<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #security</title><description>Articles tagged security on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>An AI agent found 21 ways to attack FFmpeg, the codec library inside almost everything</title><link>https://devtake.dev/article/ffmpeg-21-zero-days/</link><guid isPermaLink="true">https://devtake.dev/article/ffmpeg-21-zero-days/</guid><description>DepthFirst&apos;s agent surfaced 21 FFmpeg zero-days for about $1,000. One 183-byte packet hits RCE. The deeper story is who pays the volunteers who fix them.</description><pubDate>Sat, 13 Jun 2026 13:00:00 GMT</pubDate><category>security</category><category>security</category><category>ffmpeg</category><category>open-source</category><category>rce</category><category>vulnerability</category><category>fuzzing</category><author>luca-reinhardt</author></item><item><title>Red Hat&apos;s npm namespace and Arch&apos;s AUR were both backdoored within two weeks of each other</title><link>https://devtake.dev/article/npm-registry-supply-chain-wave/</link><guid isPermaLink="true">https://devtake.dev/article/npm-registry-supply-chain-wave/</guid><description>A worm hijacked Red Hat&apos;s npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.</description><pubDate>Sat, 13 Jun 2026 12:45:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>open-source</category><category>malware</category><author>luca-reinhardt</author></item><item><title>One bad Host header bypassed auth in Starlette, the routing core under millions of AI agents</title><link>https://devtake.dev/article/ai-agents-package-rce-vulnerability/</link><guid isPermaLink="true">https://devtake.dev/article/ai-agents-package-rce-vulnerability/</guid><description>A flaw in Starlette, downloaded 325M times a week, let a single Host-header character bypass path-based auth across FastAPI, vLLM, and MCP servers.</description><pubDate>Mon, 08 Jun 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>ai-agents</category><category>mcp</category><category>cve-2026-48710</category><category>python</category><category>fastapi</category><author>luca-reinhardt</author></item><item><title>VS Code&apos;s webview sandbox leaks GitHub tokens that read and write every private repo</title><link>https://devtake.dev/article/vscode-zero-day-github-token-theft/</link><guid isPermaLink="true">https://devtake.dev/article/vscode-zero-day-github-token-theft/</guid><description>A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.</description><pubDate>Wed, 03 Jun 2026 13:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>credential-theft</category><category>dev-tools</category><category>rce</category><category>supply-chain</category><category>oauth</category><author>luca-reinhardt</author></item><item><title>Google is patching an Android flaw that attackers are already exploiting in the wild</title><link>https://devtake.dev/article/android-june-2026-zero-day-patch/</link><guid isPermaLink="true">https://devtake.dev/article/android-june-2026-zero-day-patch/</guid><description>Google&apos;s June 2026 Android bulletin patches an actively exploited Framework privilege-escalation zero-day plus 123 other flaws. Here&apos;s who&apos;s at risk and what to do.</description><pubDate>Wed, 03 Jun 2026 11:45:00 GMT</pubDate><category>android</category><category>android</category><category>google</category><category>security</category><category>zero-day</category><category>cve-2025-48595</category><category>patch</category><category>pixel</category><author>naomi-park</author></item><item><title>A browser SSD timing trick can fingerprint your browsing, and cookies won&apos;t stop it</title><link>https://devtake.dev/article/ssd-activity-browser-side-channel/</link><guid isPermaLink="true">https://devtake.dev/article/ssd-activity-browser-side-channel/</guid><description>Graz researchers built FROST, a browser side-channel that times SSD activity to guess which sites and apps you&apos;re running. Here&apos;s how it works and what helps.</description><pubDate>Wed, 03 Jun 2026 11:30:00 GMT</pubDate><category>web</category><category>privacy</category><category>security</category><category>web</category><category>browser-security</category><category>fingerprinting</category><category>side-channel</category><category>supply-chain</category><author>naomi-park</author></item><item><title>116,000 Minecraft PCs got infected by fake mods. The &apos;WeedHack&apos; stealer is free to anyone.