Critical Bifrost AI Gateway Flaw Let Attackers Run Commands Without Credentials
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
Signal
30 articles covering "supply chain security"
CVE-2026-90898 lets unauthenticated attackers execute arbitrary commands on Bifrost AI gateway servers via a single HTTP request; fixed in transports/v2.1.0.
Security firm Air Security found a zero-click flaw letting a plugin repository owner bypass commit-hash pinning in four AI coding agents.
The indexed-btree npm package evades npm v12's install-script blocking by hiding its malware loader inside a runtime method instead, Checkmarx reports.
The Rust security response working group and crates.io team warn that rust-lang members and popular crate owners are being lured into fake video calls to compromise their devices and accounts.
vlt, a JavaScript package manager built by npm's original developers, ships 1.0 with hosted registries that block malware and phased installs that stop scripts from running automatically.
CISA added CVE-2026-82329, a 9.8-severity Artifactory authentication bypass, to its exploited-vulnerabilities catalog days after JFrog patched it.
AFP, FBI and WA Police charged a 21-year-old and a 23-year-old over the TeamPCP campaign that compromised 1,000+ organizations through open-source developer tools.
OX Security found 24 npm packages built solely to let mirrors like unpkg serve fake Cloudflare CAPTCHA pages that can redirect to ClickFix-style phishing.
Packer 1.16 adds a provenance post-processor and a verify-attestation command, letting teams cryptographically sign and check the origin of every machine image they build.
Flux's new CLI plugin mirrors images, Helm charts, and OCI artifacts into registries teams control, holding back newly signed artifacts to blunt fast-moving supply-chain attacks.
Socket added Firefox extension scanning for enterprise customers days after its researchers uncovered 40 malicious extensions stealing crypto wallet secrets.
A type confusion bug in isolated-vm's ExternalCopy let sandboxed JavaScript corrupt host memory, up to control-flow hijack; patched in 7.0.1 and 6.2.0.