A self-propagating worm compromised hundreds of popular npm packages, harvesting cloud keys and CI tokens then using them to publish further poisoned releases.
Four high-severity vulnerabilities in widely deployed enterprise software — including a build-artefact repository that sits directly in the software supply chain.
Cisco disclosed CVE-2026-20212 (CVSS 9.8), an unauthenticated root code execution flaw on Silicon One-based Nexus 9000 datacenter switches due to open debugging ports.
Researchers logged 7.4 million infected devices between January and June 2026 — a 27% jump — as the infostealer market matured into a fully automated criminal supply chain.
Adversary-in-the-middle phishing now defeats standard MFA at industrial scale. Microsoft tracked a single April 2026 campaign spanning 26 countries in 72 hours.