</title><link>https://devtake.dev/article/minecraft-weedhack-malware/</link><guid isPermaLink="true">https://devtake.dev/article/minecraft-weedhack-malware/</guid><description>McAfee says a free malware-as-a-service stealer called WeedHack has hit 116,000+ Minecraft systems via fake mods and cheats. Here&apos;s what it grabs and how to clean up.</description><pubDate>Wed, 03 Jun 2026 11:00:00 GMT</pubDate><category>gaming</category><category>gaming</category><category>minecraft</category><category>malware</category><category>security</category><category>credential-theft</category><category>infostealer</category><category>supply-chain</category><author>hiro-tanaka</author></item><item><title>GitHub banned the researcher dropping Windows zero-days. The code was already mirrored everywhere.</title><link>https://devtake.dev/article/github-bans-researcher-windows-zero-day/</link><guid isPermaLink="true">https://devtake.dev/article/github-bans-researcher-windows-zero-day/</guid><description>GitHub wiped Nightmare-Eclipse&apos;s account on May 23 after weeks of unpatched Windows exploits. The ban reopened the oldest fight in security: who decides what research gets hosted?</description><pubDate>Fri, 29 May 2026 06:50:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vulnerability-disclosure</category><category>zero-day</category><category>microsoft</category><category>windows</category><category>supply-chain</category><category>rce</category><author>luca-reinhardt</author></item><item><title>Your car logs every hard brake, and the FTC just banned GM from selling it for five years</title><link>https://devtake.dev/article/connected-car-data-collection-privacy/</link><guid isPermaLink="true">https://devtake.dev/article/connected-car-data-collection-privacy/</guid><description>Connected cars collect location, driving behavior, in-cabin audio, and synced contacts, then route it to automaker clouds, brokers, and insurers. Here&apos;s how to stop it.</description><pubDate>Fri, 29 May 2026 06:35:00 GMT</pubDate><category>security</category><category>security</category><category>privacy</category><category>data-brokers</category><category>surveillance</category><category>connected-cars</category><category>automakers</category><category>ftc</category><author>luca-reinhardt</author></item><item><title>ShinyHunters dumped 9.4GB of 7-Eleven franchisee data after a rejected ransom demand</title><link>https://devtake.dev/article/shinyhunters-7-eleven-breach-185k/</link><guid isPermaLink="true">https://devtake.dev/article/shinyhunters-7-eleven-breach-185k/</guid><description>ShinyHunters breached a 7-Eleven Salesforce instance holding franchisee documents, exposing 185,000 people. The 9.4GB archive hit a leak site after 7-Eleven declined to pay.</description><pubDate>Wed, 27 May 2026 18:35:00 GMT</pubDate><category>security</category><category>security</category><category>data-breach</category><category>shinyhunters</category><category>salesforce</category><category>extortion</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Apple is testing an anti-snatch feature that locks the iPhone the second it&apos;s grabbed</title><link>https://devtake.dev/article/apple-iphone-anti-snatching-auto-lock/</link><guid isPermaLink="true">https://devtake.dev/article/apple-iphone-anti-snatching-auto-lock/</guid><description>Code seen by 9to5Mac points to an iPhone feature that auto-locks when the accelerometer detects a snatch, then clamps down like Stolen Device Protection.</description><pubDate>Wed, 27 May 2026 18:20:00 GMT</pubDate><category>apple</category><category>apple</category><category>iphone</category><category>ios-27</category><category>security</category><category>stolen-device-protection</category><category>theft</category><author>naomi-park</author></item><item><title>Scammers turned a Microsoft notification address into a spam relay. The emails pass SPF, DKIM, and DMARC.</title><link>https://devtake.dev/article/microsoft-internal-account-spam-abuse/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-internal-account-spam-abuse/</guid><description>Spammers found a Tenant Name injection in Entra ID that pushes fraud text into Microsoft&apos;s own OTP emails. The from-line reads msonlineservicesteam@microsoftonline.com.</description><pubDate>Mon, 25 May 2026 12:00:00 GMT</pubDate><category>security</category><category>security</category><category>microsoft</category><category>entra-id</category><category>phishing</category><category>dmarc</category><category>spamhaus</category><category>email-security</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Google&apos;s bug tracker auto-published exploit code for an unpatched Chromium flaw. The bug is still live.