GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests malware reports from OpenSSF’s malicious-packages repository, a public feed in OSV format that launch

GitHub's Dependabot malware alert system has expanded its coverage from a single ecosystem, npm, to include seven additional package ecosystems: PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This enhancement, which became active in August 2026, allows Dependabot to issue malware alerts for packages across all eight supported ecosystems, provided users enable the feature.
The expansion was made possible by integrating GitHub's Advisory Database with the OpenSSF's malicious-packages repository. This public feed, launched in 2023, provides malware reports in OSV format and has accumulated over 15,000 entries covering various threats such as typosquatting, dependency confusion, account takeovers, and malicious prebuilt binaries. Previously, Dependabot's malware detection relied solely on npm data.
Instead of developing separate detection systems for each ecosystem, GitHub engineered a single importer to process the OpenSSF feed. This importer maps the external data into GitHub's existing advisory structure, similar to how it handles RubySec and RustSec advisories. The process involved normalizing data discrepancies, such as differing ecosystem names (e.g., "PyPI" versus "pip"), converting discrete version values into ranges, and consolidating multiple reports for the same package. The system also accounts for retracted advisories, which are stored in a dedicated "osv/withdrawn" folder within the OpenSSF repository.
A key challenge in integrating the OpenSSF feed was avoiding a feedback loop, as GitHub's own npm malware findings already contribute to the OpenSSF repository. To address this, the importer filters out any OSV records tagged "ghsa-malware," which originate from GitHub. This filtering proved crucial, as over half of the new npm reports arriving monthly were found to be such round-trip entries.
Unlike vulnerability advisories, which undergo human review for package mappings, version ranges, and severity before publication, malware advisories are published automatically. This expedited process is intentional, as delaying alerts for credential-stealing packages would benefit attackers. The recent expansion now allows these unreviewed malware advisories to directly trigger Dependabot alerts, a capability that was not available before.
To safeguard against potential compromise of the upstream OpenSSF feed, GitHub has implemented several protective measures. A batch cap limits the number of advisories created in a single import run; exceeding this cap halts the process, publishes nothing, and alerts the engineering team. Every imported advisory retains provenance linking it to the specific upstream commit, enabling rapid tracing of any erroneous advisories. Additionally, entire batches can be reverted as a single unit, streamlining the removal of problematic records.
Dependabot's malware alerts are an opt-in feature. Users must enable them within their repository, organization, or enterprise security settings. Once activated, Dependabot will begin matching dependencies against malware advisories in the Advisory Database, including a backfill against existing advisories. Dependabot currently operates across more than 30 million repositories and over 34 package ecosystems.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed