Fortinet confirmed active exploitation of a critical pre-auth API access bypass in FortiClient Endpoint Management Server, allowing privilege escalation (CVE-2026-35616, CVSS 9.1). Emergency hotfixes are available for FortiClient EMS 7.4.5 and 7.4.6; organizations should patch immediately, restrict EMS exposure, and review logs for anomalous unauthenticated API activity.
Source: Help Net Security
European Commission breach tied to Trivy supply chain attack; 300GB exfiltrated
The European Commission confirmed that attackers linked a breach to the Trivy supply chain attack and stole over 300GB of data from its AWS environment, including personal information. The incident underscores risks from developer tooling; teams should inventory CI/CD dependencies, rotate tokens, and scrutinize cloud access logs for anomalous activity tied to scanning workflows.
Source: SecurityWeek
CISA adds TrueConf Client flaw (CVE-2026-3502) to KEV, signaling active exploitation
CISA added a TrueConf Client vulnerability (CVE-2026-3502, CVSS 7.8) to the Known Exploited Vulnerabilities catalog, indicating in-the-wild exploitation. Given TrueConf’s use in secure and offline environments, agencies and enterprises should prioritize patching or mitigations, enforce application allow‑listing, and monitor for suspicious client update or interprocess activity.
Source: Security Affairs
36 malicious npm packages masquerade as Strapi plugins to drop persistent implants
Researchers uncovered 36 npm packages posing as Strapi CMS plugins that executed postinstall payloads to exploit Redis and PostgreSQL, deploy reverse shells, harvest credentials, and establish persistence. Developers should audit dependencies for suspicious postinstall scripts, purge impacted packages, and rotate database credentials and tokens used in affected builds.
Source: The Hacker News
GitHub Actions under fire: prt-scan supply chain campaign abused pull_request_target
Wiz Research traced six waves of a coordinated GitHub Actions campaign to a single actor, exploiting pull_request_target to run untrusted code; over 500 malicious PRs were sent with roughly 10% success. Organizations should avoid pull_request_target where possible, harden workflows with least-privileged tokens and OIDC, and block Actions from forks unless explicitly required.
Source: Wiz
North Korean group UNC1069 targets Node.js maintainers via fake LinkedIn and Slack
UNC1069 is impersonating recruiters and community contacts on LinkedIn and Slack to social-engineer Node.js package maintainers, aiming to seed malware and compromise open-source releases. Package owners should enforce 2FA, verify identities out-of-band, restrict publisher permissions, and adopt signed releases and protected branches to curb supply chain risk.
Source: HackRead
Post-quantum cryptography urgency grows as research moves ‘Q‑Day’ as early as 2029
New research cited by Google accelerates timelines for quantum threats that could break today’s public-key cryptography, pushing enterprises from awareness to execution. Security leaders should begin crypto inventories, prioritize data with long confidentiality lifetimes, pilot hybrid PQC in protocols, and plan staged migrations aligned with NIST-approved algorithms.
Source: GovTech
You May Also Be Interested In... How critical Axios NPM package got hacked: maintainer shared full story
Qilin ransomware group claims the hack of German political party Die Linke
Hackers Are Posting the Claude Code Leak With Bonus Malware