Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
Time to start dropping SBOMs FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from tens of thousands – if not more – organizatio...
Related Vulnerabilities
- CVE-2026-35662: OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing le MEDIUM
- CVE-2026-40086: Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the MEDIUM
- CVE-2026-3690: OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to b HIGH
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-4305: The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
Related Coverage
Threat Actors