TrapDoor Supply Chain Attack Distributes Credential-Stealing Malware Across Ecosystems
Audit all packages for TrapDoor malware and remove infected ones.
Get 5 things to act on each day — instead of 1,500 articles to read. Free, Builder, or Pro.
Audit all packages for TrapDoor malware and remove infected ones.
Remove mouse5212-super-formatter and audit dependencies for malicious code.
Patch Ghost CMS to fix CVE-2026-26980 immediately.
Patch Drupal Core immediately to the latest version that includes CVE-2026-9082 to stop active exploitation.
Patch critical internet‑exposed systems within 12 hours of detection to comply with CERT‑IN guidelines.
Patch SharePoint to the latest version to mitigate CVE‑2026‑45659.
Patch Yoast SEO Premium to 27.6.1 immediately if using .htaccess redirects and edit_posts capability.
Patch ACF to 6.8.2 immediately to fix frontend form security.
Patch Salesforce and other systems to prevent credential stuffing, enforce MFA, review code for errors, and monitor for suspicious activity.
Patch: Scan Composer packages for malicious package.json entries that download binaries from GitHub Releases, and replace or remove affected packages.
Patch MFA workflows to enforce device‑based second factors and educate users to avoid phishing.
Block GlassWorm C2 domains and monitor for related malware on your network.
Remove or replace the compromised Sicoob.Sdk package and revoke exposed PFX certificates.
Patch all laravel‑lang packages to the latest secure versions and audit dependencies for similar supply‑chain vulnerabilities.
Patch your hosting infrastructure to remove any connections to sanctioned entities and verify compliance with EU sanctions.
Block recruitment‑themed phishing and harden macOS endpoints to defend against targeted cryptocurrency attacks.
Patch NGINX to the latest release (≥1.30.1) immediately to fix CVE-2026-42945, a heap buffer overflow in ngx_http_rewrite_module that is actively exploited.
Patch the kernel to the latest version or apply the rds module mitigation immediately.
Patch Microsoft Defender to the latest update immediately.
Patch the kernel to the latest version that fixes DirtyDecrypt immediately to stop the PoC exploit.
Patch the Linux kernel to the latest version that contains the CVE-2026-46333 fix.
Reserve time and apply the Drupal core security update on 20 May 2026 before 5‑9 UTC.
Apply the Microsoft BitLocker mitigation immediately.
Patch or uninstall the rwl.angular-console v18.95.0 extension immediately to stop the malicious code from running.
Patch all GitHub repositories by rotating secrets and monitoring for unauthorized access after the Nx Console 18.95.0 compromise.
Patch your MFA flow to reject device login requests that contain short codes and verify the request source.
Upgrade Secure Workload to release 3.10.8.3 or 4.0.3.17 and confirm API authentication is enforced.
Delete the compromised actions-cool/issues-helper workflow and replace it with a trusted version or custom action.
Verify the integrity of signed binaries and monitor for unauthorized signing certificates.
Patch Apple M5 devices immediately to mitigate the kernel memory corruption vulnerability discovered using Anthropic’s Mythos.
We use cookies so the comment feature on this site works. Read more