LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
malware

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests malware reports from OpenSSF’s malicious-packages repository, a public feed in OSV format that launch

zeroday.news ·

GitHub's Dependabot malware alert system has expanded its coverage from a single ecosystem, npm, to include seven additional package ecosystems: PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This enhancement, which became active in August 2026, allows Dependabot to issue malware alerts for packages across all eight supported ecosystems, provided users enable the feature.

The expansion was made possible by integrating GitHub's Advisory Database with the OpenSSF's malicious-packages repository. This public feed, launched in 2023, provides malware reports in OSV format and has accumulated over 15,000 entries covering various threats such as typosquatting, dependency confusion, account takeovers, and malicious prebuilt binaries. Previously, Dependabot's malware detection relied solely on npm data.

Instead of developing separate detection systems for each ecosystem, GitHub engineered a single importer to process the OpenSSF feed. This importer maps the external data into GitHub's existing advisory structure, similar to how it handles RubySec and RustSec advisories. The process involved normalizing data discrepancies, such as differing ecosystem names (e.g., "PyPI" versus "pip"), converting discrete version values into ranges, and consolidating multiple reports for the same package. The system also accounts for retracted advisories, which are stored in a dedicated "osv/withdrawn" folder within the OpenSSF repository.

A key challenge in integrating the OpenSSF feed was avoiding a feedback loop, as GitHub's own npm malware findings already contribute to the OpenSSF repository. To address this, the importer filters out any OSV records tagged "ghsa-malware," which originate from GitHub. This filtering proved crucial, as over half of the new npm reports arriving monthly were found to be such round-trip entries.

Unlike vulnerability advisories, which undergo human review for package mappings, version ranges, and severity before publication, malware advisories are published automatically. This expedited process is intentional, as delaying alerts for credential-stealing packages would benefit attackers. The recent expansion now allows these unreviewed malware advisories to directly trigger Dependabot alerts, a capability that was not available before.

To safeguard against potential compromise of the upstream OpenSSF feed, GitHub has implemented several protective measures. A batch cap limits the number of advisories created in a single import run; exceeding this cap halts the process, publishes nothing, and alerts the engineering team. Every imported advisory retains provenance linking it to the specific upstream commit, enabling rapid tracing of any erroneous advisories. Additionally, entire batches can be reverted as a single unit, streamlining the removal of problematic records.

Dependabot's malware alerts are an opt-in feature. Users must enable them within their repository, organization, or enterprise security settings. Once activated, Dependabot will begin matching dependencies against malware advisories in the Advisory Database, including a backfill against existing advisories. Dependabot currently operates across more than 30 million repositories and over 34 package ecosystems.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

IT threat evolution in Q2 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.

security

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.

finance

IT threat evolution in Q2 2026. Mobile statistics

This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.

security

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository

aicritical

OpenAI locks down Astra over potential critical cyber capabilities

OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The Preparedness Framework, first published in December 2023, outlines how OpenAI evaluates frontier AI risks and determ

ai

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated