๐ต๏ธ RESEARCH & DEEP DIVES
- Australia arrests two alleged TeamPCP members over global supply-chain attacks
Australian authorities arrested two alleged TeamPCP members over global supply-chain attacks.- Open-source developers and organizations across government, academia, and the private sector were affected.
- TeamPCP allegedly compromised Trivy, LiteLLM, Telnyx, KICS, TanStack, and other packages and platforms.
- The campaign potentially breached more than 1,000 organizations, stealing over 500,000 credentials and 300 GB of data.
- Attackers injected malicious code into trusted repositories that developers unknowingly incorporated into their systems.
- The Mini Shai-Hulud worm stole credentials and authentication tokens, then self-propagated across package registries and CI/CD environments.
๐ Coverage: techcrunch.com ยท ๐ via Risky Business News
๐ ADVISORIES
- ๐ Source for TranslatePress <=3.3.3 Exposes WordPress Sites to Unauthenticated Stored XSS โ wordfence.com
๐ CVEs & KEV
-
CVE-2026-18983 โ CVSS 7.5 โ One User Avatar | User Profile Picture through 2.5.4 - Authenticated (Subscriber+)...
-
CVE-2026-18324 โ CVSS 7.2 โ Forminator Forms through 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting vi...
-
CVE-2026-18978 โ CVSS 7.2 โ LiteSpeed Cache through 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Co...
-
CVE-2026-77365 โ CVSS 7.2 โ Optimole through 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (abo...
-
CVE-2026-16759 โ CVSS 6.5 โ Tutor LMS through 4.0.5 - Unauthenticated Remote Code Execution via 'template' and...
-
CVE-2026-16654 โ CVSS 6.4 โ Avada (Fusion) Builder through 3.15.6 - Authenticated (Contributor+) Stored Cross-...
-
CVE-2026-3129 โ CVSS 6.4 โ LiteSpeed Cache through 7.7 - Authenticated (Author+) Stored Cross-Site Scripting ...
-
CVE-2026-82081 โ CVSS 6.4 โ wallabag 2 through 2.6.14 allows SSRF because a crafted title or content fiel...
-
CVE-2026-15798 โ CVSS 6.4 โ Smart Slider 3 through 3.5.1.38 - Authenticated (Contributor+) Stored Cross-S...