Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
“Although the affected packages were all Composer packages, the malicious code was not added to composer.json,” Socket said. “Instead, it was inserted into package.json, targeting projects that ship JavaScript
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
Project Glasswing is an effort led by the artificial intelligence (AI) company, as part of which a small set of about 50 partners
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic.
The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek.
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
The affected packages include –
laravel-lang/lang
laravel-lang/http-statuses
laravel-lang/attributes
laravel-lang/actions
“The timing and pattern of the newly published tags
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.
“Any cPanel user (including an attacker or a compromised account) may
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core.
“Drupal Core
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
The disruption of First VPN Service was led by France and the Netherlands, with several other nations supporting the investigation since December
