When AI Coding Agents Pull the Wrong Dependency: How a Trojaned PyPI Release Against LiteLLM Triggered Autonomous EDR and Stopped a Chain Reaction
Related Vulnerabilities
- CVE-2026-5994: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the CRITICAL
- CVE-2026-35662: OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing le MEDIUM
- CVE-2026-6069: NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, HIGH
- CVE-2026-29043: HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file MEDIUM
- CVE-2026-4664: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in MEDIUM
Related Coverage
Threat Actors