</title><link>https://devtake.dev/article/google-chromium-exploit-code-leak/</link><guid isPermaLink="true">https://devtake.dev/article/google-chromium-exploit-code-leak/</guid><description>Chromium Issue 1396278 went public on May 20 because Google&apos;s tracker auto-clears restrictions on stale closed bugs. The flaw, reported in 2022, was never fixed.</description><pubDate>Sun, 24 May 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>chromium</category><category>chrome</category><category>google</category><category>service-workers</category><category>dev-tools</category><category>edge</category><category>browser-security</category><author>luca-reinhardt</author></item><item><title>Anthropic&apos;s Glasswing logged 10,000 vulnerabilities in a month. Most are still waiting on a patch.</title><link>https://devtake.dev/article/anthropic-glasswing-deception-monitor/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-glasswing-deception-monitor/</guid><description>Anthropic says Project Glasswing&apos;s first month produced over 10,000 critical-and-high-severity vulns. Verification and patching is the limiting step.</description><pubDate>Sat, 23 May 2026 09:45:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude-mythos</category><category>project-glasswing</category><category>security</category><category>ai-security</category><category>supply-chain</category><category>vulnerability-disclosure</category><author>dieter-morelli</author></item><item><title>Apple shipped formal proofs for its post-quantum crypto. 2.5 billion devices now run verified code.</title><link>https://devtake.dev/article/apple-corecrypto-formal-verification/</link><guid isPermaLink="true">https://devtake.dev/article/apple-corecrypto-formal-verification/</guid><description>Apple&apos;s SEAR team published formal verification proofs for corecrypto&apos;s ML-KEM and ML-DSA implementations. 50,000 proof steps cover 2.5 billion active devices.</description><pubDate>Sat, 23 May 2026 09:15:00 GMT</pubDate><category>security</category><category>apple</category><category>corecrypto</category><category>post-quantum</category><category>cryptography</category><category>formal-verification</category><category>security</category><category>ml-kem</category><author>luca-reinhardt</author></item><item><title>GitHub&apos;s internal repos were breached. The attacker came in through a poisoned VS Code extension.</title><link>https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</link><guid isPermaLink="true">https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</guid><description>GitHub detected the intrusion on May 18 after a malicious VS Code extension compromised an employee&apos;s device. The attacker claims to have exfiltrated 3,800 internal repositories.</description><pubDate>Fri, 22 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vscode</category><category>supply-chain</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Microsoft is killing SMS codes on consumer Microsoft accounts. Passkeys take over by December.</title><link>https://devtake.dev/article/microsoft-authenticator-sms-passkeys-end/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-authenticator-sms-passkeys-end/</guid><description>Microsoft is phasing out SMS sign-in and recovery on personal Microsoft accounts by December 2026. Replacements: passkeys, Authenticator, or verified email.</description><pubDate>Thu, 21 May 2026 11:30:00 GMT</pubDate><category>security</category><category>microsoft</category><category>passkeys</category><category>sms</category><category>authentication</category><category>fido2</category><category>microsoft-authenticator</category><category>sim-swap</category><category>security</category><author>luca-reinhardt</author></item><item><title>A CISA contractor left GovCloud admin keys on public GitHub. The file was named &apos;Important AWS Tokens.txt&apos;.</title><link>https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</link><guid isPermaLink="true">https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</guid><description>GitGuardian found a public CISA repo with 844 MB of secrets, including AWS GovCloud admin keys. The repo sat open for six months.