Shai-Hulud-Style npm Worm Hits @tanstack
Compromised npm packages tied to @tanstack, @mistralai, @uipath, @squawk, and safe-action stole GitHub credentials and AWS secrets.
Signals are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Coverage • May 12, 2026
Compromised npm packages tied to @tanstack, @mistralai, @uipath, @squawk, and safe-action stole GitHub credentials and AWS secrets.
Decision Insights Threat Desk • May 11, 2026
Casdoor’s Local File System provider lets authenticated upload users traverse paths and write arbitrary files outside $CASDOOR/files/ via /api/upload-resource.
Decision Insights Threat Desk • May 11, 2026
Multiple dnsmasq vulnerabilities could enable cache poisoning, DNSSEC-related DoS, information leakage, and DHCPv6-based local root code execution.
Decision Insights Coverage • May 8, 2026
DirtyFrag is a Linux local privilege escalation using CVE-2026-43284 and CVE-2026-43500, with module-blocking mitigation recommended.
Decision Insights Signals • May 5, 2026
Varonis Systems announced its Data Security Platform achieved High (Alta) certification under Spain’s Esquema Nacional de Seguridad (ENS) at the Royal Decree 311/2022 controls level. The company said the certification expands its audited security, privacy, and controls verification list for public-sector requirements, positioning the platform for compliance and data protection.
Decision Insights Signals • April 22, 2026
Aqua Security introduced Aqua Compass, an MCP server in runtime security workflows, and new runtime risk dashboards that recalculate monetary exposure as controls enforce.
Decision Insights Coverage • April 20, 2026
Netskope Threat Labs reports a ClickFix campaign delivering an AppleScript macOS infostealer that harvests Keychain data and browser session cookies via forced password prompts.
Decision Insights Threat Desk • March 30, 2026
CrewAI has vulnerabilities enabling RCE, arbitrary file read, and SSRF, with multiple CVEs tied to Code Interpreter and Docker fallback.
Decision Insights Threat Desk • March 24, 2026
IDrive Cloud Backup Client for Windows before 7.0.0.63 contains CVE-2026-1995 allowing SYSTEM-level arbitrary executables via writable files.
Decision Insights Threat Desk • January 20, 2026
Safetica's ProcessMonitorDriver.sys in endpoint client x64 has an IOCTL flaw allowing unprivileged users to terminate protected processes.
Decision Insights Threat Desk • January 15, 2026
Redmi Buds 3 Pro–6 Pro contain RFCOMM flaws that can leak call data or trigger firmware crashes over Bluetooth.
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.