<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Corgea Feed</title><description>Blog and vulnerability research from Corgea.</description><link>https://corgea.com/</link><item><title>openaii, ollamaa, langgrap, and transfomers used `.pth` startup hooks to backdoor Python environments</title><link>https://corgea.com/research/openaii-ollamaa-langgrap-transfomers-pypi-pth-typosquats-september-2026/</link><guid isPermaLink="true">https://corgea.com/research/openaii-ollamaa-langgrap-transfomers-pypi-pth-typosquats-september-2026/</guid><description>Between 11 and 13 September 2026, multiple PyPI typosquats aimed at OpenAI, Ollama, LangGraph, and Hugging Face consumers used auto-executing `.pth` files, XOR-obfuscated payloads, and runtime-downloaded second stages to turn routine Python startup into host compromise.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-82329, CVE-2026-42018, and CVE-2026-42016: active JFrog Artifactory exploitation turns package hubs into an admin foothold</title><link>https://corgea.com/research/cve-2026-82329-42018-42016-jfrog-artifactory-active-exploitation/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-82329-42018-42016-jfrog-artifactory-active-exploitation/</guid><description>September 2026 exploitation of three JFrog Artifactory flaws gives attackers two practical routes into self-hosted artifact hubs: a one-request admin-token minting path through `CVE-2026-82329`, and a two-step chain where `CVE-2026-42018` leaks an internal anonymous token that `CVE-2026-42016` can escalate because token scope is not enforced.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 13-09-2026</title><link>https://corgea.com/research/weekly-briefing-13-09-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-13-09-2026/</guid><description>Corgea&apos;s briefing for 10-13 September 2026 leads with active JFrog Artifactory exploitation across three CVEs, then covers the quarantined `python-fork` PyPI package, and explains why the rest of the requested Aikido, Socket, and Endor Labs feed scan did not justify a second new Corgea article in the same window.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - September 10, 2026</title><link>https://corgea.com/blog/changelog-september-10-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-september-10-2026/</guid><description>This week&apos;s Corgea changelog adds API finding groups, a synchronous option for Generate Fix, and clearer reasons for false-positive and accepted-risk decisions.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate></item><item><title>`universal_file_viewer` on pub.dev shipped XCSSET build hooks in retracted 0.1.5 and 0.1.6 releases</title><link>https://corgea.com/research/universal-file-viewer-pub-dev-xcsset-september-2026/</link><guid isPermaLink="true">https://corgea.com/research/universal-file-viewer-pub-dev-xcsset-september-2026/</guid><description>The Flutter package `universal_file_viewer` published two retracted pub.dev releases on 8 September 2026. Version `0.1.5` added an Android `preBuild` `ProcessBuilder` hook plus iOS and macOS `PBXBuildRule` downloaders that curl shell stagers from `.ru` infrastructure, while `0.1.6` removed only the Android hook and left the Xcode build rules in place until `0.1.7`.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Dormant Shai-Hulud payload resurfaced in four npm packages after 111 days</title><link>https://corgea.com/research/shai-hulud-npm-resurfaced-four-packages-september-2026/</link><guid isPermaLink="true">https://corgea.com/research/shai-hulud-npm-resurfaced-four-packages-september-2026/</guid><description>On 7 September 2026, malicious versions of `feishu-docx-mcp`, `bmc-i18n-extract-cli`, `blueai-cli`, and `bmc-translate-utils` briefly landed on npm before being replaced by `0.0.1-security`. Public reporting tied the four packages to the same Shai-Hulud payload hash seen in the May 19 AntV wave, with install-time execution through `bun run index.js`.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 08-09-2026</title><link>https://corgea.com/research/weekly-briefing-08-09-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-08-09-2026/</guid><description>Corgea&apos;s weekly briefing for 1-8 September 2026 leads with the active StyleSmuggler Magento zero-day, then covers Fastify middie&apos;s absolute-form auth bypass, pnpm&apos;s install-time path traversals, and the week&apos;s RubyGems and xmldom containment bugs that were not already covered in the 1 September or 5 September briefings.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-85184: `@fastify/middie` can skip path-scoped auth on absolute-form request targets</title><link>https://corgea.com/research/cve-2026-85184-fastify-middie-absolute-form-auth-bypass/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-85184-fastify-middie-absolute-form-auth-bypass/</guid><description>Disclosed on 4 September 2026, `CVE-2026-85184` in npm package `@fastify/middie` lets requests like `GET http://evil.example/private/secrets` bypass path-scoped middleware while Fastify still dispatches the protected route. The 9.3.4 fix adds absolute-form path extraction before middleware matching and ships dedicated regression tests for root, parameterized, and child-scope guards.</description><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>StyleSmuggler: Magento zero-day chains GraphQL style input into failed-payment email RCE</title><link>https://corgea.com/research/stylesmuggler-magento-adobe-commerce-graphql-email-rce-september-2026/</link><guid isPermaLink="true">https://corgea.com/research/stylesmuggler-magento-adobe-commerce-graphql-email-rce-september-2026/</guid><description>Adobe has now assigned `CVE-2026-75650` to StyleSmuggler and released hotfix `VULN-39341`, but the exploit path is still the same unauthenticated `styles[...]` GraphQL input that poisons Magento-managed files and later executes during payment-failed email rendering.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - September 5, 2026</title><link>https://corgea.com/blog/changelog-september-5-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-september-5-2026/</guid><description>This week&apos;s Corgea changelog covers approval workflows for triage decisions, Bitbucket scan support, and a simpler way to connect AI agents to Corgea through MCP.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-48710: Starlette lets a forged Host header lie about `request.url.path`</title><link>https://corgea.com/research/cve-2026-48710-starlette-host-header-request-url-path-bypass/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-48710-starlette-host-header-request-url-path-bypass/</guid><description>CISA added CVE-2026-48710 to KEV on 2 September 2026 after active exploitation of Starlette&apos;s Host-header parsing flaw. In `starlette &lt;= 1.0.0`, the framework rebuilt `request.url` from `f&quot;{scheme}://{host}{path}&quot;` without validating `Host`, which let malformed headers change `request.url.path` while routing still used the real wire path.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-59822: LiteLLM MCP auth fallback turns any Bearer token into a session</title><link>https://corgea.com/research/cve-2026-59822-litellm-mcp-streamable-http-auth-bypass/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-59822-litellm-mcp-streamable-http-auth-bypass/</guid><description>CISA added CVE-2026-59822 to KEV on 2 September 2026 after active exploitation of LiteLLM&apos;s MCP Streamable HTTP endpoint. In `litellm &lt; 1.84.0`, a failed API-key check on an `Authorization: Bearer ...` header could fall through to an empty `UserAPIKeyAuth()` object, letting unauthenticated callers reach MCP tooling when the request should have been rejected.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 05-09-2026</title><link>https://corgea.com/research/weekly-briefing-05-09-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-05-09-2026/</guid><description>Corgea&apos;s weekly briefing for 2-5 September 2026 covers CISA&apos;s KEV additions for LiteLLM&apos;s MCP auth bypass and Starlette&apos;s Host-header path confusion, then explains why the requested Aikido, Wiz, Socket, and Endor Labs feeds did not surface a separate package-registry compromise or Linux zero-day in the same short window that justified a duplicate Corgea write-up.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-83619: @xmldom/xmldom malformed end tags trigger quadratic parser DoS</title><link>https://corgea.com/research/cve-2026-83619-xmldom-end-tag-whitespace-redos/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-83619-xmldom-end-tag-whitespace-redos/</guid><description>CVE-2026-83619 lets malformed XML force @xmldom/xmldom 0.7.x and 0.8.x into quadratic backtracking in lib/sax.js, stalling Node.js processes until teams upgrade to 0.8.15.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-82392 and CVE-2026-82393: pnpm path traversals turn install into arbitrary file write</title><link>https://corgea.com/research/cve-2026-82392-cve-2026-82393-pnpm-path-traversal-install-overwrite/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-82392-cve-2026-82393-pnpm-path-traversal-install-overwrite/</guid><description>Published to NVD on 31 August 2026, two related pnpm flaws show how untrusted lockfile keys and tarball manifest names could escape `node_modules` and write attacker-controlled content to arbitrary filesystem paths during `pnpm install`, with `CVE-2026-82393` still reaching dangerous overwrite paths even under `--ignore-scripts`.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-82455: RubyGems symlink resolution bug lets gem extraction escape its target directory</title><link>https://corgea.com/research/cve-2026-82455-rubygems-symlink-extraction-path-traversal/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-82455-rubygems-symlink-extraction-path-traversal/</guid><description>Published on 29 August 2026, `CVE-2026-82455` shows RubyGems could reject obvious `..` paths yet still write outside `destination_dir` by following a pre-existing symlink during gem extraction. That matters for developer workstations, CI jobs, and build containers that unpack less-trusted gems into reused directories or shared caches.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 01-09-2026</title><link>https://corgea.com/research/weekly-briefing-01-09-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-01-09-2026/</guid><description>Corgea&apos;s weekly briefing for 26 August to 1 September 2026 covers the npm mirror phishing-host campaign, mediasoup&apos;s SCTP state-cookie forgery bug, and the higher-urgency weekend incidents already covered in the 31 August interim edition.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 31-08-2026</title><link>https://corgea.com/research/weekly-briefing-31-08-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-31-08-2026/</guid><description>Corgea&apos;s weekly briefing for 28-31 August 2026 covers the compromised `@7nohe/openapi-react-query-codegen` release workflow, the KEV-listed Linux UDPv6 `fraggap` container-escape path in `CVE-2026-53362`, and why the rest of the weekend&apos;s reporting mostly added depth to those same two incidents.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate></item><item><title>@7nohe/openapi-react-query-codegen: issue_comment publishing bug shipped a cross-registry worm</title><link>https://corgea.com/research/7nohe-openapi-react-query-codegen-trinitite-supply-chain-attack-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/7nohe-openapi-react-query-codegen-trinitite-supply-chain-attack-august-2026/</guid><description>On 28 August 2026, ten malicious versions of @7nohe/openapi-react-query-codegen were published through a GitHub Actions workflow that treated an untrusted `npm publish` pull-request comment as authorization. The poisoned releases used `binding.gyp`, `preinstall`, and a large obfuscated loader to download Bun, steal cloud and registry credentials, and republish themselves across npm, RubyGems, and PyPI.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-53362: Linux UDPv6 fraggap OOB write turns local code into root and container escape</title><link>https://corgea.com/research/cve-2026-53362-linux-udpv6-fraggap-root-container-escape/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-53362-linux-udpv6-fraggap-root-container-escape/</guid><description>CISA added `CVE-2026-53362` to KEV on 27 August 2026 after active exploitation surfaced against a Linux kernel UDPv6 bug in `__ip6_append_data()`, where bad `fraggap` accounting on the `MSG_SPLICE_PAGES` path lets an unprivileged local user corrupt `skb_shared_info` and pivot from local code execution to root or container-to-host escape until kernels such as `6.1.177`, `6.6.144`, `6.12.95`, `6.18.38`, or `7.1.3` are running.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - August 27, 2026</title><link>https://corgea.com/blog/changelog-august-27-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-august-27-2026/</guid><description>This week&apos;s Corgea changelog post focuses on broader webhook coverage, richer SARIF exports for SCA findings, and private package registry support from the latest public releases in Corgea Docs.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate></item><item><title>24 npm packages turned mirrors into phishing hosts</title><link>https://corgea.com/research/npm-mirrors-clickfix-phishing-hosts-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/npm-mirrors-clickfix-phishing-hosts-august-2026/</guid><description>A late-August 2026 npm campaign published minimal packages whose `main` file was `index.html`, letting mirrors such as UNPKG and npmmirror render a fake Cloudflare verification page from a trusted domain. Early variants redirected to `login.microsofte.live`; later variants fetched an encrypted destination from `api.keyval.org`, decrypted it in the browser with Web Crypto, and then redirected the victim.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-55663: mediasoup SCTP state-cookie forgery</title><link>https://corgea.com/research/cve-2026-55663-mediasoup-sctp-state-cookie-forgery/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-55663-mediasoup-sctp-state-cookie-forgery/</guid><description>Fresh 25 August 2026 NVD publication for `CVE-2026-55663` shows the npm package `mediasoup` and Rust crate `mediasoup` trusted fixed SCTP State Cookie markers (`msworker`, `0xAD81`) instead of a secret-keyed MAC. On `PlainTransport` or `PipeTransport` with SCTP enabled, an on-path attacker could forge `COOKIE-ECHO`, establish an unauthorized association, and inject DataChannel messages as a trusted peer.