A new npm supply chain attack self-branded “Mini Shai-Hulud” compromised four SAP-ecosystem packages on April 29, 2026. Snyk has live advisories. Here’s the technical breakdown, IOCs, and what to do.
Bridge the gap to autonomous fixes. Snyk and Atlassian integrate to transform Jira security tickets into precision fixes using Snyk Studio AI, eliminating context switching and resolving vulnerabilities in minutes.
CVE-2026-40478: The Thymeleaf template injection (CVSS 9.1) is conditional. Patch to 3.1.4+ immediately, and audit your code for dynamic view or template expression misuse, which is the key precondition for exploitability.
Chainguard introduces a 1-day KEV SLA, ensuring exploited vulnerabilities are fixed fast—aligned with how security teams prioritize real-world threats.
Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments.
Snyk Agent Fix upgrades to a new agentic architecture for faster, smarter, and more secure AI-powered code fixes. Now with full Snyk Code language coverage and verified remediation.
Anthropic’s Mythos is reshaping zero-day threats. Learn how Chainguard helps you stay ahead with source-built, continuously secure software supply chains.
Two authentication bypass vulnerabilities (CVE-2026-3965, CVE-2026-4047) in the Qinglong task scheduling panel were exploited in the wild to deploy cryptomining malware. Here’s what happened, how the attacks worked, and what self-hosted application operators should learn from this incident.
Malicious elementary-data version hit PyPI. Chainguard customers stayed protected by detecting malware pre-build and serving only verified safe versions.
Google’s Threat Intelligence teams are focusing on Indirect Prompt Injection (IPI) as a significant threat to AI systems, monitoring for attacks before they affect users. IPI can manipulate AI by embedding harmful prompts in web content, differing from direct injections. Using Common Crawl, researchers identified various types of prompt injections, from harmless pranks to malicious attempts for data theft. While current attacks show limited sophistication, a noted increase in malicious attempts suggests that IPI threats are evolving. Google is actively enhancing defenses against these emerging threats.