supply-chain Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads A supply chain attack targeting the Rust programming language ecosystem has been discovered, involving a compromised maintainer account publishing malicious versions of three crates – arrayref, internment, and append-only-vec. These crates, including a malicious version of proc-macro1, were designed to execute a remote… The Hacker News · Aug 20, 2026 High supply chaincrates.iorust
threat-intel Shai-Hulud Worm Clones Spread After Code Release The release of Shai-Hulud source code by TeamPCP, a financially motivated threat actor, has triggered the spread of clones targeting software developers and the open-source ecosystem. This incident highlights a new attac… Dark Reading · May 18, 2026 High supply-chainopen-sourcedeveloper
vulnerability Siemens gWAP A remote code execution vulnerability has been identified in Siemens gWAP, stemming from a prototype pollution issue within the Axios HTTP client library. This vulnerability, exploitable through a ‘Gadget’ attack chain,… CISA Advisories · May 14, 2026 High CVE-2026-40175DEremote code executionprototype pollutionaxios