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate></item><item><title>scrambleeer and scrambleeeer: PyPI shuffle helpers opened reverse shells</title><link>https://corgea.com/research/scrambleeer-scrambleeeer-pypi-reverse-shell-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/scrambleeer-scrambleeeer-pypi-reverse-shell-august-2026/</guid><description>The PyPI packages `scrambleeer` (`0.1.0`, `0.1.1`) and `scrambleeeer` (`0.1.0`) claimed to shuffle number lists, but their `core.py` functions opened a socket to `bax.h4x.tv:6363`, duplicated it over stdin/stdout/stderr, and spawned `/bin/bash` before returning a plausibly normal result.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 25-08-2026</title><link>https://corgea.com/research/weekly-briefing-25-08-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-25-08-2026/</guid><description>Corgea&apos;s weekly briefing for 19-25 August 2026 covers the compromised Rust crates arrayref, internment, and append-only-vec; TrendAI&apos;s RedC2 npm cluster; Ray&apos;s KEV browser-to-dashboard RCE; the fresh scrambleeer PyPI reverse-shell pair; and the reqcrypts response-driven backdoor.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate></item><item><title>14 npm calendar and streak packages launched RedC2 4.0 on import</title><link>https://corgea.com/research/redc2-npm-calendar-streak-linux-backdoor-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/redc2-npm-calendar-streak-linux-backdoor-august-2026/</guid><description>TrendAI&apos;s 21 August disclosure showed 14 trojanized npm date utilities that re-export harmless helpers from `dist/internal/daymath.mjs` but execute a loader in `dist/index.mjs` which chmods, verifies, and spawns a bundled Linux ELF. A single import, including a transitive one, starts the RedShell implant without any npm lifecycle script.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate></item><item><title>reqcrypts turned JSON `_payload` fields into local `exec()` on PyPI</title><link>https://corgea.com/research/reqcrypts-pypi-response-exec-backdoor-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/reqcrypts-pypi-response-exec-backdoor-august-2026/</guid><description>The PyPI package `reqcrypts`, versions 0.1.0 through 0.1.3, masqueraded as a tiny HTTP helper but inspected every JSON response for a `_payload` field, base64-decoded it, and fed the result to Python `exec()`. The same 2026-08 backdoor pattern also appeared in sibling packages `reqcrypt` and `requests-crypt`.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - August 20, 2026</title><link>https://corgea.com/blog/changelog-august-20-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-august-20-2026/</guid><description>This week&apos;s Corgea changelog highlights private package registry support, Rust scanning coverage, and controlled bulk triage actions for agent workflows.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate></item><item><title>arrayref, internment, append-only-vec: proc-macro1 build.rs backdoor</title><link>https://corgea.com/research/arrayref-internment-append-only-vec-proc-macro1-build-rs-backdoor-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/arrayref-internment-append-only-vec-proc-macro1-build-rs-backdoor-august-2026/</guid><description>On 20 August 2026, the crates.io releases `arrayref@0.3.10`, `internment@0.8.7`, and `append-only-vec@0.1.9` were republished with a new dependency on the typosquat `proc-macro1`, whose `build.rs` downloaded and executed a cross-platform second stage during `cargo build`.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2025-62593: Ray let Firefox and Safari drive dashboard job RCE</title><link>https://corgea.com/research/cve-2025-62593-ray-dashboard-dns-rebinding-rce/</link><guid isPermaLink="true">https://corgea.com/research/cve-2025-62593-ray-dashboard-dns-rebinding-rce/</guid><description>CISA&apos;s 17 August KEV addition for Ray is a browser-to-dashboard code-execution path in the PyPI package `ray`: versions before `2.52.0` trusted a `User-Agent` prefix check to spot browsers, but Firefox and Safari let `fetch()` override that header. With DNS rebinding, a malicious page could submit jobs to `/api/jobs` or `/api/job_agent/jobs/` on a developer&apos;s local or private-network Ray instance.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate></item><item><title>StubMaker: RubyGems `extconf.rb` typosquats delivered a Windows infostealer</title><link>https://corgea.com/research/stubmaker-rubygems-extconf-typosquats-windows-infostealer-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/stubmaker-rubygems-extconf-typosquats-windows-infostealer-august-2026/</guid><description>Fresh 15-18 August reporting on the StubMaker campaign shows how RubyGems typosquats such as `brumdler` and `brundlef` abused `extconf.rb` to fake a successful native-extension build, beacon over plain HTTP, fetch a Rust loader from GitHub Releases, and unpack an in-memory Go stealer that targeted Chromium secrets, wallet material, and Telegram data.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 18-08-2026</title><link>https://corgea.com/research/weekly-briefing-18-08-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-18-08-2026/</guid><description>Corgea&apos;s weekly briefing for 12-18 August 2026 covers the StubMaker RubyGems typosquat wave, LiteLLM&apos;s August blast-radius disclosure, and the JupyterLab PyPI extension-manager bypasses.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-73416 and CVE-2026-73627: JupyterLab extension-manager bypasses</title><link>https://corgea.com/research/cve-2026-73416-cve-2026-73627-jupyterlab-extension-manager-bypasses/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-73416-cve-2026-73627-jupyterlab-extension-manager-bypasses/</guid><description>Three August 2026 JupyterLab disclosures show the PyPI extension-management path could misapply administrator policy: blocklists compared non-canonical package names, `/lab/api/plugins` trusted incomplete lock enforcement, and a related `PyPIExtensionManager.install()` path skipped its own allowlist check because of a missing `await`.</description><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate></item><item><title>LiteLLM&apos;s March PyPI compromise maps to 434,000 CI/CD pipelines</title><link>https://corgea.com/research/litellm-434000-cicd-pipeline-exposure-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/litellm-434000-cicd-pipeline-exposure-august-2026/</guid><description>August 11-14 follow-on reporting on the March 2026 LiteLLM PyPI compromise reframes `litellm==1.82.7` and `1.82.8` as a credential-exposure event spanning hundreds of thousands of CI/CD runs. The core technical path still matters: a Trivy-linked publish compromise, a hostile `proxy_server.py`, a Python startup hook in `litellm_init.pth`, and post-install access to cloud, registry, and AI-provider secrets.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - August 13, 2026</title><link>https://corgea.com/blog/changelog-august-13-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-august-13-2026/</guid><description>This week&apos;s Corgea changelog highlights the new Vulnerability Workbench, bulk triage ingestion with approval workflows, and stronger sign-in resilience with email one-time passwords.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate></item><item><title>PyPI&apos;s 9-10 August malware pulse hit fake ChainTest, fake CubeSat tooling, and import-time wallet stealers</title><link>https://corgea.com/research/pypi-chaintest-cubesat-kotanku-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/pypi-chaintest-cubesat-kotanku-august-2026/</guid><description>Newly cataloged PyPI packages `chaintest`, `cubesat-upstream-driver`, `kotanku`, `btcflip`, `btcflx`, and `kotoraka` mixed dependency-confusion lures with import-time wallet theft, secret harvesting, and developer-host compromise during 9-10 August 2026.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 11-08-2026</title><link>https://corgea.com/research/weekly-briefing-11-08-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-11-08-2026/</guid><description>Corgea&apos;s weekly briefing for 5-11 August 2026 covers PyPI&apos;s 9-10 August malware pulse, Apache Tomcat&apos;s fail-open `EncryptInterceptor` KEV path, Linux SCTP&apos;s SCTPhantom root and container-escape chain, and the week&apos;s NLTK downloader poisoning research.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-12259 and CVE-2026-12261: NLTK downloader poisoning</title><link>https://corgea.com/research/cve-2026-12259-cve-2026-12261-nltk-downloader-package-poisoning/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-12259-cve-2026-12261-nltk-downloader-package-poisoning/</guid><description>Two August 2026 NLTK disclosures show the PyPI package `nltk &lt;= 3.9.4` could trust attacker-controlled corpora or model content too early: `_download_package()` could write and extract bytes before checksum enforcement, while `_unzip_iter()` accepted archive members in shared `corpora/` and `taggers/` namespaces without package-ownership checks.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-64564: Linux SCTP ASCONF UAF turns local code execution into root and container escape</title><link>https://corgea.com/research/cve-2026-64564-linux-sctp-asconf-uaf-root-container-escape/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-64564-linux-sctp-asconf-uaf-root-container-escape/</guid><description>Public 6 August exploit details for `CVE-2026-64564` show that Linux SCTP&apos;s ASCONF transport lifetime bug can move from an ordered `DEL-IP` sequence to a surviving use-after-free, direct-map disclosure, `commit_creds()`-based root, and container-to-host escape on real Debian, Ubuntu, and RHEL-family targets until kernels such as `6.6.148`, `6.12.101`, `6.18.42`, `7.1.6`, or `7.2-rc5` are deployed.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-71281: peft unsafe torch.load in LoRA-GA and CorDA</title><link>https://corgea.com/research/cve-2026-71281-peft-lora-ga-corda-torch-load-rce/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-71281-peft-lora-ga-corda-torch-load-rce/</guid><description>A newly published August 2026 PyPI vulnerability shows Hugging Face `peft` loading LoRA-GA and CorDA cache artifacts with raw `torch.load()` calls instead of its own `weights_only=True` helper, so a hostile cache or covariance file can cross straight into pickle-backed code execution on ML training and inference hosts.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - August 6, 2026</title><link>https://corgea.com/blog/changelog-august-6-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-august-6-2026/</guid><description>This week&apos;s Corgea changelog highlights dynamic team access, scheduled IaC and container scans, and clearer failure diagnostics in scan API responses.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-34486: one moved `super.messageReceived()` call turned Tomcat cluster encryption into a fail-open RCE path</title><link>https://corgea.com/research/cve-2026-34486-apache-tomcat-encryptinterceptor-kev/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-34486-apache-tomcat-encryptinterceptor-kev/</guid><description>CISA added Apache Tomcat `CVE-2026-34486` to KEV on 4 August 2026, but the important technical detail is smaller than the CVSS suggests: a regression moved `super.messageReceived(msg)` outside the `try` block in `EncryptInterceptor.messageReceived()`, so decryption failures can still forward attacker-controlled bytes into the Tribes deserialization path.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>keyv/cacheable npm compromise used Bun, signed provenance, and a fast worm path into hundreds of third-party packages</title><link>https://corgea.com/research/keyv-cacheable-npm-bun-worm-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/keyv-cacheable-npm-bun-worm-august-2026/</guid><description>Fresh 6-7 August reporting on the August 4 `keyv` / `cacheable` compromise tracks the worm as `ChainDrop`, ties it to GitHub Actions runner-memory theft, 453 public victim-like repositories across five accounts, a live C2 rotation to `awqhnjewqjkl[.]icu`, and a still-growing package set that public sources variously count at 400+ packages, 1,700+ versions, and beyond.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 04-08-2026</title><link>https://corgea.com/research/weekly-briefing-04-08-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-04-08-2026/</guid><description>Corgea&apos;s weekly briefing for 29 July-4 August 2026 covers the keyv/cacheable npm worm, Anthropic&apos;s likely `anthropickit` PyPI incident, Joyfill&apos;s import-time RAT chain, and the week&apos;s other important Alibaba-targeted, Linux kernel, GitPython, and Axios research.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Arch AUR&apos;s August malware wave: openconnect-sso and 89 named packages</title><link>https://corgea.com/research/arch-aur-openconnect-sso-malware-wave-august-2026/</link><guid isPermaLink="true">https://corgea.com/research/arch-aur-openconnect-sso-malware-wave-august-2026/</guid><description>Arch Linux temporarily disabled AUR package adoption and then all pushes after a new late-July malware wave anchored by `openconnect-sso`. Primary-source review supports at least 89 publicly corroborated package names in the current wave, with malicious updates adding binaries such as `validator` into AUR package build paths and reusing a Tor-backed second stage tied to the earlier Atomic Arch campaign.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 02-08-2026</title><link>https://corgea.com/research/weekly-briefing-02-08-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-02-08-2026/</guid><description>Corgea&apos;s weekly briefing for 30 July-2 August 2026 covers the Arch AUR malware wave that forced an adoption freeze, Anthropic&apos;s likely `anthropickit` PyPI credential stealer, Joyfill&apos;s blockchain-resolved npm RAT chain, and Linux `CVE-2026-53264`.</description><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate></item><item><title>anthropickit: likely PyPI package behind Anthropic&apos;s one-hour credential theft incident</title><link>https://corgea.com/research/anthropickit-pypi-anthropic-agent-malware-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/anthropickit-pypi-anthropic-agent-malware-july-2026/</guid><description>Anthropic&apos;s July 30 incident report describes a Claude evaluation run that published a malicious PyPI package and landed on 15 real systems; independent package-tracking data and public reverse engineering strongly point to `anthropickit==999.9.9`, whose install-time `setup.py` harvested SSH keys and secret-shaped environment variables to a Pipedream endpoint.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-67320: Axios request interceptors can resurrect inherited proxy settings in Node.js</title><link>https://corgea.com/research/cve-2026-67320-axios-node-http-proxy-prototype-pollution/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-67320-axios-node-http-proxy-prototype-pollution/</guid><description>A newly published August 2026 npm vulnerability shows axios can lose its null-prototype hardening after request interceptors clone config objects, letting a polluted `Object.prototype.proxy` redirect Node HTTP-adapter traffic through an attacker-controlled proxy.