Get expert help, fast.
Security Feed
UWV-2026-91346 – AsyncAPI generator ecosystem supply-chain compromise deploys coordinated backdoor
A coordinated supply-chain compromise has impacted multiple official AsyncAPI npm packages across separate repositories and publishing pipelines. Confirmed malicious releases include @asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/specs. The backdoored packages execute attacker-controlled code during normal package use, potentially compromising developer workstations and CI/CD environments. Remove affected versions immediately, pin to verified clean releases, investigate recent installations, and rotate credentials accessible from affected systems.
Malicious jscrambler npm release ships hidden malware via compromised package version
[Under Evaluation]: The npm package [email protected] was published with hidden malware that executes when the compromised dependency is installed/used, enabling supply-chain code execution in downstream builds and runtimes. Remediate by removing [email protected], pinning to a known-good version, auditing CI logs/artifacts for unexpected scripts, and rotating exposed secrets.
Gitea container registry flaw exposes private images to unauthenticated access
[Under Evaluation - CVE-2026-27771]: A flaw in Gitea versions `
containerd CRI plugin unsanitized image LABEL propagation enables host command execution
[Under Evaluation - CVE-2026-53488, CVE-2026-50195, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262]: In containerd CRI plugin versions 1.7-2.3, image configuration LABEL instructions are propagated to containers without sanitization, allowing arbitrary host command execution via a crafted container image. This issue does not require checkpoint/restore. Upgrade to a vendor-fixed containerd build for affected platforms (EKS/ECS/Fargate/Bottlerocket/Amazon Linux).
Apache Tomcat CRL handling flaw in FFM-based connector can fail open on error
[Under Evaluation – CVE-2026-53434]: Apache Tomcat has a flaw in its FFM-based connector when configuring CRLs. Error conditions during CRL processing can proceed without the required action, impacting TLS client certificate revocation enforcement. Affects 11.0.0-M1-11.0.22, 10.1.0-M7-10.1.55, 9.0.83-9.0.118. Upgrade to 11.0.23, 10.1.56, or 9.0.119.
7-Zip Compound Document extraction null pointer dereference leads to denial of service
[Under Evaluation – CVE-2025-53817]: 7-Zip Compound Document extraction is affected by a null pointer dereference in the Compound handler in versions < 25.0.0. An attacker can supply a crafted Compound Document to trigger a crash, causing denial of service (availability impact). Upgrade to 7-Zip 25.0.0 or later to remediate.
Deep Threat Research

Mastra Supply Chain Compromise: easy-day-js Dropper Pulls a Cross-Platform RAT Into @mastra InstallsÂ

From “Encrypt Everything” to “Encrypt for the Quantum Era”: The Upwind Cloud Cryptography Framework

Newly Discovered durabletask Malware Targeted Kubernetes, Cloud Secrets, and CI/CD Infrastructure








