search

Sections

Cyber Security

2432 articles

TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack
cybersecurity

TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack

On May 11, 2026, a breach known as the Mini Shai-Hulud worm affected 84 npm package artifacts within 42 @tanstack/* packages, alongside others like @squawk/* and @mistralai/*. The attack utilized a GitHub Actions “Pwn Request,” cache poisoning, and extracted OIDC tokens from runner memory, marking it as the first npm supply chain attack to achieve valid SLSA Build Level 3 attestations. The article outlines the details of the incident, what was compromised, and necessary immediate actions for users.

Blog RSS Feed | Snyk ·
Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
cybersecurity

Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

This research analyzes the Linux kernel privilege escalation vulnerabilities Copy Fail and DirtyFrag, which exploit subtle page cache corruption bugs to create reliable paths to root access. Additionally, Elastic Security Labs is releasing detection logic for these vulnerabilities.

Elastic Security Labs ·
Known Techniques, Unknown Speed: How AI Changes the Attack Chain
cybersecurity

Known Techniques, Unknown Speed: How AI Changes the Attack Chain

TL;DR AI-driven attacks on containerized environments are no longer theoretical. Frontier models can find vulnerabilities in hardened systems in hours and chain them into working exploits before your team has finished triaging the alert. When an attack moves that fast, the time your security program depends on between discovery and exploitation no longer exists. This

Aqua ·