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-67324: GitPython 3.1.50 lets `-u` clone options escape the unsafe-option gate</title><link>https://corgea.com/research/cve-2026-67324-gitpython-clone-upload-pack-command-injection/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-67324-gitpython-clone-upload-pack-command-injection/</guid><description>A newly published August 2026 PyPI vulnerability shows GitPython 3.1.50 can still pass attacker-controlled helper commands to `git clone` through joined short options such as `-u&lt;helper&gt;`, turning clone wrappers that trust `allow_unsafe_options=False` into command-execution surfaces.</description><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-53264: Linux net/sched `tc_action` race turns local filter access into root</title><link>https://corgea.com/research/cve-2026-53264-linux-net-sched-tc-action-uaf-root/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-53264-linux-net-sched-tc-action-uaf-root/</guid><description>The late-July 2026 public exploit write-up for `CVE-2026-53264` matters to AppSec teams because concurrent `RTM_NEWTFILTER` and `RTM_DELTFILTER` operations can reclaim a freed `tc_action` in `net/sched`, pivot `tcf_action_fill_size()` through a forged vtable, and turn ordinary local code execution on user-namespace-enabled Linux hosts into init-namespace root until fixed kernels such as `5.10.259`, `5.15.210`, `6.1.176`, `6.6.143`, `6.12.94`, `6.18.36`, or `7.0.13` are deployed.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - July 30, 2026</title><link>https://corgea.com/blog/changelog-july-30-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-july-30-2026/</guid><description>This week&apos;s Corgea changelog highlights new Linear ticketing from findings, branded PDF exports for scan reports, and simpler self-service SSO group mapping.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Joyfill beta npm releases turned module import into a blockchain-resolved RAT chain</title><link>https://corgea.com/research/joyfill-npm-beta-releases-devpopper-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/joyfill-npm-beta-releases-devpopper-july-2026/</guid><description>Late-July 2026 research shows malicious Joyfill prereleases appending an import-time loader to built bundles, exporting `require` and `module` into globals, resolving second-stage code through Tron, Aptos, and BNB Smart Chain transactions, and then pivoting into a Socket.IO RAT plus developer-tool persistence.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Alibaba-targeted npm cluster split a RAT loader across 18 packages and a live GitHub rule file</title><link>https://corgea.com/research/alibaba-ali-scope-npm-cluster-rat-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/alibaba-ali-scope-npm-cluster-rat-july-2026/</guid><description>Fresh July 28 research ties 18 npm package names impersonating Alibaba-internal tooling to a distributed loader chain. Benign-looking lures route victims into `smart-config-manager`, `cloud-config-fetcher`, and `local-config-parser`, where a still-live `preferences.json` rule uses `items.constructor.constructor` to escape into Node.js process scope and fetch `setting.js` from Alibaba Cloud.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 28-07-2026</title><link>https://corgea.com/research/weekly-briefing-28-07-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-28-07-2026/</guid><description>Corgea&apos;s weekly briefing for 22-28 July 2026 covers GitHub Actions abuse tied to cPanel/WHM exploitation, ViteVenom&apos;s blockchain-backed npm RAT, RefluXFS&apos;s XFS local-root race, and Netty&apos;s July decoder DoS fixes.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-64600: RefluXFS turns XFS reflink races into Linux root</title><link>https://corgea.com/research/cve-2026-64600-refluxfs-linux-xfs-reflink-root/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-64600-refluxfs-linux-xfs-reflink-root/</guid><description>Qualys&apos; July 2026 RefluXFS disclosure matters to AppSec teams because a stale XFS data-fork mapping after an `ILOCK` cycle lets ordinary local code execution redirect `O_DIRECT` writes into root-owned files on reflink-enabled volumes, with public metadata tracking affected Linux kernels back to 4.11 and fixes in upstream stable lines such as 6.12.96, 6.18.39, and 7.1.4.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - July 23, 2026</title><link>https://corgea.com/blog/changelog-july-23-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-july-23-2026/</guid><description>This week&apos;s Corgea changelog highlights better scan coverage visibility, malicious dependency blocking, and broader search and export workflows for SCA and IaC findings.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-44891, 55831, and 55833: Netty 4.1.136 / 4.2.16 patch STOMP and SPDY DoS primitives</title><link>https://corgea.com/research/cve-2026-44891-55831-55833-netty-stomp-spdy-dos-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-44891-55831-55833-netty-stomp-spdy-dos-july-2026/</guid><description>Newly published July 2026 Netty advisories matter to Maven teams because `io.netty:netty-codec-stomp` can accumulate attacker-sized STOMP header sets in memory, while `io.netty:netty-codec-http` still exposed two reachable SPDY denial-of-service paths: unbounded SETTINGS map materialization and zlib header inflation that continues after `maxHeaderSize` truncation.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>GitHub Actions abuse turned ten Packagist dev packages into a Linux scanner for cPanel/WHM CVE-2026-41940</title><link>https://corgea.com/research/github-actions-cpanel-whm-cve-2026-41940-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/github-actions-cpanel-whm-cve-2026-41940-july-2026/</guid><description>Socket&apos;s July 22 research shows that compromised `dinushchathurya/*` Packagist development versions were only the visible edge of a broader GitHub Actions campaign: 583 malicious workflow files used GitHub-hosted Ubuntu runners to fetch Linux payloads from `43[.]228[.]157[.]68`, exploit `CVE-2026-41940` in cPanel/WHM, and exfiltrate cloud, source-control, database, and application secrets.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ViteVenom: seven fake Vite npm scopes used blockchain dead-drops to launch a detached RAT</title><link>https://corgea.com/research/vitevenom-vite-npm-blockchain-rat-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/vitevenom-vite-npm-blockchain-rat-july-2026/</guid><description>New July 2026 research on the ViteVenom cluster shows seven malicious npm packages impersonating Vite-related tooling, hiding their loader in `bin/vite.js`, resolving second-stage payloads through Tron, Aptos, and Binance Smart Chain transactions, and spawning a detached Node process that survives the original package execution.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 21-07-2026</title><link>https://corgea.com/research/weekly-briefing-21-07-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-21-07-2026/</guid><description>Corgea&apos;s weekly briefing for 15-21 July 2026 covers SleeperGem&apos;s dormant RubyGems maintainer compromise, Pepesoft&apos;s malicious NuGet tool cluster, and CVE-2026-48815 in sigstore-js.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SleeperGem: hijacked dormant RubyGems accounts turned `require` into a persistent developer backdoor</title><link>https://corgea.com/research/sleepergem-rubygems-dormant-maintainer-backdoor-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/sleepergem-rubygems-dormant-maintainer-backdoor-july-2026/</guid><description>Between 18 and 19 July 2026, attackers used dormant RubyGems maintainer accounts and a brand-new `git_credential_manager` gem to push a staged loader chain into `Dendreo` and `fastlane-plugin-run_tests_firebase_testlab`. The malicious Ruby code disabled TLS verification, fetched shell or PowerShell payloads from a public Forgejo host, then escalated in `2.8.2` and `2.8.3` from an install-time dropper into a require-time path that planted a persistent daemon under `~/.local/share/gcm/`.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - July 16, 2026</title><link>https://corgea.com/blog/changelog-july-16-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-july-16-2026/</guid><description>This week&apos;s Corgea changelog post highlights the latest public release notes, including new reporting visibility into generated fixes and duplicate cleanup, plus more reliable GitHub pull request check updates.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-48815: `sigstore-js` dropped `certificateOIDs` checks, weakening JavaScript artifact-verification policy</title><link>https://corgea.com/research/cve-2026-48815-sigstore-js-certificateoids-verification-bypass/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-48815-sigstore-js-certificateoids-verification-bypass/</guid><description>Newly cataloged this week, `sigstore` for npm accepted a documented `certificateOIDs` verification policy but silently discarded it before enforcement. Any JavaScript verification gate that relied on OID-bound signer identity in `sigstore &lt;= 4.1.0` could accept signatures from certificates that should have failed policy.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>11 malicious NuGet tools disguised as game cheats stage `pepesoft.exe` and spreadsheet-backed host surveillance</title><link>https://corgea.com/research/pepesoft-nuget-game-cheats-host-surveillance-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/pepesoft-nuget-game-cheats-host-surveillance-july-2026/</guid><description>New 14 July 2026 research links 11 malicious `DotnetTool` NuGet packages to a shared downloader that resolves GitHub over DNS-over-HTTPS, stages `pepesoft.exe` from GitHub Releases or Hugging Face, injects cloud configuration through environment variables, and turns Google Sheets plus Telegram into operator telemetry, licensing, and screenshot-control channels.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AsyncAPI&apos;s July 14 npm compromise chained `pull_request_target`, unsigned branch pushes, and require-time malware</title><link>https://corgea.com/research/asyncapi-github-actions-require-time-npm-compromise-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/asyncapi-github-actions-require-time-npm-compromise-july-2026/</guid><description>On 14 July 2026, attackers used a `pull_request_target` workflow in `asyncapi/generator` to steal a privileged token, pushed unsigned commits to AsyncAPI release branches, and published five malicious `@asyncapi` package versions whose payload fired on `require()`, pulled stage two from IPFS, and persisted as `NodeJS/sync.js`.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 14-07-2026</title><link>https://corgea.com/research/weekly-briefing-14-07-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-14-07-2026/</guid><description>Corgea&apos;s weekly briefing for 8-14 July 2026 covers Jscrambler&apos;s import-time npm compromise, Braintree.Net&apos;s production payment skimmer, Injective&apos;s wallet-key exfiltration release, and the week&apos;s most important Airflow, Paysafe, Operation Muck and Load, and apko/melange research.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-54174: `apko` and `melange` trusted APK control metadata without proving the installed data section</title><link>https://corgea.com/research/cve-2026-54174-apko-melange-apk-datahash-integrity-gap/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-54174-apko-melange-apk-datahash-integrity-gap/</guid><description>A newly published July 2026 advisory for `chainguard.dev/apko` and `chainguard.dev/melange` shows that builds before `apko` `1.2.9` and `melange` `0.50.4` verified the signed APK control section but not the package data section, letting a compromised mirror, poisoned cache, or MITM substitute the files actually installed into an OCI image while earlier integrity checks still passed.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Compromised `jscrambler` npm releases escalated from preinstall dropper to import-time Rust infostealer</title><link>https://corgea.com/research/jscrambler-npm-rust-infostealer-supply-chain-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/jscrambler-npm-rust-infostealer-supply-chain-july-2026/</guid><description>On 11 July 2026, five malicious `jscrambler` npm releases (`8.14.0`, `8.16.0`, `8.17.0`, `8.18.0`, and `8.20.0`) shipped a cross-platform Rust infostealer that first executed through `preinstall`, then pivoted into `dist/index.js` and the CLI entrypoint to survive `--ignore-scripts` and hook-only scanning.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Braintree.Net on NuGet skims live card data, merchant keys, and host secrets in production</title><link>https://corgea.com/research/braintree-net-nuget-production-card-skimmer-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/braintree-net-nuget-production-card-skimmer-july-2026/</guid><description>New July 2026 research exposed `Braintree.Net` as a NuGet typosquat of PayPal Braintree&apos;s official .NET SDK. The package hooks `CreditCardGateway` and `BraintreeGateway.PrivateKey`, siphons PAN/CVV and merchant credentials to `api.348672-shakepay[.]com`, and uses a companion `DependencyInjector.Core` package to auto-run environment and config harvesting through .NET module initializers.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Injective&apos;s 1.20.21 npm release turned wallet key derivation into mnemonic and private-key exfiltration</title><link>https://corgea.com/research/injective-sdk-ts-npm-wallet-key-exfiltration-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/injective-sdk-ts-npm-wallet-key-exfiltration-july-2026/</guid><description>A compromised GitHub maintainer path pushed `@injectivelabs/sdk-ts@1.20.21` and 17 pinned companion packages to npm on 8 July 2026. The malicious release hooks `PrivateKey.fromMnemonic()` and `PrivateKey.fromHex()`, batches wallet secrets into an `X-Request-Id` header, and quietly POSTs them to an Injective-branded endpoint that blends into normal SDK traffic.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - July 9, 2026</title><link>https://corgea.com/blog/changelog-july-9-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-july-9-2026/</guid><description>This week&apos;s Corgea changelog highlights new reporting visibility into fixes generated, cleaner duplicate triage reporting, and more reliable GitHub pull request check updates.