This day 02:06 06:06 10:06 14:07 18:07
Info  2026-08-04 18:07Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-08-04 — npm Under Siege, AI Weaponises Vuln Data

Executive summary: Two concurrent npm supply-chain attacks — the self-propagating ChainDrop worm (1,300+ packages) and the Keyv-linked credential-stealing worm (353 poisoned versions) — are flooding the JavaScript ecosystem and demand immediate dependency audits. AI is now actively polluting vulnerability infrastructure: 54 hallucinated SQLite CVEs with fake 9.8 ratings have entered NVD, while Unit 42's NOVA system demonstrates industrialised AI-driven zero-day discovery across OSS. Greatness PhaaS has integrated device-code phishing, extending an already surging attack vector into commercial crimeware.

Top items

Themes

npm supply chain under coordinated assault: Two independent worms (ChainDrop and Keyv-linked) hitting npm simultaneously is unprecedented. Both are self-propagating and target high-download-count packages. Engineering teams should freeze dependency updates, audit lockfiles against known-clean hashes, and monitor for credential exfiltration from developer environments — especially VS Code and Claude Code hook configurations.

AI as a double-edged sword for vulnerability management: The same day Unit 42 demonstrates AI finding 14,000+ real zero-days, we see AI generating 54 fake CVEs polluting NVD. The net effect: vulnerability pipelines will soon be flooded with both legitimate high-volume AI discoveries and AI-generated noise. Triage automation and upstream-source verification become critical.

Phishing industrialisation continues: Greatness adding device-code phishing to a commercial PhaaS platform mirrors the broader trend of sophisticated techniques (MFA bypass, OAuth abuse) trickling down from bespoke APT tooling to subscription crimeware. Defensive focus should shift to conditional access policies that restrict device-code flow authentication.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb