LIVE · cybersecurity feed
Live wire
CVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEs
nation-state

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

zeroday.news ·

Photo: Lisa Risager from Denmark (CC BY-SA 2.0) via Wikimedia Commons

CrowdSec has reported that an attack involving the compromise of TanStack's npm packages led to the unauthorized copying of approximately 170 of its private GitHub repositories. The incident, which occurred on May 22, was attributed to the compromise of a former employee's laptop. CrowdSec, a French security company, stated that the employee's GitHub access remained active following their departure, and their device was subsequently compromised in a supply chain attack targeting TanStack.

The mechanism of the attack reportedly involved malicious versions of TanStack's npm packages. In a typical software supply chain attack of this nature, an attacker injects malicious code into legitimate software components, such as npm packages, that are widely used by developers. When developers incorporate these compromised packages into their projects, the malicious code can execute on their machines. In this specific case, the malicious npm packages are said to have stolen credentials from the former employee's laptop, which then facilitated unauthorized access to CrowdSec's GitHub repositories.

The affected vendor in this incident is TanStack, a collection of open-source libraries for web development. Products in this category, particularly npm packages, are frequently integrated into development workflows, making them attractive targets for supply chain attacks. The scope of such an attack can be broad, potentially affecting any organization or individual whose development environment incorporates the compromised packages. The incident highlights the inherent risks associated with third-party dependencies in modern software development.

CrowdSec indicated that the attacker leveraged the GitHub access of an employee who had recently left the company. This suggests a lapse in offboarding procedures, where access privileges for departing personnel were not promptly revoked. Maintaining active access for former employees, especially to critical systems like source code repositories, creates a significant security vulnerability that can be exploited if their accounts or devices are compromised.

Typical mitigation guidance for this class of issue includes robust offboarding processes to ensure timely revocation of access for departing employees. Organizations are also advised to implement strong access controls, such as multi-factor authentication (MFA), for all critical systems, including GitHub. Furthermore, supply chain security best practices, such as regularly auditing third-party dependencies, using software composition analysis (SCA) tools, and pinning package versions, can help detect and prevent the use of compromised packages.

This incident underscores the persistent and evolving threat of supply chain attacks, particularly those targeting widely used developer tools and libraries. It also highlights the critical importance of comprehensive identity and access management practices, extending to the secure offboarding of employees. As software development increasingly relies on complex ecosystems of open-source components, organizations must adopt multi-layered security strategies to protect against both external threats and internal vulnerabilities arising from access management oversights.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-58138critical

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

ai

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

security

Flock Offers Employees Buyouts as Customers Flee

As dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.

supply chain attackhigh

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A supply-chain attack on the marketing platform Brevo, formerly Sendinblue, leveraged a compromised Cloudflare API key to inject malicious code into over 100,000 websites. The attackers initially gained access through a SAML SSO vulnerability, compromising customer accounts and exporting data. After blocking the initial breach, they returned and used a stolen Cloudflare API key to deploy a malicious Worker that modified website responses at the edge, bypassing origin server security checks and distributing malware to visitors.

security

Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

ai

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.