RubyDoc Builds Let Malicious Gems Run Code on Shared Servers
More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
More than 100 malicious gems used RubyDoc documentation builds to execute supplied code. Maintainers should review package and account changes tied to legacy API keys.
Read article →An exploited GitLab flaw exposes arbitrary server files through the commits API. Self-managed operators should install 19.1.8, 19.2.6, or 19.3.2 immediately.
Read article →Kestra OSS versions through 1.3.20 let unauthenticated requests create workflows and run commands as root inside workers. CISA confirms exploitation.
Read article →Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →A public Telerik UI exploit chains two cryptographic oracles to unsafe type loading. Upgrade ASP.NET AJAX to 2026.2.708 and check IIS for post-exploit activity.
Read article →Ten malicious OpenAPI React Query Codegen releases ran on install and carried credential-stealing code with valid provenance. Teams must scope lockfiles, rebuild hosts and rotate credentials.
Read article →Zenity saw file-read probes matching CVE-2026-35029. LiteLLM advises upgrading to 1.83.0 or later; defenders should hunt configuration changes and rotate exposed secrets.
Read article →StyleSmuggler turns poisoned Magento logs into server-side code execution, then hides a persistent implant outside the shop's webroot. Adobe has not issued a fix.
Read article →JetBrains confirmed that an unpatched TeamCity flaw exposed Cadence users’ code and secrets. Former users should rotate credentials and review connected systems.
Read article →Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
Read article →CISA confirms exploitation of a critical Artifactory flaw and requires federal forensic triage. Self-hosted operators have six fixed-version floors to verify.
Read article →A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Read article →CISA confirmed exploitation of a 2019 SQL Server flaw and now requires affected systems to be patched after evidence preservation and forensic triage.
Read article →