This day 02:06 06:06 10:06 14:07 18:07
Info  2026-08-04 18:07Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-08-04 — npm Under Siege, AI Weaponises Vuln Data

Executive summary: Two concurrent npm supply-chain attacks — the self-propagating ChainDrop worm (1,300+ packages) and the Keyv-linked credential-stealing worm (353 poisoned versions) — are flooding the JavaScript ecosystem and demand immediate dependency audits. AI is now actively polluting vulnerability infrastructure: 54 hallucinated SQLite CVEs with fake 9.8 ratings have entered NVD, while Unit 42's NOVA system demonstrates industrialised AI-driven zero-day discovery across OSS. Greatness PhaaS has integrated device-code phishing, extending an already surging attack vector into commercial crimeware.

Top items

Themes

npm supply chain under coordinated assault: Two independent worms (ChainDrop and Keyv-linked) hitting npm simultaneously is unprecedented. Both are self-propagating and target high-download-count packages. Engineering teams should freeze dependency updates, audit lockfiles against known-clean hashes, and monitor for credential exfiltration from developer environments — especially VS Code and Claude Code hook configurations.

AI as a double-edged sword for vulnerability management: The same day Unit 42 demonstrates AI finding 14,000+ real zero-days, we see AI generating 54 fake CVEs polluting NVD. The net effect: vulnerability pipelines will soon be flooded with both legitimate high-volume AI discoveries and AI-generated noise. Triage automation and upstream-source verification become critical.

Phishing industrialisation continues: Greatness adding device-code phishing to a commercial PhaaS platform mirrors the broader trend of sophisticated techniques (MFA bypass, OAuth abuse) trickling down from bespoke APT tooling to subscription crimeware. Defensive focus should shift to conditional access policies that restrict device-code flow authentication.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db