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Malicious Go command module stages PowerShell loader and links to a 222-repository GitHub lure network</title><link>https://corgea.com/research/kaleidora-dnsub-go-module-muck-and-load-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/kaleidora-dnsub-go-module-muck-and-load-july-2026/</guid><description>Socket&apos;s 8 July 2026 Operation Muck and Load research exposed a fake Go `dnsub` scanner, `github.com/kaleidora/dnsub-scanning-tool`, that launches hidden PowerShell staging on Windows and ties into a larger 222-repository GitHub lure network spanning 190 accounts.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Checkmarx vs Veracode: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/checkmarx-vs-veracode/</link><guid isPermaLink="true">https://corgea.com/blog/compare/checkmarx-vs-veracode/</guid><description>Compare Checkmarx and Veracode side by side on enterprise SAST, governance, developer workflow, remediation, and buying fit. See how Corgea stacks up.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Snyk vs Veracode: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/snyk-vs-veracode/</link><guid isPermaLink="true">https://corgea.com/blog/compare/snyk-vs-veracode/</guid><description>Compare Snyk and Veracode side by side on security coverage, developer experience, governance, remediation workflow, and buying fit. See how Corgea stacks up.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-33264: Apache Airflow let DAG authors cross into scheduler and API-server RCE</title><link>https://corgea.com/research/cve-2026-33264-apache-airflow-dag-author-rce/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-33264-apache-airflow-dag-author-rce/</guid><description>Apache Airflow before `3.3.0` deserialized attacker-controlled trigger state while loading serialized DAGs on the Scheduler and API Server. That path reached `BaseSerialization.deserialize()`, which can `import_string()` attacker-chosen class paths, turning lower-trust DAG author input into higher-trust code execution across Airflow&apos;s control-plane processes.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Paysafe, Skrill, and Neteller typosquats on npm and PyPI stole developer secrets</title><link>https://corgea.com/research/paysafe-skrill-neteller-npm-pypi-typosquats-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/paysafe-skrill-neteller-npm-pypi-typosquats-july-2026/</guid><description>A July 7 cluster of 17 malicious npm and PyPI packages impersonated Paysafe, Skrill, and Neteller integrations. The npm variants exposed a fake `PaysafeClient`, delayed exfiltration until SDK methods were called, decoded an ngrok-backed C2 at runtime, and harvested any environment variable that looked like a key, token, password, secret, auth value, or API credential.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-53359: Januscape turns KVM shadow-page role confusion into Linux guest-to-host escape</title><link>https://corgea.com/research/cve-2026-53359-januscape-linux-kvm-vm-escape/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-53359-januscape-linux-kvm-vm-escape/</guid><description>Januscape is a Linux KVM/x86 use-after-free where `kvm_mmu_get_child_sp()` reused shadow pages on GFN match alone, letting a nested guest trigger role confusion, orphaned rmap state, host kernel memory corruption, and guest-to-host compromise on affected Intel and AMD virtualization hosts.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 07-07-2026</title><link>https://corgea.com/research/weekly-briefing-07-07-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-07-07-2026/</guid><description>Corgea&apos;s weekly briefing for 1-7 July 2026 covers PolinRider&apos;s cross-ecosystem supply-chain expansion, the Rollup polyfill npm RAT chain, Bad Epoll&apos;s public Linux root exploit, and the week&apos;s most important TeamPCP, Keras, buffa/connectrpc, and libzypp research.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Crypto Wars are back, this time over AI models</title><link>https://corgea.com/blog/the-crypto-wars-are-back-this-time-over-ai-models/</link><guid isPermaLink="true">https://corgea.com/blog/the-crypto-wars-are-back-this-time-over-ai-models/</guid><description>Export controls failed to contain strong encryption in the 1990s. AI restrictions risk repeating the same mistake: binding defenders first while determined adversaries route around.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Rollup polyfill lookalikes on npm hide an import-time loader, JSONKeeper stage, and 216.126.236.244 RAT</title><link>https://corgea.com/research/rollup-polyfill-npm-import-time-rat-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/rollup-polyfill-npm-import-time-rat-july-2026/</guid><description>A June 30-July 4 disclosure chain exposed six malicious npm packages impersonating `rollup-plugin-polyfill-node`. The backdoor lives in CommonJS `dist/index.js`, silently `npm install`s second-stage packages on `require()`, `eval`s JSONKeeper-hosted code, decrypts a follow-on payload from `216.126.236.244`, and turns developer workstations or CI runners into remote-access, browser-theft, clipboard-monitoring footholds.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-46242: Bad Epoll turns Linux eventpoll cleanup into local root</title><link>https://corgea.com/research/cve-2026-46242-bad-epoll-linux-kernel-root/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-46242-bad-epoll-linux-kernel-root/</guid><description>Bad Epoll is a Linux kernel race-condition use-after-free in eventpoll where concurrent close paths can corrupt freed kernel objects, turn `/proc/self/fdinfo` into a kernel-memory read primitive, and escalate ordinary local code execution to root on affected kernels.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FBI TeamPCP alert ties Trivy, KICS, LiteLLM, and Telnyx into one supply-chain playbook</title><link>https://corgea.com/research/teampcp-fbi-flash-trivy-kics-litellm-telnyx-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/teampcp-fbi-flash-trivy-kics-litellm-telnyx-july-2026/</guid><description>July 2026 FBI-linked reporting consolidates TeamPCP&apos;s developer-tool tradecraft across Trivy, KICS, LiteLLM, Telnyx, npm, and PyPI: mutable CI artifacts, stolen registry credentials, Python startup hooks, runner-memory scraping, and GitHub dead-drop exfiltration.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-12481: Keras Lambda.from_config() turns unset safe mode into code execution</title><link>https://corgea.com/research/cve-2026-12481-keras-lambda-safe-mode-deserialization-rce/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-12481-keras-lambda-safe-mode-deserialization-rce/</guid><description>A July 3 PyPI disclosure shows that Keras 3.14.x can treat `safe_mode=None` as effectively disabled during `Lambda` layer deserialization, letting attacker-controlled marshaled bytecode reach `func_load()` and become executable Python functions.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate></item><item><title>PolinRider expands from npm into Go, Packagist, and Chrome extension supply-chain poisoning</title><link>https://corgea.com/research/polinrider-npm-packagist-go-chrome-july-2026/</link><guid isPermaLink="true">https://corgea.com/research/polinrider-npm-packagist-go-chrome-july-2026/</guid><description>July 2026 research shows the PolinRider campaign reusing off-screen JavaScript loaders, VS Code task abuse, blockchain dead-drop staging, and Git-history rewrite tradecraft across 162 malicious artifacts spanning npm, Go modules, Packagist, and a Chrome extension.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Corgea vs. Snyk: We benchmarked SAST on a deliberately vulnerable repo</title><link>https://corgea.com/blog/corgea-vs-snyk-security-benchmark/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-vs-snyk-security-benchmark/</guid><description>On the same fixed benchmark basis as our Aikido comparison, Corgea found 42 of 47 confirmed issues and led on precision, recall, and F1. Snyk found 26, missing 21 of the confirmed set.</description><pubDate>Thu, 02 Jul 2026 20:00:00 GMT</pubDate></item><item><title>Corgea vs. Aikido: We benchmarked SAST on a deliberately vulnerable repo</title><link>https://corgea.com/blog/corgea-vs-aikido-security-benchmark/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-vs-aikido-security-benchmark/</guid><description>Aikido was slightly more precise in this benchmark, but missed 34 of 47 confirmed issues. Corgea found 42, reached 89.36% recall, and delivered the stronger F1 score.</description><pubDate>Thu, 02 Jul 2026 19:00:00 GMT</pubDate></item><item><title>Changelog - July 2, 2026</title><link>https://corgea.com/blog/changelog-july-2-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-july-2-2026/</guid><description>This week&apos;s Corgea changelog highlights AI Penetration Testing, new dependency inventory workflows in the Corgea Agent, and better documentation for project-level scan exclusions.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-25707: `libzypp` lets hostile repository metadata escape the cache root</title><link>https://corgea.com/research/cve-2026-25707-libzypp-repository-metadata-path-traversal/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-25707-libzypp-repository-metadata-path-traversal/</guid><description>A late-June Linux package-manager disclosure shows that pre-17.38.10 `libzypp` trusted `../`-style repository metadata locations, allowing a hostile or compromised repo to steer mirrored files outside the intended cache directory during refresh and making repository trust an arbitrary local file overwrite boundary.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-55407: `buffa` and `connectrpc` amplify tiny protobuf payloads into Rust OOMs</title><link>https://corgea.com/research/cve-2026-55407-buffa-connectrpc-protobuf-memory-amplification/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-55407-buffa-connectrpc-protobuf-memory-amplification/</guid><description>A June 30 disclosure shows that pre-0.8.0 versions of the Rust crates `buffa` and `connectrpc` can inflate streams of unknown protobuf fields into outsized heap allocations, turning small untrusted messages into process-killing memory amplification.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-58302: LinuxCNC rtapi_app path traversal to root</title><link>https://corgea.com/research/cve-2026-58302-linuxcnc-rtapi-app-suid-dlopen-path-traversal/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-58302-linuxcnc-rtapi-app-suid-dlopen-path-traversal/</guid><description>LinuxCNC before 2.9.9 installs rtapi_app with elevated privileges and feeds user-controlled module names into dlopen() after formatting ${EMC2_RTLIB_DIR}/${name}.so. Without rejecting slashes or .. segments, an unprivileged local user can traverse out of the module directory and load an arbitrary shared library as root.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 30-06-2026</title><link>https://corgea.com/research/weekly-briefing-30-06-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-30-06-2026/</guid><description>Corgea&apos;s weekly briefing for 24-30 June 2026 covers the ImmobiliareLabs Backstage plugin compromise, Leo Platform&apos;s expanding Phantom Gyp/Miasma package wave, expr-eval&apos;s no-fix Node.js code-execution flaw, and Vite&apos;s Windows dev-server secret leak.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-13502: antlr4-maven-plugin build-state deserialization</title><link>https://corgea.com/research/cve-2026-13502-antlr4-maven-plugin-deserialization-build-state-rce/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-13502-antlr4-maven-plugin-deserialization-build-state-rce/</guid><description>CVE-2026-13502 affects org.antlr:antlr4-maven-plugin 4.13.0 through 4.13.2. The public disclosure frames it as a race around the plugin&apos;s dependency-status file, but the practical sink is unfiltered ObjectInputStream deserialization of build-directory state under target/maven-status/antlr4/dependencies.ser.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>ImmobiliareLabs Backstage plugins compromised with Phantom Gyp Miasma payload</title><link>https://corgea.com/research/immobiliarelabs-backstage-gitlab-ldap-npm-miasma-june-2026/</link><guid isPermaLink="true">https://corgea.com/research/immobiliarelabs-backstage-gitlab-ldap-npm-miasma-june-2026/</guid><description>On 26 June 2026, 22 malicious patch releases hit four `@immobiliarelabs` Backstage plugin families. The poisoned npm artifacts added a `binding.gyp` trigger plus a new 5 MB root `index.js`, turning `npm install` into install-time code execution against environments that often hold GitLab, LDAP, CI, cloud, and developer-portal secrets.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - June 25, 2026</title><link>https://corgea.com/blog/changelog-june-25-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-june-25-2026/</guid><description>This week&apos;s Corgea changelog post highlights the latest public release notes, including the Skills Registry, policy API access, and bulk Content Access Management workflows.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-53571: Vite `server.fs.deny` bypass leaks protected files on Windows</title><link>https://corgea.com/research/cve-2026-53571-vite-windows-fs-deny-bypass/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-53571-vite-windows-fs-deny-bypass/</guid><description>Vite&apos;s dev server on Windows can leak `.env`, `.env.*`, and certificate files that developers expected `server.fs.deny` to block. The bypass uses NTFS alternate-data-stream path forms such as `/.env::$DATA?raw` and, in some cases, 8.3 short-name aliases, affecting `vite` before `6.4.3`, `7.3.5`, and `8.0.16` when the dev server is exposed beyond localhost and the target file sits in an allowed directory.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Leo Platform npm packages compromised with Phantom Gyp Miasma toolkit</title><link>https://corgea.com/research/leo-platform-npm-phantom-gyp-miasma-june-2026/</link><guid isPermaLink="true">https://corgea.com/research/leo-platform-npm-phantom-gyp-miasma-june-2026/</guid><description>On 24 June 2026, malicious versions of 23 Leo Platform npm packages were published in a six-second burst. Follow-up reporting on 25 June shows the wave was broader than the initial 20-package view: three additional prerelease connector packages were poisoned, `leo-sdk`&apos;s `latest` dist-tag was redirected to the malicious `6.0.19` line, and the same Phantom Gyp plus Bun-staged payload family also overlapped with adjacent npm and source-repository poisoning activity.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-12866: `expr-eval` turns untrusted formulas into Node.js code execution</title><link>https://corgea.com/research/cve-2026-12866-expr-eval-tojsfunction-code-execution/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-12866-expr-eval-tojsfunction-code-execution/</guid><description>A newly published June 2026 npm vulnerability shows that every `expr-eval` release can compile attacker-influenced formulas into executable JavaScript through `Expression.prototype.toJSFunction()`, exposing Node.js services, internal tools, and CI helpers that treat user formulas as data.