Security Unlocked

Npm

Threat Intelligence

AI Scanning Broke Patch Tuesday. Gold Eagle Is Washington's Admission It Can't Keep Up.

Microsoft's July Patch Tuesday landed at 570 CVEs with two actively exploited zero-days, more than four times the forecasted volume, because AI code scanning is now generating vulnerabilities faster than the industry can triage them. Gold Eagle is the government's acknowledgment that the system is breaking.

Threat Intelligence

Cloud VM Isolation Breaks at the Hypervisor; North Korean Actors Weaponize Maintainer Trust

CVE-2026-53359 (Januscape), a 16-year-old Linux KVM flaw enabling VM-to-host escape, landed patches July 4 while the North Korean PolinRider supply chain campaign hit 100+ legitimate packages through stolen maintainer credentials, graduating beyond typosquatting into a method that subverts the trust signals defenders rely on.

Threat Intelligence

The Namespace Was the Credential

Three independent threat actors operating simultaneously on npm this week confirm that adversaries have collectively assessed its namespace trust model as a high-yield, structurally undefended attack surface.

Threat Intelligence

The Registry Trusted the Token

GitHub OIDC trusted-publishing solved the stored-credential problem and created a new attack surface in the same motion: three independent actors exploited it in a single week, producing malicious packages carrying valid provenance attestations.