Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
4 / 154 results
criticalbug_reportVulnerabilityCompromised @antv npm packages deploy credential-stealing malware
Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.
highbug_reportVulnerabilityGrafana breach via unrotated GitHub token after TanStack npm compromise
Grafana Labs infrastructure. Organizations using Grafana products are not directly affected by the breach itself, but should monitor for potential secondary impacts.
criticalbug_reportVulnerabilityReact Server Components RCE flaw enables unauthenticated remote execution
React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.
criticalbug_reportVulnerabilityMicrosoft patches critical WSUS RCE flaw with public PoC exploit
Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.