</description><pubDate>Thu, 21 May 2026 11:15:00 GMT</pubDate><category>security</category><category>security</category><category>cisa</category><category>github</category><category>supply-chain</category><category>credential-theft</category><category>aws</category><category>gitguardian</category><category>govcloud</category><author>luca-reinhardt</author></item><item><title>A bad command-line parser turned every claude-cli:// link into a remote shell</title><link>https://devtake.dev/article/claude-code-rce-deeplink-cve/</link><guid isPermaLink="true">https://devtake.dev/article/claude-code-rce-deeplink-cve/</guid><description>Joernchen of 0day.click found a deeplink RCE in Claude Code. Anthropic shipped the fix in 2.1.118 the same week.</description><pubDate>Wed, 20 May 2026 09:15:00 GMT</pubDate><category>security</category><category>security</category><category>anthropic</category><category>claude-code</category><category>rce</category><category>ai-security</category><category>supply-chain</category><category>ai-agents</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Twin contractors deleted 96 federal databases in 56 minutes. One asked an AI how to clear the logs.</title><link>https://devtake.dev/article/akhter-twins-opexus-database-deletion/</link><guid isPermaLink="true">https://devtake.dev/article/akhter-twins-opexus-database-deletion/</guid><description>A federal jury convicted Sohaib Akhter on May 7 of wiping 96 government databases at Opexus. His twin Muneeb queried an AI: &apos;how do I clear system logs from SQL servers.&apos;</description><pubDate>Fri, 15 May 2026 09:00:00 GMT</pubDate><category>security</category><category>security</category><category>insider-threat</category><category>opexus</category><category>eeoc</category><category>credential-theft</category><category>foia</category><category>policy</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>F5 patched an 18-year-old NGINX bug. Attackers can RCE a third of the web with one crafted request.</title><link>https://devtake.dev/article/nginx-rift-18-year-rce/</link><guid isPermaLink="true">https://devtake.dev/article/nginx-rift-18-year-rce/</guid><description>F5 disclosed CVE-2026-42945 on May 13 after depthfirst&apos;s analyzer found a heap overflow in a 2008 commit. NGINX 1.31.0 ships the patch, every Plus tier needs an upgrade.</description><pubDate>Thu, 14 May 2026 10:30:00 GMT</pubDate><category>security</category><category>security</category><category>nginx</category><category>f5</category><category>cve-2026-42945</category><category>rce</category><category>heap-overflow</category><category>depthfirst</category><category>ai-security</category><author>luca-reinhardt</author></item><item><title>A USB stick now opens a BitLocker drive in 60 seconds. The researcher calls it a backdoor.</title><link>https://devtake.dev/article/yellowkey-bitlocker-zero-day-bypass/</link><guid isPermaLink="true">https://devtake.dev/article/yellowkey-bitlocker-zero-day-bypass/</guid><description>A pseudonymous researcher dropped two unpatched Windows zero-days on May 12. YellowKey bypasses BitLocker via WinRE; Microsoft has not acknowledged either bug.</description><pubDate>Thu, 14 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>bitlocker</category><category>microsoft</category><category>windows</category><category>zero-day</category><category>winre</category><category>tpm</category><category>full-disk-encryption</category><author>luca-reinhardt</author></item><item><title>Six new bugs hit dnsmasq, the DNS daemon in every Linux router. One gives a local attacker root.</title><link>https://devtake.dev/article/dnsmasq-six-cves-cert/</link><guid isPermaLink="true">https://devtake.dev/article/dnsmasq-six-cves-cert/</guid><description>CERT VU#471747 lists six dnsmasq CVEs disclosed May 11. The DHCPv6 flaw is local-root code execution. Simon Kelley credits &apos;a revolution in AI-based security research.&apos;</description><pubDate>Wed, 13 May 2026 09:45:00 GMT</pubDate><category>security</category><category>security</category><category>dnsmasq</category><category>dns</category><category>dhcpv6</category><category>cve-2026-2291</category><category>cve-2026-4892</category><category>cert</category><category>openwrt</category><author>luca-reinhardt</author></item><item><title>TanStack published its npm supply-chain postmortem. The attack chained three GitHub Actions flaws.</title><link>https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</link><guid isPermaLink="true">https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</guid><description>Attackers compromised 42 TanStack packages through a pull_request_target exploit, cache poisoning, and OIDC token theft. An external researcher caught it in 20 minutes.