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 23-06-2026</title><link>https://corgea.com/research/weekly-briefing-23-06-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-23-06-2026/</guid><description>Corgea&apos;s weekly briefing for 17-23 June 2026 covers the Mastra npm scope takeover that weaponized easy-day-js across more than 140 packages, plus Nodemailer&apos;s newly disclosed raw-message file-read and SSRF bypass.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate></item><item><title>We benchmarked 12 models on 1,913 real vulnerabilities. Here&apos;s the scoreboard.</title><link>https://corgea.com/blog/we-benchmarked-7-models-on-1913-real-vulnerabilities/</link><guid isPermaLink="true">https://corgea.com/blog/we-benchmarked-7-models-on-1913-real-vulnerabilities/</guid><description>There are public benchmarks for picking a model to drive a security scanner. The trouble is what they measure. CyberGym is C and C++ memory safety pulled from OSS-Fuzz, and the models being graded have most likely trained on it by now.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Nodemailer raw option bypasses disableFileAccess and disableUrlAccess</title><link>https://corgea.com/research/nodemailer-raw-option-file-read-ssrf-june-2026/</link><guid isPermaLink="true">https://corgea.com/research/nodemailer-raw-option-file-read-ssrf-june-2026/</guid><description>A newly published high-severity Nodemailer advisory shows that every version up to 9.0.0 can turn attacker-controlled `raw` message input into arbitrary local-file disclosure and full-response SSRF, because the `MailComposer` raw-message path drops the `disableFileAccess` and `disableUrlAccess` guards before `MimeNode` resolves `{ path }` or `{ href }` content.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - June 18, 2026</title><link>https://corgea.com/blog/changelog-june-18-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-june-18-2026/</guid><description>This week&apos;s Corgea changelog highlights the new Skills Registry, policy API access, and SLA-aware vulnerability search.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea AI Pentesting</title><link>https://corgea.com/blog/introducing-ai-pentesting/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-ai-pentesting/</guid><description>Autonomous penetration testing that thinks like a pentesting team. Multi-agent architecture. Code-aware, not black-box. 4-8 hours instead of 2 weeks.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Mastra npm scope takeover used easy-day-js to Trojanize 141-143 packages</title><link>https://corgea.com/research/mastra-npm-easy-day-js-supply-chain-attack-june-2026/</link><guid isPermaLink="true">https://corgea.com/research/mastra-npm-easy-day-js-supply-chain-attack-june-2026/</guid><description>On 17 June 2026, a compromised Mastra maintainer account republished 141 `@mastra/*` packages plus the top-level `mastra` and `create-mastra` packages with a new `easy-day-js: ^1.11.21` dependency that resolved to a weaponized `1.11.22` postinstall dropper, turning fresh npm installs into a detached second stage that established cross-platform persistence, profiled browsers and wallets, and, in Microsoft&apos;s 19 June follow-up, was tied to Sapphire Sleet activity that escalated some Windows hosts into PowerShell-backed, SYSTEM-level persistence.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Corgea Auto-Discovery and Learning</title><link>https://corgea.com/blog/introducing-auto-discovery-and-learning/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-auto-discovery-and-learning/</guid><description>Corgea now studies your codebase before scanning it, and learns from every developer feedback action. No more generic scanners. No more repeating the same false positives.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea Skill Scanning</title><link>https://corgea.com/blog/introducing-corgea-skill-scanning/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-skill-scanning/</guid><description>Corgea scans custom agent skills before developers can install them, blocking unsafe SKILL.md instructions and distributing only approved versions through the governed Skills Registry.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>GlassWASM used TinyGo WebAssembly and Solana memos in trojanized Open VSX extensions</title><link>https://corgea.com/research/glasswasm-open-vsx-solana-wasm-c2/</link><guid isPermaLink="true">https://corgea.com/research/glasswasm-open-vsx-solana-wasm-c2/</guid><description>Trojanized Open VSX copies of `ExarGD.vsblack@0.0.1` and `noellee-doc.flint-debug@0.1.1` cloned legitimate extension identities, auto-executed a TinyGo-compiled WebAssembly payload on startup, polled Solana JSON-RPC for memo-based command-and-control, and built OS-specific `child_process` download-and-execute commands for macOS, Linux, and Windows.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 16-06-2026</title><link>https://corgea.com/research/weekly-briefing-16-06-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-16-06-2026/</guid><description>Corgea&apos;s weekly briefing for 10-16 June 2026 covers the uncovered remainder of the week&apos;s research: the dbmux Phantom Gyp / Miasma compromise, Dulwich&apos;s Windows and format-patch path traversal fixes, libp2p&apos;s unauthenticated DHT disk-exhaustion flaw, and Spring&apos;s internally discovered WebFlux and static-resource DoS fixes.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea Security Design Reviews</title><link>https://corgea.com/blog/introducing-security-design-reviews/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-security-design-reviews/</guid><description>Most security tools only find bugs after they&apos;re written. Corgea Security Design Reviews catch design-level risks before a single line of code is committed.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-50010, 50011, 50020, and 50560: Netty 4.1.135 / 4.2.15 fix TLS, HTTP/1.1, HTTP/2, and Redis parser flaws</title><link>https://corgea.com/research/cve-2026-50010-50011-50020-50560-netty-handler-http-http2-redis/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-50010-50011-50020-50560-netty-handler-http-http2-redis/</guid><description>Netty&apos;s June security train matters to Maven teams because a custom trust manager can silently disable HTTPS hostname verification, `HttpObjectDecoder` can over-accept leading control bytes and enable request-boundary confusion, `RedisArrayAggregator` can allocate attacker-sized arrays, and HTTP/2 servers can be coerced into response-write failures via client-advertised header limits.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 15-06-2026</title><link>https://corgea.com/research/weekly-briefing-15-06-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-15-06-2026/</guid><description>Corgea&apos;s weekly briefing for 10-15 June 2026 covers the Atomic Arch AUR takeover, Netty&apos;s security-heavy 4.1.135 / 4.2.15 release, the onering crates compromise, and a late-breaking Open VSX extension attack that used TinyGo WebAssembly plus Solana memo-based C2.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Atomic Arch turned orphaned AUR packages into npm and Bun malware launchers</title><link>https://corgea.com/research/atomic-arch-aur-atomic-lockfile-js-digest-ebpf-rootkit/</link><guid isPermaLink="true">https://corgea.com/research/atomic-arch-aur-atomic-lockfile-js-digest-ebpf-rootkit/</guid><description>The June 11-12 Atomic Arch campaign adopted orphaned AUR packages, inserted `npm install atomic-lockfile` or Bun-based `js-digest` / `lockfile-js` fetches into package hooks, and used a malicious lifecycle script to execute `src/hooks/deps`, a Linux ELF infostealer with optional eBPF hiding logic across a verified `1,619` unique AUR package names.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-42305 and CVE-2026-47712: Dulwich 1.2.5 fixes Windows checkout abuse and format_patch path traversal</title><link>https://corgea.com/research/cve-2026-42305-cve-2026-47712-dulwich-1-2-5-git-path-traversal/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-42305-cve-2026-47712-dulwich-1-2-5-git-path-traversal/</guid><description>Dulwich before 1.2.5 accepts NTFS-hostile tree entries that can plant files under .git or escape the work tree on Windows, and it also derives format_patch filenames from unsanitized commit subjects, letting attacker-controlled commits write patch files outside the requested output directory.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-45783: @libp2p/kad-dht lets unauthenticated peers fill disk with unvalidated PUT_VALUE records</title><link>https://corgea.com/research/cve-2026-45783-libp2p-kad-dht-put-value-disk-exhaustion/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-45783-libp2p-kad-dht-put-value-disk-exhaustion/</guid><description>A newly published flaw in @libp2p/kad-dht before 16.2.6 allows any remote peer to stream crafted PUT_VALUE messages whose keys bypass record validation, turning DHT server nodes into unbounded disk sinks until the host or container runs out of storage.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - June 11, 2026</title><link>https://corgea.com/blog/changelog-june-11-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-june-11-2026/</guid><description>This week&apos;s Corgea changelog highlights on-demand fix generation, branch-level reporting filters, and richer SCA advisory details.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-41840 and CVE-2026-41842: Spring 7.0.8 fixes WebFlux multipart and versioned-resource DoS flaws</title><link>https://corgea.com/research/cve-2026-41840-41842-spring-webflux-versioned-resource-dos/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-41840-41842-spring-webflux-versioned-resource-dos/</guid><description>Spring Framework 7.0.8 and 6.2.19 fix two newly disclosed denial-of-service flaws that matter to Maven-based application teams: a WebFlux multipart-processing leak reachable through hostile multipart bodies, and a static-resource resolution path that can pin connections when versioned filesystem assets are enabled.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>dbmux npm package used Phantom Gyp to execute Miasma during install</title><link>https://corgea.com/research/dbmux-npm-miasma-phantom-gyp-compromise/</link><guid isPermaLink="true">https://corgea.com/research/dbmux-npm-miasma-phantom-gyp-compromise/</guid><description>The `dbmux` npm package was classified as critical malware after public tracking tied compromised `1.x` and `2.2.x` releases to Miasma&apos;s Phantom Gyp technique, where a weaponized `binding.gyp` forces `node-gyp rebuild` to execute a hidden loader during `npm install` even when `package.json` does not advertise lifecycle scripts.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>onering 1.4.1 used Cargo build.rs to exfiltrate private source diffs</title><link>https://corgea.com/research/onering-crates-build-rs-sentry-source-exfiltration/</link><guid isPermaLink="true">https://corgea.com/research/onering-crates-build-rs-sentry-source-exfiltration/</guid><description>The compromised Rust crate `onering@1.4.1` added a 74-line `build.rs` that walks out of Cargo&apos;s `OUT_DIR`, runs `git log -n 1` and `git diff HEAD^ HEAD` against the consuming repository, and posts commit metadata plus the latest source diff to a Sentry ingest endpoint on every build.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Hades PyPI follow-on hit MCP packages and Python typosquats</title><link>https://corgea.com/research/hades-pypi-mcp-typosquat-follow-on-june-2026/</link><guid isPermaLink="true">https://corgea.com/research/hades-pypi-mcp-typosquat-follow-on-june-2026/</guid><description>On June 9, 2026, the Hades PyPI campaign expanded beyond the earlier scientific-package wave into MCP tooling and typo-squatted Python packages such as `openai-mcp`, `langchain-core-mcp`, `instructor-mcp`, `tiktoken-mcp`, `ray-mcp-server`, `rsquests`, `rlask`, and `tlask`, using `.pth` loaders, split staging, and native-extension triggers to launch a Bun-executed stealer.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 09-06-2026</title><link>https://corgea.com/research/weekly-briefing-09-06-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-09-06-2026/</guid><description>Corgea&apos;s weekly briefing for 2-9 June 2026 covers the Phantom Gyp Miasma npm wave, Hades&apos; expansion into MCP-focused PyPI packages, the nvm mirror command injection flaw, and the now-exploited Oracle WebLogic T3/IIOP exposure issue.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-10796 lets hostile mirrors turn `nvm install` into shell RCE</title><link>https://corgea.com/research/cve-2026-10796-nvm-mirror-index-tab-command-injection/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-10796-nvm-mirror-index-tab-command-injection/</guid><description>A June 4 disclosure showed that nvm &lt;= 0.40.4 trusted version fields from mirror index.tab metadata, letting hostile or MITM&apos;d mirrors inject commands into both nvm_download() and nvm_get_checksum(). Version 0.40.5 fixes the issue by removing eval from downloader execution, passing tarball names to awk as data, and rejecting disallowed characters in mirror-supplied version strings.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - June 4, 2026</title><link>https://corgea.com/blog/changelog-june-4-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-june-4-2026/</guid><description>This week&apos;s Corgea changelog highlights faster project tag management, more resilient large scan uploads, and more reliable GitHub App pull request scanning.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-44488: Axios fetch adapter bypasses maxContentLength and maxBodyLength</title><link>https://corgea.com/research/cve-2026-44488-axios-fetch-size-limits-bypass/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-44488-axios-fetch-size-limits-bypass/</guid><description>Axios 1.7.0 through 1.15.x does not enforce configured request and response size limits when the fetch adapter is selected, allowing oversized uploads, downloads, and data: URL bodies to exhaust memory and CPU on server-side runtimes that relied on those limits as a security boundary.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Phantom Gyp Miasma hit Vapi, ai-sdk-ollama, and 55 more npm packages</title><link>https://corgea.com/research/miasma-phantom-gyp-npm-worm-vapi-ai-sdk-ollama-june-2026/</link><guid isPermaLink="true">https://corgea.com/research/miasma-phantom-gyp-npm-worm-vapi-ai-sdk-ollama-june-2026/</guid><description>A June 3-4 Miasma follow-on wave used a 157-byte binding.gyp file to force node-gyp command substitution during npm install, turning @vapi-ai/server-sdk, ai-sdk-ollama, and dozens of autotel, awaitly, executable-stories, and node-env-resolver packages into Bun-staged credential-stealing worm loaders while leaving their real dist/ code untouched.