Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
Time to start dropping SBOMs FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from tens of thousands – if not more – organizatio...
Related Vulnerabilities
- CVE-2026-5207: The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all v MEDIUM
- CVE-2026-4305: The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
- CVE-2026-35620: OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist MEDIUM
- CVE-2026-35669: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plu HIGH
- CVE-2021-47961: A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows HIGH
Related Coverage
Threat Actors