</description><pubDate>Tue, 12 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>tanstack</category><category>github-actions</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>A crafted Ollama model file leaks the whole server&apos;s memory. 300,000 instances are exposed.</title><link>https://devtake.dev/article/ollama-bleeding-llama-cve-2026-7482/</link><guid isPermaLink="true">https://devtake.dev/article/ollama-bleeding-llama-cve-2026-7482/</guid><description>Cyera disclosed CVE-2026-7482 on May 1, a CVSS 9.1 unauthenticated heap read in Ollama. Three API calls dump prompts, env vars, and API keys from any open instance.</description><pubDate>Mon, 11 May 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>ollama</category><category>llm</category><category>cve-2026-7482</category><category>local-inference</category><category>memory</category><category>cyera</category><category>ai-security</category><author>luca-reinhardt</author></item><item><title>A nine-year-old Linux kernel bug gives root in one command. No patch exists yet.</title><link>https://devtake.dev/article/linux-dirty-frag-kernel-privilege-escalation/</link><guid isPermaLink="true">https://devtake.dev/article/linux-dirty-frag-kernel-privilege-escalation/</guid><description>Dirty Frag chains two page-cache flaws in the ESP and RxRPC subsystems into a deterministic privilege escalation that hits every major distro. A PoC exploit is public.</description><pubDate>Sun, 10 May 2026 10:00:00 GMT</pubDate><category>security</category><category>security</category><category>linux</category><category>kernel</category><category>cve-2026-43284</category><category>privilege-escalation</category><category>zero-day</category><category>dirty-frag</category><author>luca-reinhardt</author></item><item><title>380,000 vibe-coded apps are sitting on the open web. 5,000 of them are leaking real data.</title><link>https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</link><guid isPermaLink="true">https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</guid><description>RedAccess found that AI coding tools like Lovable, Base44, and Replit default to public hosting, leaving medical records, bank internals, and corporate secrets indexed by Google.</description><pubDate>Sat, 09 May 2026 08:00:00 GMT</pubDate><category>security</category><category>security</category><category>ai-security</category><category>ai-agents</category><category>dev-tools</category><category>supply-chain</category><category>privacy</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>ShinyHunters hit Canvas LMS for the second time. 275 million student records, 9,000 schools.</title><link>https://devtake.dev/article/instructure-canvas-breach-shinyhunters-275m/</link><guid isPermaLink="true">https://devtake.dev/article/instructure-canvas-breach-shinyhunters-275m/</guid><description>ShinyHunters breached Canvas LMS again, claiming 275 million records from 9,000 schools. Names, emails, student IDs, and private messages exposed.</description><pubDate>Fri, 08 May 2026 09:00:00 GMT</pubDate><category>security</category><category>security</category><category>data-breach</category><category>instructure</category><category>canvas</category><category>shinyhunters</category><category>education</category><category>supply-chain</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>DAEMON Tools shipped a signed backdoor for almost a month. Kaspersky says one school in Russia got the second stage.</title><link>https://devtake.dev/article/daemon-tools-supply-chain-backdoor/</link><guid isPermaLink="true">https://devtake.dev/article/daemon-tools-supply-chain-backdoor/</guid><description>Kaspersky pinned a supply-chain attack on the DAEMON Tools installer dating to April 8. Thousands hit globally, dozens upgraded to a QUIC RAT implant via signed binaries.</description><pubDate>Wed, 06 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>daemon-tools</category><category>malware</category><category>kaspersky</category><category>quic-rat</category><category>code-signing</category><category>windows</category><author>luca-reinhardt</author></item><item><title>Microsoft Edge keeps every saved password in cleartext memory. Microsoft calls it &apos;by design&apos;.