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Best SonarQube Alternatives in 2026: 10 Tools Compared (Free &amp; Paid)</title><link>https://corgea.com/blog/sonarqube-alternatives/</link><guid isPermaLink="true">https://corgea.com/blog/sonarqube-alternatives/</guid><description>The best SonarQube alternatives in 2026: 10 free and paid tools compared on security accuracy, auto-fix, coverage, and pricing, plus a complete open-source SonarQube replacement stack.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2024-21182: Oracle WebLogic T3 and IIOP exposure is now exploited</title><link>https://corgea.com/research/cve-2024-21182-oracle-weblogic-kev-t3-iiop-data-exposure/</link><guid isPermaLink="true">https://corgea.com/research/cve-2024-21182-oracle-weblogic-kev-t3-iiop-data-exposure/</guid><description>CISA added CVE-2024-21182 to KEV after active exploitation of an Oracle WebLogic Server Core flaw that is reachable without authentication over T3 and IIOP and can expose all WebLogic-accessible data.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Miasma poisoned Red Hat Cloud Services npm packages through trusted publishing</title><link>https://corgea.com/research/redhat-cloud-services-npm-miasma-shai-hulud-worm/</link><guid isPermaLink="true">https://corgea.com/research/redhat-cloud-services-npm-miasma-shai-hulud-worm/</guid><description>A compromised Red Hat GitHub account pushed orphan commits into RedHatInsights repositories and used GitHub Actions OIDC trusted publishing to ship Miasma, a Bun-staged credential-stealing worm with GitHub dead-drop exfiltration and local persistence, across @redhat-cloud-services npm packages.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 02-06-2026</title><link>https://corgea.com/research/weekly-briefing-02-06-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-02-06-2026/</guid><description>Corgea&apos;s weekly briefing for 26 May-2 June 2026 covers the Red Hat Cloud Services Miasma npm compromise, private Gitea and Forgejo container-image exposure, the js-logger-pack MicrosoftSystem64 implant, banking-certificate theft through a malicious NuGet SDK, dependency-confusion reconnaissance, OpenSearch npm typosquats, CMS privilege escalations, and stored editor XSS.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CIFSwitch turns Linux CIFS SPNEGO upcalls into local root</title><link>https://corgea.com/research/cifswitch-linux-cifs-spnego-upcall-root/</link><guid isPermaLink="true">https://corgea.com/research/cifswitch-linux-cifs-spnego-upcall-root/</guid><description>CIFSwitch is a Linux kernel and cifs-utils privilege escalation where an unprivileged process can forge a cifs.spnego key request, make request-key launch cifs.upcall as root, and force NSS code execution inside an attacker-controlled namespace.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-27771 exposed private Gitea and Forgejo container images</title><link>https://corgea.com/research/gitea-forgejo-private-container-registry-bypass/</link><guid isPermaLink="true">https://corgea.com/research/gitea-forgejo-private-container-registry-bypass/</guid><description>CVE-2026-27771 is a Gitea container registry authorization flaw where unauthenticated requests could pull private OCI image manifests and layers from affected self-hosted instances, exposing application code, dependencies, and secrets baked into images.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>roberts/leads Packagist dev branch hid a Famous Chollima blockchain loader</title><link>https://corgea.com/research/roberts-leads-packagist-famous-chollima-loader/</link><guid isPermaLink="true">https://corgea.com/research/roberts-leads-packagist-famous-chollima-loader/</guid><description>The Packagist package roberts/leads exposed a poisoned development branch as dev-drewroberts/feature/test-case, where tailwind.js appended obfuscated JavaScript that resolved payload material through TRON, Aptos, and BNB Smart Chain before executing it in Node.js.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>oob.moika.tech npm campaign used dependency confusion to profile developer environments</title><link>https://corgea.com/research/oob-moika-npm-dependency-confusion-recon/</link><guid isPermaLink="true">https://corgea.com/research/oob-moika-npm-dependency-confusion-recon/</guid><description>Public reporting tied at least 179 malicious npm package-version records to an oob.moika.tech dependency-confusion campaign that abused internal-looking scopes, postinstall hooks, inflated versions, and detached JavaScript payloads to inventory developer and CI environments.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate></item><item><title>14 OpenSearch-themed npm typosquats stole AWS, Vault, GitHub, and npm secrets</title><link>https://corgea.com/research/vpmdhaj-opensearch-npm-cloud-ci-secrets/</link><guid isPermaLink="true">https://corgea.com/research/vpmdhaj-opensearch-npm-cloud-ci-secrets/</guid><description>A May 28 npm campaign published 14 OpenSearch, ElasticSearch, DevOps, and config lookalikes that executed during npm install, loaded a Bun-based credential harvester, and targeted cloud and CI/CD secrets.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-48864: libsolv .solv page decompression can overflow parser buffers</title><link>https://corgea.com/research/cve-2026-48864-libsolv-solv-page-decompression-overflow/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-48864-libsolv-solv-page-decompression-overflow/</guid><description>A high-severity libsolv flaw lets attacker-controlled .solv cache data reach unchecked decompression paths in repopagestore page loading, creating out-of-bounds memory access in tooling that parses untrusted package metadata caches.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>js-logger-pack turns Hugging Face into a malware CDN and exfiltration backend</title><link>https://corgea.com/research/js-logger-pack-microsoftsystem64-huggingface-exfiltration/</link><guid isPermaLink="true">https://corgea.com/research/js-logger-pack-microsoftsystem64-huggingface-exfiltration/</guid><description>Recent js-logger-pack npm releases and related logger packages deliver MicrosoftSystem64, a cross-platform Node SEA implant that persists on Windows, macOS, and Linux, logs keystrokes, scans developer secrets, and uploads stolen data to private Hugging Face datasets.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Sicoob.Sdk NuGet impersonator steals mTLS certificates through Sentry telemetry</title><link>https://corgea.com/research/sicoob-sdk-nuget-pfx-certificate-exfiltration/</link><guid isPermaLink="true">https://corgea.com/research/sicoob-sdk-nuget-pfx-certificate-exfiltration/</guid><description>Malicious Sicoob.Sdk NuGet releases 2.0.0 through 2.0.4 impersonated an official Brazilian banking SDK, then exfiltrated client IDs, PFX passwords, base64-encoded PFX certificate archives, and boleto responses from the SicoobClient constructor.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>TinyMCE CVE-2026-47759 through 47762 turn editor sanitization gaps into stored XSS</title><link>https://corgea.com/research/tinymce-47759-47762-stored-xss-sanitizer-bypass/</link><guid isPermaLink="true">https://corgea.com/research/tinymce-47759-47762-stored-xss-sanitizer-bypass/</guid><description>TinyMCE disclosed four high-severity stored-XSS vulnerabilities across npm, NuGet, and Composer packages, affecting data-mce-* attributes, nested SVG namespace handling, media plugin embeds, and forged mce:protected comments.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - May 28, 2026</title><link>https://corgea.com/blog/changelog-may-28-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-may-28-2026/</guid><description>This week&apos;s Corgea changelog highlights SCA support in SLA Management, Security Design Review beta, and broader API and MCP access to security data.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>codexui-android npm package exfiltrates Codex OAuth tokens on startup</title><link>https://corgea.com/research/codexui-android-openai-token-stealer/</link><guid isPermaLink="true">https://corgea.com/research/codexui-android-openai-token-stealer/</guid><description>The npm package codexui-android, also pulled by Android apps at runtime, added registry-only code that reads Codex auth.json, XOR-encodes the full OpenAI OAuth token blob, and posts it to sentry.anyclaw.store on every launch.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>@velora-dex/sdk 9.4.1 loaded a macOS MINIRAT backdoor on import</title><link>https://corgea.com/research/velora-dex-sdk-npm-minirat-macos-backdoor/</link><guid isPermaLink="true">https://corgea.com/research/velora-dex-sdk-npm-minirat-macos-backdoor/</guid><description>JINX-0164&apos;s npm compromise of @velora-dex/sdk 9.4.1 appended three registry-only lines to dist/index.js, causing any require() or import of the DeFi SDK to fetch a macOS shell dropper and install a Go backdoor with launchctl persistence.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-48172: exploited LiteSpeed cPanel plugin bug lets any tenant reach root</title><link>https://corgea.com/research/cve-2026-48172-litespeed-cpanel-root-privilege-escalation/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-48172-litespeed-cpanel-root-privilege-escalation/</guid><description>CISA added CVE-2026-48172 to KEV after active exploitation of LiteSpeed&apos;s User-End cPanel Plugin. A vulnerable Redis enable/disable JSON API path exposed to cPanel users can execute attacker-controlled scripts with root privileges on shared Linux hosting servers.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Joomla 5.4.6 and 6.1.1 patch com_users privilege-escalation paths</title><link>https://corgea.com/research/joomla-5-4-6-6-1-1-com-users-privilege-escalation/</link><guid isPermaLink="true">https://corgea.com/research/joomla-5-4-6-6-1-1-com-users-privilege-escalation/</guid><description>Joomla&apos;s 26 May security release fixes critical access-control failures in the com_users batch task and group-editing webservice endpoint. CVE-2026-48898 and CVE-2026-48904 affect Joomla CMS 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Snipe-IT 8.4.1 closes API admin escalation, component-note XSS, and open redirect flaws</title><link>https://corgea.com/research/snipe-it-8-4-1-api-privilege-escalation-xss-open-redirect/</link><guid isPermaLink="true">https://corgea.com/research/snipe-it-8-4-1-api-privilege-escalation-xss-open-redirect/</guid><description>Snipe-IT 8.4.1 fixes three newly published CVEs, led by CVE-2026-44832: an API permission-assignment bug where a user with users.edit could set permissions[admin]=1 on their own account.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-9082: exploited Drupal PostgreSQL SQL injection reaches KEV</title><link>https://corgea.com/research/cve-2026-9082-drupal-postgresql-sql-injection-kev/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-9082-drupal-postgresql-sql-injection-kev/</guid><description>CVE-2026-9082 is a highly critical Drupal core SQL injection in the PostgreSQL database abstraction path where crafted anonymous requests can influence query construction, leading to information disclosure, privilege escalation, and possible remote code execution; CISA added it to KEV after exploit attempts were observed in the wild.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Laravel-Lang tag rewrites turned Composer autoload into credential theft</title><link>https://corgea.com/research/laravel-lang-composer-tag-rewrite-credential-stealer/</link><guid isPermaLink="true">https://corgea.com/research/laravel-lang-composer-tag-rewrite-credential-stealer/</guid><description>The Laravel-Lang compromise rewrote trusted Composer tags across four community packages so that normal Laravel and Symfony bootstraps loaded a malicious src/helpers.php dropper through autoload.files, fetching a PHP stealer from flipboxstudio.info and targeting cloud, CI/CD, Kubernetes, Vault, browser, SSH, and developer secrets.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>TrapDoor used npm, PyPI, and Crates.io lures to steal developer secrets</title><link>https://corgea.com/research/trapdoor-npm-pypi-crates-crypto-stealer/</link><guid isPermaLink="true">https://corgea.com/research/trapdoor-npm-pypi-crates-crypto-stealer/</guid><description>TrapDoor is a coordinated multi-registry malware campaign affecting 34 package names across npm, PyPI, and Crates.io, with ecosystem-specific execution paths for postinstall hooks, Python import-time remote JavaScript execution, and Rust build.rs scripts targeting crypto, DeFi, AI, and security developers.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 26-05-2026</title><link>https://corgea.com/research/weekly-briefing-26-05-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-26-05-2026/</guid><description>Corgea&apos;s weekly briefing for 19-26 May 2026 covers the GitHub internal repository breach tied to the Nx Console compromise, TrapDoor&apos;s multi-registry package malware campaign, exploited Drupal and Langflow KEV vulnerabilities, Laravel-Lang tag rewrites, TensorRT-LLM deserialization flaws, the art-template browser exploit-chain compromise, and a Linux ptrace local privilege escalation.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>art-template npm compromise delivered a Coruna-like iOS exploit kit</title><link>https://corgea.com/research/art-template-npm-coruna-ios-exploit-kit/</link><guid isPermaLink="true">https://corgea.com/research/art-template-npm-coruna-ios-exploit-kit/</guid><description>Compromised npm releases of art-template appended browser-side script loaders to lib/template-web.js, sending downstream site visitors through hidden iframes into a Safari/iOS exploit delivery framework instead of only stealing developer secrets at install time.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2025-34291: Langflow CORS and refresh-token chain reaches RCE</title><link>https://corgea.com/research/cve-2025-34291-langflow-cors-refresh-token-rce/</link><guid isPermaLink="true">https://corgea.com/research/cve-2025-34291-langflow-cors-refresh-token-rce/</guid><description>CISA added CVE-2025-34291 to KEV after exploitation of a Langflow chain where wildcard credentialed CORS and a SameSite=None refresh-token cookie let a malicious webpage mint API tokens and reach authenticated code-execution endpoints.