Info
2026-08-20 22:10Z · last 4h · 8 findings
· glm-5.2:cloud
Threat Brief — 2026-08-20 — Build-Time Malware and Fresh RCEs
Executive Summary
The Rust supply-chain attack first reported this morning is broader than initial coverage suggested — three widely downloaded crates (not just arrayref) were compromised via a maintainer account, injecting build-time infostealer malware. A ThreatsDay roundup surfaces two new RCEs worth tracking: Gogs 10.0 and n8n workflow-to-RCE. The Windows IKE Extension RCE already in CISA KEV received an informational mitigation update — no change to exploit status.
Top items
- Rust crate supply-chain attack scope expands to three crates (245M+ downloads). A compromised maintainer account published malicious versions of three widely used Rust crates on crates.io, each adding a typosquatted dependency whose build script downloaded and executed remote payloads on developer machines. The Rust Project has deleted the malicious versions. This is a developing story: initial reporting (BleepingComputer, 2026-08-20) focused on
arrayref; The HackerNews confirms the campaign hit at least two additional crates with a combined 245 million downloads. Affected developers should auditCargo.lockfor unexpected dependencies and rebuild from clean caches. (src: The Hacker News), (src: BleepingComputer)
- Gogs 10.0 RCE and n8n Workflow-to-RCE disclosed. A ThreatsDay roundup highlights two new remote code execution vulnerabilities: Gogs 10.0 (self-hosted Git service) and n8n (workflow automation platform), both reachable without authentication under certain configurations. Both products are widely self-hosted in enterprise environments; prioritise patching or restricting network exposure until fixes land. (src: The Hacker News)
- Windows IKE Extension RCE (CVE-2026-33824KEV) — mitigation guidance updated. Microsoft pushed a clarifying update to the mitigation for this actively exploited, CISA-KEV-listed vulnerability. This is an informational change only; exploit status and urgency are unchanged. FDE/BYA deadline remains. Originally reported 2026-08-19 by BleepingComputer. (src: MSRC)
Themes
- Build-time trust is under sustained attack. The Rust crate campaign is the latest in a string of supply-chain compromises (npm StubMaker typosquats, arrayref) where malicious code executes at compile time — meaning CI/CD pipelines and developer workstations become the beachhead, not production servers. Lock-file pinning and dependency auditing in CI are now baseline requirements, not nice-to-haves.
- Trusted systems weaponised. The ThreatsDay roundup's framing — "something trusted doing exactly what it was allowed to do" — echoes the signed-driver abuse and legitimate-app blending trends already surfacing this week. Defenders should assume the approved-tools list is part of the attack surface.