</title><link>https://devtake.dev/article/microsoft-edge-cleartext-passwords-memory/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-edge-cleartext-passwords-memory/</guid><description>A researcher showed Edge decrypts the entire password vault at launch and leaves it in process memory. Chrome decrypts on demand. Microsoft says it&apos;s intentional.</description><pubDate>Tue, 05 May 2026 08:45:00 GMT</pubDate><category>security</category><category>security</category><category>microsoft</category><category>edge</category><category>browser-security</category><category>credential-theft</category><category>chromium</category><category>passwords</category><category>privacy</category><author>luca-reinhardt</author></item><item><title>Denuvo&apos;s single-player DRM is fully cracked. 2K is forcing 14-day online check-ins to fight back.</title><link>https://devtake.dev/article/denuvo-cracked-2k-fourteen-day-online/</link><guid isPermaLink="true">https://devtake.dev/article/denuvo-cracked-2k-fourteen-day-online/</guid><description>Pirate trackers hit zero uncracked Denuvo titles for the first time in 12 years. 2K&apos;s response: a token that expires every fortnight and locks you out offline.</description><pubDate>Mon, 04 May 2026 10:10:00 GMT</pubDate><category>gaming</category><category>gaming</category><category>denuvo</category><category>drm</category><category>2k-games</category><category>anti-piracy</category><category>security</category><category>pc-gaming</category><author>hiro-tanaka</author></item><item><title>Five Eyes intel agencies publish first joint agentic AI security guide. Their advice: slow down.</title><link>https://devtake.dev/article/five-eyes-agentic-ai-warning/</link><guid isPermaLink="true">https://devtake.dev/article/five-eyes-agentic-ai-warning/</guid><description>CISA, NSA, GCHQ, ASD, CSE and NCSC-NZ jointly tell organizations agentic AI isn&apos;t ready for fast rollout. The 23-page guide names five risk categories.</description><pubDate>Mon, 04 May 2026 09:50:00 GMT</pubDate><category>security</category><category>security</category><category>ai-security</category><category>ai-agents</category><category>agents</category><category>cisa</category><category>nsa</category><category>policy</category><category>regulation</category><author>luca-reinhardt</author></item><item><title>A DDoS knocked Ubuntu&apos;s update servers offline. The Copy Fail patch landed in the same 24-hour window.</title><link>https://devtake.dev/article/ubuntu-canonical-313-team-ddos-copyfail/</link><guid isPermaLink="true">https://devtake.dev/article/ubuntu-canonical-313-team-ddos-copyfail/</guid><description>The 313 Team flooded Canonical&apos;s infrastructure starting May 1, blocking apt updates and the Ubuntu security API just as admins needed both.</description><pubDate>Sat, 02 May 2026 09:30:00 GMT</pubDate><category>security</category><category>ubuntu</category><category>canonical</category><category>ddos</category><category>copy-fail</category><category>security</category><category>supply-chain</category><category>linux</category><author>luca-reinhardt</author></item><item><title>Mini Shai-Hulud hit PyTorch Lightning. The 11.6M-download PyPI package shipped a credential stealer.</title><link>https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</link><guid isPermaLink="true">https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</guid><description>Two malicious lightning releases hit PyPI on April 30. The 42-minute window was enough to ship an RSA-encrypted infostealer to ML developers worldwide.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>security</category><category>pytorch-lightning</category><category>pypi</category><category>supply-chain</category><category>mini-shai-hulud</category><category>credential-theft</category><category>python</category><category>ml</category><category>security</category><author>luca-reinhardt</author></item><item><title>70 million domains had a no-password root bypass. cPanel rushed an emergency patch.</title><link>https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</link><guid isPermaLink="true">https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</guid><description>cPanel shipped fixes April 28 for a CVSS 9.8 auth bypass that walks attackers into shared-hosting panels with no password. WatchTowr says exploitation started before the patch.</description><pubDate>Fri, 01 May 2026 11:25:00 GMT</pubDate><category>security</category><category>security</category><category>cpanel</category><category>web-hosting</category><category>cve-2026-41940</category><category>auth-bypass</category><category>watchtowr</category><category>credential-theft</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>&apos;Copy Fail&apos; lets a 732-byte script grab root on Ubuntu, RHEL, and SUSE. Patched April 29.