Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

22 / 82 results
Active filter:tag: #software-development✕ clear
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI07:31 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm22:06 UTC
Threat actors abuse ChatGPT sharing to host fake OpenAI outage pageshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse ChatGPT sharing to host fake OpenAI outage pages

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…

OpenAI16:21 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm01:04 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette12:32 UTC
Malicious npm package targets Claude AI user data directoryhighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package targets Claude AI user data directory

npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.

npm13:44 UTC
Glassworm botnet targeting developers disrupted via C2 takedownhighbug_reportVulnerability
bug_reportVulnerability

Glassworm botnet targeting developers disrupted via C2 takedown

Software developers and development environments targeted by Glassworm botnet. The botnet leveraged Solana blockchain and BitTorrent DHT for command-and-control infrastructure, indicating attacks against software supply chains.

BleepingComputer11:28 UTC
CrowdStrike, Google disrupt GlassWorm C2 targeting software developershighbug_reportVulnerability
bug_reportVulnerability

CrowdStrike, Google disrupt GlassWorm C2 targeting software developers

Software developers using third-party packages and browser extensions. GlassWorm campaign active since early 2025, distributing malware through supply chain vectors including malicious packages and extensions.

CrowdStrike09:48 UTC
Gitea auth bypass exposes private container images to unauthenticated usershighbug_reportVulnerability
bug_reportVulnerability

Gitea auth bypass exposes private container images to unauthenticated users

Gitea versions prior to 1.26.2. All deployments using Gitea's container registry feature are affected. Unauthenticated remote attackers can pull private container images without credentials.

CVE-2026-2777108:06 UTC
OutSystems Lifetime authorization bypass via user-controlled keyhighbug_reportVulnerability
bug_reportVulnerability

OutSystems Lifetime authorization bypass via user-controlled key

OutSystems Lifetime software. Specific affected versions not disclosed. Vulnerability allows authorization bypass through improper handling of user-controlled keys.

CVE-2026-4012708:55 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm03:59 UTC
Laravel Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel Lang packages compromised to deliver credential-stealing malware

Laravel Lang localization packages distributed via Composer. Affects developers who installed or updated compromised packages during the attack window. Specific package names and versions not yet publicly disclosed.

Laravel18:48 UTC
Supply chain attack compromises 8 Packagist packages with malicious binaryhighbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 8 Packagist packages with malicious binary

Eight Composer packages on Packagist containing JavaScript components. Malicious code injected into package.json files executes a Linux binary from GitHub Releases. Downstream projects using these packages are affected.

Packagist14:07 UTC
Anthropic Glasswing project finds 10,000+ critical flaws in key softwarehighbug_reportVulnerability
bug_reportVulnerability

Anthropic Glasswing project finds 10,000+ critical flaws in key software

Widely used, systemically important software (specific products not disclosed). Over 10,000 high- or critical-severity vulnerabilities identified since project launch last month.

<UNKNOWN>09:55 UTC
Laravel-Lang packages compromised to deliver credential-stealing malwarehighbug_reportVulnerability
bug_reportVulnerability

Laravel-Lang packages compromised to deliver credential-stealing malware

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.

Laravel-Lang07:51 UTC
Megalodon campaign injects 5,718 malicious commits into GitHub reposhighperson_alertThreat Actor
person_alertThreat Actor

Megalodon campaign injects 5,718 malicious commits into GitHub repos

Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.

GitHub09:55 UTC
Chromium zero-day disclosed: JavaScript persists after browser closehighbug_reportVulnerability
bug_reportVulnerability

Chromium zero-day disclosed: JavaScript persists after browser close

Chromium-based browsers (Google Chrome, Microsoft Edge, Brave, Opera, Vivaldi) - specific affected versions not disclosed. Vulnerability remains unpatched at time of disclosure.

Google16:13 UTC
Critical flaws in Sparx Pro Cloud Server actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Critical flaws in Sparx Pro Cloud Server actively exploited in the wild

Sparx Systems Pro Cloud Server and Enterprise Architect products. Specific vulnerable versions not disclosed in summary; CERT.BE advisory should be consulted for version details.

Sparx Systems06:49 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm15:48 UTC
Grafana breach via unrotated GitHub token after TanStack npm compromisehighbug_reportVulnerability
bug_reportVulnerability

Grafana breach via unrotated GitHub token after TanStack npm compromise

Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.

Grafana13:46 UTC
React Server Components RCE flaw enables unauthenticated remote executioncriticalbug_reportVulnerability
bug_reportVulnerability

React Server Components RCE flaw enables unauthenticated remote execution

React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.

Meta13:50 UTC
Microsoft patches critical WSUS RCE flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical WSUS RCE flaw with public PoC exploit

Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.

Microsoft16:42 UTC