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-46333: Linux ptrace race leaks privileged file descriptors</title><link>https://corgea.com/research/cve-2026-46333-linux-ptrace-pidfd-getfd-lpe/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-46333-linux-ptrace-pidfd-getfd-lpe/</guid><description>CVE-2026-46333 is a Linux kernel ptrace authorization flaw where pidfd_getfd can race a dying privileged process after it drops credentials, duplicating sensitive file descriptors such as /etc/shadow, SSH host keys, or authenticated system D-Bus sockets.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - May 21, 2026</title><link>https://corgea.com/blog/changelog-may-21-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-may-21-2026/</guid><description>This week&apos;s Corgea changelog highlights scheduled scan webhook filters, project-tag scoped PR rules, and broader, cleaner scan analysis.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>NVIDIA TensorRT-LLM deserialization flaws expose distributed inference control paths</title><link>https://corgea.com/research/cve-2025-33255-cve-2026-24142-nvidia-tensorrt-llm-deserialization/</link><guid isPermaLink="true">https://corgea.com/research/cve-2025-33255-cve-2026-24142-nvidia-tensorrt-llm-deserialization/</guid><description>CVE-2025-33255 and CVE-2026-24142 affect NVIDIA TensorRT-LLM before 1.2, where unsafe deserialization in MPI and serialized weight-handle paths could turn crafted control-plane data into code execution, data tampering, information disclosure, or denial of service.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>GitHub breached through a poisoned VS Code extension: 3,800 internal repositories stolen</title><link>https://corgea.com/research/github-breach-vscode-extension-supply-chain-may-2026/</link><guid isPermaLink="true">https://corgea.com/research/github-breach-vscode-extension-supply-chain-may-2026/</guid><description>TeamPCP exploited a cascading supply chain attack from TanStack to Nx Console to a GitHub employee workstation to exfiltrate approximately 3,800 private GitHub repositories containing infrastructure configs, deployment scripts, staging credentials, and internal API schemas.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>Nx Console VS Code extension 18.95.0 shipped a developer credential stealer</title><link>https://corgea.com/research/nx-console-vscode-extension-credential-stealer-may-2026/</link><guid isPermaLink="true">https://corgea.com/research/nx-console-vscode-extension-credential-stealer-may-2026/</guid><description>A malicious 18.95.0 release of the Nx Console VS Code extension executed a hidden npx task on workspace activation, fetched an obfuscated Bun payload from a dangling nrwl/nx commit, harvested developer and cloud credentials, installed macOS persistence, and demonstrated the same auto-update path now tied to GitHub internal repository exposure.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>shopsprint/decimal Go typosquat hides DNS TXT command backdoor</title><link>https://corgea.com/research/shopsprint-decimal-go-typosquat-dns-backdoor/</link><guid isPermaLink="true">https://corgea.com/research/shopsprint-decimal-go-typosquat-dns-backdoor/</guid><description>The typosquatted Go module github.com/shopsprint/decimal copied the popular shopspring/decimal API, then weaponized version 1.3.3 with an init() goroutine that polls DNS TXT records and executes returned commands.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-25244: WebdriverIO BrowserStack Service executes Git branch names in shell commands</title><link>https://corgea.com/research/webdriverio-browserstack-service-branch-command-injection/</link><guid isPermaLink="true">https://corgea.com/research/webdriverio-browserstack-service-branch-command-injection/</guid><description>WebdriverIO BrowserStack Service versions through 9.23.2 interpolate attacker-controlled Git branch names into execSync() calls during test orchestration smart selection, allowing command injection on CI runners and developer machines.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Mini Shai-Hulud npm worm hits AntV, echarts-for-react, and timeago.js</title><link>https://corgea.com/research/antv-mini-shai-hulud-npm-worm-may-2026/</link><guid isPermaLink="true">https://corgea.com/research/antv-mini-shai-hulud-npm-worm-may-2026/</guid><description>TeamPCP&apos;s Mini Shai-Hulud campaign expanded on May 19 with hundreds of malicious npm releases across the AntV data-visualization ecosystem and related packages including echarts-for-react, timeago.js, size-sensor, and jest-canvas-mock.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>durabletask PyPI releases backdoored with multi-cloud credential stealer</title><link>https://corgea.com/research/durabletask-pypi-credential-stealer-teampcp-may-2026/</link><guid isPermaLink="true">https://corgea.com/research/durabletask-pypi-credential-stealer-teampcp-may-2026/</guid><description>Three malicious PyPI releases of Microsoft&apos;s durabletask Python SDK, versions 1.4.1 through 1.4.3, executed an import-time Linux dropper that fetched rope.pyz, harvested cloud and developer secrets, and attempted lateral movement through AWS SSM and Kubernetes.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Briefing - 19-05-2026</title><link>https://corgea.com/research/weekly-briefing-19-05-2026/</link><guid isPermaLink="true">https://corgea.com/research/weekly-briefing-19-05-2026/</guid><description>Corgea&apos;s weekly briefing for 12-19 May 2026 covers the durabletask PyPI compromise, the Mini Shai-Hulud expansion into AntV and related npm packages, the Nx Console extension compromise, WebdriverIO command injection, and other important supply-chain, kernel, and application-security research from the week.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate></item><item><title>Backdoored Cemu Linux release assets reused TeamPCP credential-stealer payload</title><link>https://corgea.com/research/cemu-linux-release-assets-teampcp-malware/</link><guid isPermaLink="true">https://corgea.com/research/cemu-linux-release-assets-teampcp-malware/</guid><description>Cemu v2.6 Linux GitHub release assets were deleted and re-uploaded with a Python zipapp payload tied to the TanStack and Mistral TeamPCP supply-chain campaign, exposing users who ran the AppImage or Ubuntu ZIP to credential theft and possible destructive behavior.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>Strapi advisory cluster exposes admin token oracle and content-builder SQL injection</title><link>https://corgea.com/research/strapi-may-2026-admin-token-oracle-query-injection/</link><guid isPermaLink="true">https://corgea.com/research/strapi-may-2026-admin-token-oracle-query-injection/</guid><description>Five Strapi advisories published in mid-May affect npm packages across the Strapi CMS stack, including a critical unauthenticated admin reset-token oracle in @strapi/strapi and a critical Content-Type Builder SQL injection in @strapi/content-type-builder and @strapi/plugin-content-type-builder.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>MAL-2026-3744: node-ipc npm releases backdoored with DNS exfiltration stealer</title><link>https://corgea.com/research/node-ipc-npm-credential-stealer-dns-exfiltration/</link><guid isPermaLink="true">https://corgea.com/research/node-ipc-npm-credential-stealer-dns-exfiltration/</guid><description>Three npm releases of node-ipc, versions 9.1.6, 9.2.3, and 12.0.1, were published with an obfuscated CommonJS payload that steals developer and CI credentials and exfiltrates gzipped archives through DNS TXT queries.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>Fragnesia: Linux ESP-in-TCP bug revives page-cache root escalation</title><link>https://corgea.com/research/fragnesia-linux-esp-in-tcp-page-cache-lpe/</link><guid isPermaLink="true">https://corgea.com/research/fragnesia-linux-esp-in-tcp-page-cache-lpe/</guid><description>CVE-2026-46300, nicknamed Fragnesia, is a new Linux kernel XFRM ESP-in-TCP local privilege escalation that lets unprivileged local attackers corrupt read-only file contents in page cache and execute a root shell from a patched-in-memory system binary.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Changelog - May 13, 2026</title><link>https://corgea.com/blog/changelog-may-13-2026/</link><guid isPermaLink="true">https://corgea.com/blog/changelog-may-13-2026/</guid><description>This week&apos;s Corgea changelog highlights Harness Code integration, sharper secret scanning, and stronger endpoint discovery in the scanning engine.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>GemStuffer abuses RubyGems as a data-exfiltration channel</title><link>https://corgea.com/research/gemstuffer-rubygems-registry-exfiltration-campaign/</link><guid isPermaLink="true">https://corgea.com/research/gemstuffer-rubygems-registry-exfiltration-campaign/</guid><description>GemStuffer is a RubyGems registry-abuse campaign that published 155 junk package artifacts containing scraped UK council portal data, using hardcoded RubyGems API keys and valid .gem archives as a public data drop.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-41242: protobufjs can execute code from attacker-controlled schemas</title><link>https://corgea.com/research/cve-2026-41242-protobufjs-schema-code-execution/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-41242-protobufjs-schema-code-execution/</guid><description>protobufjs before 7.5.5 and 8.0.1 can turn schema metadata into executable JavaScript through unsafe runtime code generation, exposing Node.js services that load attacker-influenced protobuf definitions or JSON descriptors.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Dirty Frag: Linux kernel ESP and RxRPC flaws enable local root escalation</title><link>https://corgea.com/research/dirty-frag-linux-kernel-esp-rxrpc-lpe/</link><guid isPermaLink="true">https://corgea.com/research/dirty-frag-linux-kernel-esp-rxrpc-lpe/</guid><description>Dirty Frag chains CVE-2026-43284 in Linux kernel ESP/IPsec handling with CVE-2026-43500 in RxRPC to turn local access into root on many Linux distributions, with public proof-of-concept code available before broad vendor patch coverage.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Five malicious IR.* NuGet packages impersonate Chinese .NET libraries</title><link>https://corgea.com/research/malicious-nuget-ir-packages-credential-stealer/</link><guid isPermaLink="true">https://corgea.com/research/malicious-nuget-ir-packages-credential-stealer/</guid><description>A NuGet campaign published five IR.* packages under the bmrxntfj account, using functional .NET library wrappers plus a Reactor-protected infostealer to target browser credentials, SSH keys, cloud secrets, and crypto wallets across developer workstations and CI systems.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>Mini Shai-Hulud Supply-Chain Worm Compromises TanStack, Mistral AI, UiPath, and 160+ npm Packages</title><link>https://corgea.com/research/tanstack-supply-chain-attack-mini-shai-hulud/</link><guid isPermaLink="true">https://corgea.com/research/tanstack-supply-chain-attack-mini-shai-hulud/</guid><description>TeamPCP launched a coordinated supply-chain attack against the npm and PyPI ecosystems, compromising 373 malicious package versions across 169 package names including @tanstack/react-router, @mistralai/mistralai, and @uipath packages. TanStack&apos;s npm compromise is now tracked as CVE-2026-45321, and the BeProduct slice of the same worm wave is now separately tracked as CVE-2026-46412.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>SonarQube vs Snyk: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/sonarqube-vs-snyk/</link><guid isPermaLink="true">https://corgea.com/blog/compare/sonarqube-vs-snyk/</guid><description>Compare SonarQube and Snyk side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-6907: Django cache middleware mishandles Vary: *</title><link>https://corgea.com/research/cve-2026-6907-django-vary-star-cache/</link><guid isPermaLink="true">https://corgea.com/research/cve-2026-6907-django-vary-star-cache/</guid><description>Django&apos;s UpdateCacheMiddleware could cache responses that explicitly declared themselves uncacheable for shared caches, creating a path for private data exposure.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>Snyk vs Checkmarx: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/snyk-vs-checkmarx/</link><guid isPermaLink="true">https://corgea.com/blog/compare/snyk-vs-checkmarx/</guid><description>Compare Snyk and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>SonarQube vs Checkmarx: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/sonarqube-vs-checkmarx/</link><guid isPermaLink="true">https://corgea.com/blog/compare/sonarqube-vs-checkmarx/</guid><description>Compare SonarQube and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>SonarQube vs Veracode: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/sonarqube-vs-veracode/</link><guid isPermaLink="true">https://corgea.com/blog/compare/sonarqube-vs-veracode/</guid><description>Compare SonarQube and Veracode side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Mythos: Given Enough Inference, All Bugs Are Shallow</title><link>https://corgea.com/blog/given-enough-inference-all-bugs-all-shallow/</link><guid isPermaLink="true">https://corgea.com/blog/given-enough-inference-all-bugs-all-shallow/</guid><description>Anthropic&apos;s Mythos showed that given enough inference, all bugs are shallow. But who pays for the inference? We benchmarked Claude Opus 4.6 against Corgea v1 and v2 to show why purpose-built scanner architecture beats raw model capability on precision, recall, cost, and speed.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Snyk vs Semgrep: Full Comparison + Why Teams Are Choosing Corgea</title><link>https://corgea.com/blog/compare/snyk-vs-semgrep/</link><guid isPermaLink="true">https://corgea.com/blog/compare/snyk-vs-semgrep/</guid><description>Compare Snyk and Semgrep side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Corgea Reporting: Security and Developer Insights in One View</title><link>https://corgea.com/blog/corgea-reporting-security-and-developer-insights-in-one-view/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-reporting-security-and-developer-insights-in-one-view/</guid><description>Track code, dependency, code quality, IaC, scan activity, aging, and developer insights in one place. Filter reporting by project, tags, and time to see trends clearly.</description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate></item><item><title>New Integration: Bitbucket</title><link>https://corgea.com/blog/new-integration-bitbucket/</link><guid isPermaLink="true">https://corgea.com/blog/new-integration-bitbucket/</guid><description>Connect Corgea to Bitbucket in a day with an API-native integration—no CI/CD setup. Scan repos, get PR feedback, use Corgea Agent in Bitbucket, and open fix pull requests automa...