Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
Time to start dropping SBOMs FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from tens of thousands – if not more – organizatio...
Related Vulnerabilities
- CVE-2026-35667: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command MEDIUM
- CVE-2026-5207: The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all v MEDIUM
- CVE-2026-35619: OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endp MEDIUM
- CVE-2026-4305: The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
- CVE-2026-4149: Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerabil CRITICAL
Related Coverage
Threat Actors