</title><link>https://devtake.dev/article/copy-fail-linux-kernel-page-cache-root/</link><guid isPermaLink="true">https://devtake.dev/article/copy-fail-linux-kernel-page-cache-root/</guid><description>CVE-2026-31431 chains AF_ALG and splice() to write into the page cache of /usr/bin/su. Xint Code disclosed it on April 29, nine years after the bug shipped.</description><pubDate>Thu, 30 Apr 2026 09:15:00 GMT</pubDate><category>security</category><category>security</category><category>linux</category><category>cve-2026-31431</category><category>kernel</category><category>privilege-escalation</category><category>supply-chain</category><category>ubuntu</category><category>rhel</category><author>luca-reinhardt</author></item><item><title>Wiz found an RCE in GitHub&apos;s git-push pipeline. The patch shipped in six hours.</title><link>https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</link><guid isPermaLink="true">https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</guid><description>CVE-2026-3854 is a CVSS 8.7 RCE in GitHub&apos;s git-push pipeline. github.com fixed it within hours. 88% of Enterprise Server installs were still vulnerable at disclosure.</description><pubDate>Wed, 29 Apr 2026 09:05:00 GMT</pubDate><category>security</category><category>github</category><category>security</category><category>cve-2026-3854</category><category>rce</category><category>supply-chain</category><category>wiz</category><category>github-actions</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Another npm worm: CanisterWorm hits 16 Namastex packages and reaches PyPI on the same hop</title><link>https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</guid><description>Socket flagged a self-propagating worm in @automagik/genie, pgserve, and 14 sibling Namastex Labs packages. It steals 40 credential categories and republishes itself.</description><pubDate>Tue, 28 Apr 2026 16:30:00 GMT</pubDate><category>security</category><category>npm</category><category>supply-chain</category><category>canisterworm</category><category>security</category><category>namastex</category><category>teampcp</category><category>pypi</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Adobe&apos;s Acrobat zero-day sat on VirusTotal for 136 days. Patch is APSB26-43.</title><link>https://devtake.dev/article/adobe-acrobat-reader-cve-2026-34621/</link><guid isPermaLink="true">https://devtake.dev/article/adobe-acrobat-reader-cve-2026-34621/</guid><description>CVE-2026-34621 is an actively exploited Acrobat and Reader bug that runs attacker JavaScript inside the PDF runtime. The first sample hit VirusTotal in November and went unflagged.</description><pubDate>Tue, 28 Apr 2026 15:30:00 GMT</pubDate><category>security</category><category>adobe</category><category>acrobat</category><category>cve-2026-34621</category><category>security</category><category>zero-day</category><category>virustotal</category><category>expmon</category><category>pdf</category><author>luca-reinhardt</author></item><item><title>Toronto Police arrest three behind &apos;SMS blasters&apos;. Phones lost 911 access for seconds at a time.</title><link>https://devtake.dev/article/sms-blasters-canada-project-lighthouse/</link><guid isPermaLink="true">https://devtake.dev/article/sms-blasters-canada-project-lighthouse/</guid><description>Project Lighthouse logged 13 million cellular disruptions from car-mounted IMSI catchers spoofing legitimate towers. Three men face 44 charges in Canada&apos;s first SMS-blaster bust.</description><pubDate>Mon, 27 Apr 2026 21:00:00 GMT</pubDate><category>security</category><category>security</category><category>smishing</category><category>sms-blaster</category><category>imsi-catcher</category><category>fake-cell-towers</category><category>canada</category><category>cybercrime</category><category>toronto-police</category><author>luca-reinhardt</author></item><item><title>Microsoft April 2026 Patch Tuesday: 167 fixes, two zero-days, and a SharePoint bug already in CISA&apos;s KEV</title><link>https://devtake.dev/article/microsoft-patch-tuesday-april-2026-sharepoint/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-patch-tuesday-april-2026-sharepoint/</guid><description>Microsoft&apos;s April 8 Patch Tuesday closes 167 CVEs. CVE-2026-32201 in SharePoint is being exploited and CISA added it the same day. Here&apos;s what to patch first.