threat

npm Malware Built for CI:CD and Cloud Compromise

The New Face of Supply Chain Attacks: npm Malware Built for CI/CD and Cloud Compromise

Executive Summary Upwind is tracking an active software supply chain campaign impacting multiple npm packages commonly used across developer tooling, frontend frameworks, CI/CD pipelines, and cloud-native application environments. We identified malicious payloads designed specifically to target CI/CD systems, cloud identities, GitHub credentials, npm publishing workflows, developer machines, and AI developer tooling. The campaign includes install-time…
LiteLLM Supply Chain Breakdown
LiteLLM Supply Chain Breakdown

LiteLLM Supply Chain Breakdown

Executive Summary On March 24, 2026, the popular Python LLM proxy library litellm suffered a critical software supply chain compromise when malicious versions 1.82.7 and 1.82.8 were published directly to PyPI, bypassing the project's normal GitHub-based release process. At the same time, our security team detected malicious commands being executed on CI/CD runners across different…
Trivy Supply Chain Attack: GitHub Actions Compromise
Trivy Supply Chain Attack: GitHub Actions Compromise

Trivy Supply Chain Incident: GitHub Actions Compromise Breakdown

Executive Summary On March 19-20, 2026, the Trivy supply chain incident impacted the trivy project and the GitHub Actions many teams rely on to install and run Trivy in CI/CD pipelines. Late Thursday night, Upwind’s MDR team observed observed anomalous Trivy activity inside a customer environment that deviated from established runtime baselines. The team identified…
Six CVEs in One Day: What’s Going On with n8n?

Six CVEs in One Day: What’s Going On with n8n?

Executive Summary In a single day, six vulnerabilities were disclosed in n8n, spanning remote code execution, command injection, arbitrary file access, and cross-site scripting. All six issues affect authenticated functionality and repeatedly break isolation between workflows, configuration, and the underlying host. This is not random disclosure noise, it’s a clear signal of systemic security weaknesses…
CVE-2026-21858: Ni8mare Enables Unauthenticated RCE in n8n Webhooks
CVE-2026-21858: Ni8mare Enables Unauthenticated RCE in n8n Webhooks

CVE-2026-21858: Ni8mare Enables Unauthenticated RCE in n8n Webhooks

Executive Summary CVE-2026-21858 (Ni8mare) is a critical unauthenticated remote code execution vulnerability in n8n, a widely used workflow automation platform. The flaw is caused by content-type confusion in webhook request handling, allowing attackers to forge uploaded files, read arbitrary local files, forge administrator sessions, and ultimately execute commands on the underlying host. The vulnerability affects…
CVE-2026-21877: Critical Remote Code Execution in n8n
CVE-2026-21877: Critical Remote Code Execution in n8n

CVE-2026-21877: Critical Remote Code Execution in n8n

Executive Summary CVE-2026-21877 is a critical remote code execution vulnerability in n8n that allows an authenticated user to execute arbitrary code on the underlying instance. The issue affects n8n versions >= 0.123.0 and < 1.121.3 and is fixed in 1.121.3 and later. In environments where n8n automates workflows with access to internal systems, credentials, and…
Security Feed - Threat

Shai-Hulud 3.0: npm Supply Chain Worm Reappears With Enhanced Obfuscation

Executive Summary: The Three-Headed Mystery Shai-Hulud 3.0, the sandworm, is back. But is it a new monster, or just the same old worm with a new trick? The security community is currently buzzing about rumors of “Shai-Hulud 3.0.” Reports suggest the sandworm has returned and panic levels are high. But when we look at the…
CVE-2025-68664: LangChain Serialization Injection in dumps() and load()
CVE-2025-68664: LangChain Serialization Injection in dumps() and load()

CVE-2025-68664: LangChain Serialization Injection in dumps() and load()

Executive Summary CVE-2025-68664 is a critical serialization injection vulnerability in LangChain that affects how data is serialized using dumps() and dumpd(), and later reconstructed using load() and loads(). The issue stems from a failure to properly escape user-controlled dictionaries that contain the reserved lc key. Because this key is used internally by LangChain to represent…
A pink graphic shows a penguin inside a circle, symbolizing Linux, and an icon representing printing. The text reads Analyzing the Latest CUPS RCE Vulnerability: Threats and Mitigations with the Upwind logo in the top right corner.

Analyzing the Latest CUPS RCE Vulnerability: Threats and Mitigations

Remote Code Execution (RCE) in CUPS via 'cups-browsed' CUPS (Common Unix Printing System) is a popular printing system for Unix-like systems, with cups-browsed responsible for printer discovery and network browsing. A recent vulnerability in cups-browsed allows Remote Code Execution (RCE) through manipulated printer discovery responses. This vulnerability is caused by insufficient input validation on UDP…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS