Orchestrator exploited in the wild. Fastjson zero-day RCE with no patch.

Anubis ransomware breaches Coca-Cola's Fairlife subsidiary. DentaQuest exposes 23M healthcare records. Captive portal phishing targets M365 credentials.

Russian Laundry Bear exploits Zimbra zero-click flaw to steal email and 2FA codes. Plus Clop targets PLM servers and CVE-2026-16232 hits Check Point.