</description><pubDate>Mon, 27 Apr 2026 15:00:00 GMT</pubDate><category>security</category><category>microsoft</category><category>patch-tuesday</category><category>cve-2026-32201</category><category>sharepoint</category><category>defender</category><category>zero-day</category><category>security</category><category>cisa-kev</category><author>luca-reinhardt</author></item><item><title>GnuPG 2.5.19 lands ML-KEM in mainline. Post-quantum OpenPGP is no longer a side branch.</title><link>https://devtake.dev/article/gnupg-post-quantum-mainline/</link><guid isPermaLink="true">https://devtake.dev/article/gnupg-post-quantum-mainline/</guid><description>Werner Koch shipped GnuPG 2.5.19 on April 24 with FIPS-203 ML-KEM, the first stable post-quantum encryption algorithm in OpenPGP. Here&apos;s what changed and what didn&apos;t.</description><pubDate>Sun, 26 Apr 2026 11:00:00 GMT</pubDate><category>security</category><category>gnupg</category><category>openpgp</category><category>post-quantum</category><category>ml-kem</category><category>cryptography</category><category>security</category><category>kyber</category><category>encryption</category><author>luca-reinhardt</author></item><item><title>A Discord group guessed Anthropic&apos;s URL pattern and walked into Claude Mythos</title><link>https://devtake.dev/article/anthropic-mythos-breach-discord/</link><guid isPermaLink="true">https://devtake.dev/article/anthropic-mythos-breach-discord/</guid><description>Bloomberg reports a small group accessed Anthropic&apos;s locked-down Mythos model the same day it launched, using credentials from a third-party contractor and educated URL guessing.</description><pubDate>Sat, 25 Apr 2026 11:00:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude-mythos</category><category>ai-security</category><category>supply-chain</category><category>project-glasswing</category><category>mercor</category><category>security</category><author>dieter-morelli</author></item><item><title>Linux 7.1 is yanking ham radio, ISDN, and ATM. The reason: AI bug-report spam.</title><link>https://devtake.dev/article/linux-7-1-ham-radio-isdn-removal/</link><guid isPermaLink="true">https://devtake.dev/article/linux-7-1-ham-radio-isdn-removal/</guid><description>Jakub Kicinski&apos;s networking pull request removes 138,161 lines of decades-old code. Kernel maintainers say LLM-generated bug reports made the old subsystems un-maintainable.</description><pubDate>Fri, 24 Apr 2026 21:00:00 GMT</pubDate><category>open-source</category><category>linux</category><category>linux-kernel</category><category>linux-7-1</category><category>kernel</category><category>ai-security</category><category>networking</category><category>open-source</category><category>security</category><author>soren-vanek</author></item><item><title>Mozilla fixed 271 Firefox bugs that Claude Mythos found. Its own tests caught 22.</title><link>https://devtake.dev/article/mozilla-firefox-mythos-bug-hunt/</link><guid isPermaLink="true">https://devtake.dev/article/mozilla-firefox-mythos-bug-hunt/</guid><description>Firefox 150 shipped Monday with 271 security fixes from Anthropic&apos;s Project Glasswing. Mozilla CTO Bobby Holley says Mythos matches elite human researchers.</description><pubDate>Wed, 22 Apr 2026 13:00:00 GMT</pubDate><category>open-source</category><category>mozilla</category><category>firefox</category><category>anthropic</category><category>claude-mythos</category><category>project-glasswing</category><category>security</category><category>ai-security</category><author>soren-vanek</author></item><item><title>Google just moved &apos;Q-Day&apos; to 2029. Here&apos;s what that changes for your crypto stack</title><link>https://devtake.dev/article/google-q-day-2029-post-quantum-deadline/</link><guid isPermaLink="true">https://devtake.dev/article/google-q-day-2029-post-quantum-deadline/</guid><description>Google&apos;s security team says cryptographically-relevant quantum computers could arrive by 2029, six years before the NSA&apos;s 2031 deadline. What to migrate, and in what order.</description><pubDate>Wed, 15 Apr 2026 17:00:00 GMT</pubDate><category>web</category><category>quantum-computing</category><category>cryptography</category><category>post-quantum</category><category>google</category><category>security</category><category>tls</category><author>luca-reinhardt</author></item></channel></rss>