August 30, 2026
OpenAI's agents exploited CVE-2026-53362 (a Linux kernel flaw) and a JFrog vulnerability on the company's own infrastructure, prompting CISA to add both to the Known Exploited Vulnerabilities catalog—marking the first KEV entries involving AI agent exploitation. Anthropic is cutting Claude Code usage limits by 17% following demonstrated hijacks of its Opus 5 Auto Mode that succeed roughly 80% of the time via website summarization requests. Rhysida claims 5.79 TB stolen from Berlin's state agencies and is auctioning it; the city has publicly refused to pay ransom ahead of elections. Node.js disclosed six HackerOne-reported vulnerabilities across versions 22.x, 24.x, and 26.x, including HTTP/2 heap use-after-free (CVE-2026-56848) and request smuggling via header truncation (CVE-2026-58044).
August 28, 2026
- A compromised npm release uses Ethereum as a dead drop. Nextron's artifact scanner caught
@testrelic/playwright-analytics 2.13.0, whose obfuscated postinstall resolves a C2 (23.27.20.187:443) via an on-chain lookup, then fetches /boot → /init and evals the JS. Nextron suspects a new EtherHiding variant tied to DPRK operators, and published IOCs and samples (Nextron Research).
· Supply Chain & Takedowns
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 27, 2026
- REDSHELL has changed its packaging again, now shipping the payload as
math.mjs instead of .dat/.bin and surfacing in the npm package hydration-vli-ui (v1.0.0) — executables masquerading as script files, which is a workable YARA hunt (Nextron Research, earlier coverage).
· Software Supply Chain
in When the Sandbox Isn't a Boundary
August 22, 2026
- 14 trojanised npm packages drop the RedC2 4.0 Linux backdoor, which ships AI-assisted command-and-control functionality (The Hacker News).
· Supply Chain
in A CVSS 10.0 Lands in Entra ID — and Microsoft Can't Keep Its Exploitation Story Straight
August 16, 2026
- ChainDrop worm hits the npm supply chain — a self-propagating worm in npm packages is reported to evade standard defenses, the latest in a steady run of registry-borne supply-chain threats. The Register
· Threat Activity
in Bring Your Own EDR: Turning a Commercial Endpoint Agent Into a Trojan Horse
August 1, 2026
- Unit 42 flagged a fresh wave of malicious npm and PyPI packages, 65% previously unknown, spanning
.env credential theft, crypto-wallet stealers, RCE droppers, and — notably — MCP server backdoors aimed specifically at AI developers (Unit 42).
· Supply Chain
in When the Attacker Is a Model: AI Lands on Both Sides of the Fight
July 30, 2026
- Malicious npm packages are delivering RATs on import. Nextron flagged
streak-metricazbd, which drops REDSHELL, a low-detection Linux RAT with credential theft, remote execution and persistence (C2 217.60.77.63), while two @joyfill beta packages carry an import-time implant tied to the DEV#POPPER family. Nextron Research, The Hacker News
· Threat Activity - DPRK's BlueNoroff is now linked to the axios, debug, chalk and typo-crypto npm compromises, per new analysis tying the campaigns to a single threat actor. blackorbird
· Threat Activity
in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius
July 19, 2026
- npm supply-chain attackers exploited a gap in the CI/CD pipeline itself, with Unit 42 also observing an attacker leveraging GitHub Copilot to trigger infection (Unit 42).
· Cloud, Identity & Supply Chain
in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation
July 15, 2026
- Thumper — an open-source tripwire against the Shai-Hulud npm worm (and its evolved cousin "IronWorm"): plant realistic decoy credentials where the worm scans, and get alerted the instant one is read. GitHub
· New Tools & Releases
- A coordinated attack abused a GitHub Actions misconfiguration to steal a privileged token and push malicious npm packages into AsyncAPI repos, delivering multi-stage malware for persistence and exfiltration; separately, three packages (solana-key-utils, crypto-validate-lib, eth-wallet-helpers) impersonate blockchain libraries to steal MetaMask, Phantom, Ledger and Trezor credentials. Wiz, Nextron IOCs, CERT-SE
· Supply Chain
- 148 npm packages disguised as student web proxies quietly turned visitors' browsers into a DDoS botnet for about two weeks in May, using the registry as free hosting for a booby-trapped proxy site, per JFrog. The Hacker News
· Supply Chain
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
July 10, 2026
- npm 12 now disables install scripts by default (
allowScripts off) and deprecates granular access tokens that bypassed 2FA — a meaningful reduction of the postinstall attack surface. The Hacker News
· Supply Chain
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
June 29, 2026
A public exploit for CVE-2026-46331 ("pedit COW"), a critical Linux kernel privilege-escalation flaw, is now actively weaponized as offensive tooling surges, including DriverScope for BYOVD hunting and GitRunner C2 for GitLab-based command-and-control. CVE-2026-55200 in libssh2 also gained a public PoC, enabling client-side code execution from malicious SSH servers. Russian intelligence operators are now stealing Signal Backup Recovery Keys to persistently hijack accounts, while Turla deployed new malware StockStay against Ukraine and ransomware gangs SafePay and RALord show explosive growth alongside emerging leak-site brands SETTRA and REDACT.