Trojanized npm packages, AWS credential leak, Microsoft Defender driver abuse
14 trojanized npm packages deliver RedC2 4.0 Linux backdoor; 9,300 active AWS keys exposed; Microsoft Defender boot driver weaponized for security software deletion.
AI-generated daily briefings and vulnerability analysis for security teams who need signal, not noise.
14 trojanized npm packages deliver RedC2 4.0 Linux backdoor; 9,300 active AWS keys exposed; Microsoft Defender boot driver weaponized for security software deletion.
| CVE | Product | CVSS | Exploited | Patch |
|---|---|---|---|---|
| CVE-2026-16812 | Arista VeloCloud Orchestrator | 10 | KEV | advisory |
| CVE-2026-72898 | Metabase | 10 | KEV | ✓ available |
| CVE-2026-72529 | TrueConf Server | 9.8 | KEV | — |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | 9.8 | KEV | advisory |
| CVE-2026-59310 | Broadcom VMware VCenter | 9.8 | KEV | advisory |
KEV = listed in CISA catalog · IN WILD = active exploitation reported · PoC = public exploit code
14 trojanized npm packages deliver RedC2 4.0 Linux backdoor; 9,300 active AWS keys exposed; Microsoft Defender boot driver weaponized for security software deletion.
Rust crate supply-chain poisoning (245M downloads); Russian cyber espionage hijacking OAuth accounts; Microsoft patches 398 flaws including active exploitation; AI-generated Siemens PLC exploits target U.S. critical infrastructure.
CISA added four actively exploited vulnerabilities affecting Microsoft IKE, VMware vCenter, SharePoint, Dahua devices compromised en masse, and healthcare breaches expose millions.
Microsoft Copilot Personal one-click data exfiltration flaws disclosed. MLflow and FUXA critical vulnerabilities exploited for cloud credential theft. Windows Task Host now actively exploited by ransomware gangs.
59 security tools indexed · free + paid + open source · updated regularly
No tools match your search. Try a different keyword.
Pick up to 4 tools to compare pricing, deployment, and capabilities
Once a day at 04:00 UTC, the pipeline pulls ten authoritative security feeds – including CISA advisories – and extracts the day’s most important stories and the CVEs they cite.
Every CVE is checked against NVD for canonical CVSS and cross-referenced with the CISA KEV catalog. Inline citations link each story to its sources, and a skeptical second AI pass flags – or blocks – claims it can’t substantiate.
Severity is scored from CVSS and confirmed exploitation – not editorial tone – so Critical is rare by design. Structured briefings tell your team exactly what to patch, investigate, or escalate.
Join security professionals who start their morning with defend.network intelligence. Free forever.