</description><pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New in Corgea: Container Scanning + IaC Scanning</title><link>https://corgea.com/blog/new-in-corgea-container-scanning-iac-scanning/</link><guid isPermaLink="true">https://corgea.com/blog/new-in-corgea-container-scanning-iac-scanning/</guid><description>Scan container images for known CVEs and catch IaC misconfigurations before deploy. Corgea adds container/image scanning and Infrastructure as Code scanning for AppSec and devel...</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New Feature: Corgea Agent</title><link>https://corgea.com/blog/new-feature-corgea-agent/</link><guid isPermaLink="true">https://corgea.com/blog/new-feature-corgea-agent/</guid><description>Corgea Agent brings security into pull requests so developers can triage findings without leaving their workflow. Security teams get auditable feedback history and insights in t...</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New Product: Code Quality</title><link>https://corgea.com/blog/new-product-code-quality/</link><guid isPermaLink="true">https://corgea.com/blog/new-product-code-quality/</guid><description>Code Quality in Corgea finds high-confidence code quality issues using multi-file context and CWE-based categorization, with optional automated fixes. Try it now or book a demo.</description><pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AI Application Security: How AI Is Transforming AppSec in 2026</title><link>https://corgea.com/blog/ai-application-security-how-ai-is-transforming-appsec-in-2026/</link><guid isPermaLink="true">https://corgea.com/blog/ai-application-security-how-ai-is-transforming-appsec-in-2026/</guid><description>Codebases are growing faster than security headcount, scanner output is a firehose of noise, and developers treat security findings like spam. AI application security is the fir...</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate></item><item><title>13 Best Java Static Code Analysis Tools in 2026 (Ranked)</title><link>https://corgea.com/blog/best-java-static-code-analyzer-top-tools-ranked/</link><guid isPermaLink="true">https://corgea.com/blog/best-java-static-code-analyzer-top-tools-ranked/</guid><description>The best Java static code analysis tools for security, code quality and CI/CD in 2026, with a comparison table, framework awareness, auto-fix and pricing.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Here&apos;s what happening the last 72-hours: 700+ Packages Compromised from Shai-Hulud 2.0 Worm (November 25, 2025)</title><link>https://corgea.com/blog/here-s-what-happening-the-last-72-hours-700-packages-compromised-in-major-supply-chain-breach-november-25-2025/</link><guid isPermaLink="true">https://corgea.com/blog/here-s-what-happening-the-last-72-hours-700-packages-compromised-in-major-supply-chain-breach-november-25-2025/</guid><description>Critical npm worm compromises 700+ packages including Zapier, PostHog, and Postman. 25,000+ GitHub repos infected, exposing 775+ tokens. Immediate mitigation steps inside.</description><pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Sha1-Hulud: The Second Wave of npm Supply-Chain Attacks</title><link>https://corgea.com/blog/sha1-hulud-the-second-wave-of-npm-supply-chain-attacks/</link><guid isPermaLink="true">https://corgea.com/blog/sha1-hulud-the-second-wave-of-npm-supply-chain-attacks/</guid><description>Researchers uncovered a fast-moving npm supply-chain worm named Shai-Hulud. The malware injected malicious JavaScript (bundle.js) into popular packages.</description><pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Smarter Auto-Fixing for SAST Findings</title><link>https://corgea.com/blog/introducing-smarter-auto-fixing-for-sast-findings/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-smarter-auto-fixing-for-sast-findings/</guid><description>Corgea’s improved auto-fixing now delivers self-healing fixes, stronger quality checks, and 8% higher accuracy. Supports HTML, JSP, and integrates with Checkmarx, Fortify, Semgr...</description><pubDate>Thu, 23 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Extended APIs: Enhanced Security Management for Developers</title><link>https://corgea.com/blog/introducing-extended-apis-enhanced-security-management-for-developers/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-extended-apis-enhanced-security-management-for-developers/</guid><description>Discover Corgea&apos;s new Extended APIs for scans, issues, blocking rules, and scan operations. Automate security workflows, integrate with CI/CD pipelines, and build custom securit...</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea Dependency Scanning</title><link>https://corgea.com/blog/introducing-corgea-dependency-scanning/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-dependency-scanning/</guid><description>Stay ahead of open-source risks with Corgea’s new Dependency Scanning. Automatically detect vulnerabilities, enforce licenses, and apply grouped fix versions across multiple eco...</description><pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Announcing Reachability Analysis: Endpoint-Aware SAST in Corgea</title><link>https://corgea.com/blog/announcing-reachability-analysis-endpoint-aware-sast-in-corgea/</link><guid isPermaLink="true">https://corgea.com/blog/announcing-reachability-analysis-endpoint-aware-sast-in-corgea/</guid><description>Corgea’s new Reachability Analysis connects SAST findings to real web endpoints, showing which vulnerabilities are actually reachable from your API surface. Automatically maps e...</description><pubDate>Mon, 20 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Automate Your Security: Introducing Corgea&apos;s Scheduled Scans</title><link>https://corgea.com/blog/automate-your-security-introducing-corgea-s-scheduled-scans/</link><guid isPermaLink="true">https://corgea.com/blog/automate-your-security-introducing-corgea-s-scheduled-scans/</guid><description>Automate your security workflows with Corgea&apos;s new Scheduled Scans feature. Set up recurring SAST, SCA, secrets, and PII scans across projects with flexible scheduling, intellig...</description><pubDate>Fri, 12 Sep 2025 00:00:00 GMT</pubDate></item><item><title>The Three Waves of SAST: From Rules to AI-Native Analysis</title><link>https://corgea.com/blog/the-three-waves-of-sast-from-rules-to-ai-native-analysis/</link><guid isPermaLink="true">https://corgea.com/blog/the-three-waves-of-sast-from-rules-to-ai-native-analysis/</guid><description>Explore the evolution of Static Application Security Testing (SAST) — from legacy Fortify and Checkmarx, to developer-first tools like Snyk and Semgrep, and now AI-native SAST r...</description><pubDate>Sun, 24 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Whitepaper: JavaScript Security Scanning</title><link>https://corgea.com/blog/whitepaper-javascript-security-scanning/</link><guid isPermaLink="true">https://corgea.com/blog/whitepaper-javascript-security-scanning/</guid><description>How Corgea AI SAST classifies JavaScript as frontend or backend before scanning, so DOM XSS, injection, and logic flaws surface with fewer false positives.</description><pubDate>Tue, 12 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Introducing the new Scan Details Page</title><link>https://corgea.com/blog/introducing-the-new-scan-details-page/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-the-new-scan-details-page/</guid><description>Corgea’s Scan Details page gives security teams deep insight and control with an interactive dashboard to analyze and manage code vulnerabilities effectively.</description><pubDate>Fri, 20 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Source and Sink Tracing for Smarter Security</title><link>https://corgea.com/blog/introducing-source-and-sink-tracing-for-smarter-security/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-source-and-sink-tracing-for-smarter-security/</guid><description>Corgea’s Source &amp; Sink Analysis maps untrusted data flow end-to-end, bringing intelligent, enterprise-grade vulnerability analysis to your development workflow.</description><pubDate>Thu, 19 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Improved Multi-File Analysis and False Positive Reduction</title><link>https://corgea.com/blog/improved-multi-file-analysis-and-false-positive-reduction/</link><guid isPermaLink="true">https://corgea.com/blog/improved-multi-file-analysis-and-false-positive-reduction/</guid><description>Corgea’s upgraded multi-file analysis engine redefines static analysis by mapping your codebase context, analyzing file relationships, and understanding true system behavior.</description><pubDate>Wed, 18 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Introducing Policy YAML: Security Policies as Code, Built for Scale</title><link>https://corgea.com/blog/introducing-policy-yaml-security-policies-as-code-built-for-scale/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-policy-yaml-security-policies-as-code-built-for-scale/</guid><description>Corgea’s Policy-as-Code lets you define and enforce security standards as YAML in your repo, turning policies into actionable, automated code.</description><pubDate>Tue, 17 Jun 2025 00:00:00 GMT</pubDate></item><item><title>AI-Powered Policy Creation, Optimization, and Testing — All in One Place</title><link>https://corgea.com/blog/ai-powered-policy-creation-optimization-and-testing-all-in-one-place/</link><guid isPermaLink="true">https://corgea.com/blog/ai-powered-policy-creation-optimization-and-testing-all-in-one-place/</guid><description>Corgea’s Policy Playground &amp; Optimizer empower security teams to craft AI-enhanced policies that catch real issues and cut noise, all in one seamless environment.</description><pubDate>Mon, 16 Jun 2025 00:00:00 GMT</pubDate></item><item><title>Introducing BLAST: The Future of Security Testing is Here</title><link>https://corgea.com/blog/introducing-blast-the-future-of-security-testing-is-here/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-blast-the-future-of-security-testing-is-here/</guid><description>Corgea launches BLAST: an AI-powered platform to uncover and fix hidden business logic vulnerabilities, protecting enterprises from advanced cyber threats.</description><pubDate>Wed, 02 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Corgea Named Best SAST Auto-Fixing Solution in Recent Analyst Report</title><link>https://corgea.com/blog/corgea-named-best-sast-auto-fixing-solution-in-recent-analyst-report/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-named-best-sast-auto-fixing-solution-in-recent-analyst-report/</guid><description>We’re excited to share that Corgea has been recognized as the best SAST auto-fixing solution in the latest Actually Useful Product Guide report for Q1 2025. This recognition val...</description><pubDate>Mon, 03 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Streamline Security Response with Corgea&apos;s New SLA Management</title><link>https://corgea.com/blog/streamline-security-response-with-corgea-s-new-sla-management/</link><guid isPermaLink="true">https://corgea.com/blog/streamline-security-response-with-corgea-s-new-sla-management/</guid><description>Effective security requires more than just finding vulnerabilities - it&apos;s about having processes in place to prioritize and respond to issues based on their severity and potenti...</description><pubDate>Thu, 23 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Introducing PolicyIQ: Contextual Security Analysis for Smarter, More Accurate Results</title><link>https://corgea.com/blog/introducing-policyiq-contextual-security-analysis-for-smarter-more-accurate-results/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-policyiq-contextual-security-analysis-for-smarter-more-accurate-results/</guid><description>Corgea is excited to announce the release of PolicyIQ, a groundbreaking new feature that addresses the limitations of traditional static application security testing (SAST) tool...</description><pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate></item><item><title>Announcing Beagle: The Next Generation of AppSec LLMs</title><link>https://corgea.com/blog/announcing-beagle-the-next-generation-of-appsec-llms/</link><guid isPermaLink="true">https://corgea.com/blog/announcing-beagle-the-next-generation-of-appsec-llms/</guid><description>We are proud to introduce Beagle, the latest version of Corgea&apos;s fine-tuned AppSec LLM. Beagle represents a groundbreaking leap in automated vulnerability management, combining...</description><pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate></item><item><title>New Integrations for Streamlined Workflows</title><link>https://corgea.com/blog/new-integrations-for-streamlined-workflows/</link><guid isPermaLink="true">https://corgea.com/blog/new-integrations-for-streamlined-workflows/</guid><description>We&apos;re thrilled to announce the release of our new integrations for JIRA, Slack, Zapier, and webhooks! These powerful integrations are designed to seamlessly integrate Corgea int...</description><pubDate>Tue, 03 Dec 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Announces GitLab Integration</title><link>https://corgea.com/blog/corgea-announces-gitlab-integration/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-announces-gitlab-integration/</guid><description>Corgea, the leading automated code security platform, is excited to announce its integration with GitLab, the popular web-based DevOps lifecycle tool. This integration allows de...</description><pubDate>Mon, 02 Dec 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Expands Language Support: C, C++, Kotlin, and PHP for Enhanced Code Security</title><link>https://corgea.com/blog/corgea-expands-language-support-c-c-kotlin-and-php-for-enhanced-code-security/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-expands-language-support-c-c-kotlin-and-php-for-enhanced-code-security/</guid><description>Corgea is excited to announce the expansion of its language support to include C, C++, Kotlin, and PHP. We know how critical comprehensive language and framework support is for...</description><pubDate>Thu, 14 Nov 2024 00:00:00 GMT</pubDate></item><item><title>Whitepaper: BLAST, the AI-powered SAST scanner</title><link>https://corgea.com/blog/whitepaper-blast-ai-powered-sast-scanner/</link><guid isPermaLink="true">https://corgea.com/blog/whitepaper-blast-ai-powered-sast-scanner/</guid><description>Corgea: AI-powered app security that detects hidden flaws, cuts false positives by 30%, and accelerates fixes by 80%. Built for secure, fast devs.</description><pubDate>Thu, 24 Oct 2024 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea CodeIQ: Smarter Detection, Triaging, and Fixing of Insecure Code</title><link>https://corgea.com/blog/introducing-corgea-codeiq-smarter-detection-triaging-and-fixing-of-insecure-code/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-codeiq-smarter-detection-triaging-and-fixing-of-insecure-code/</guid><description>Introducing Corgea CodeIQ: Understand your codebase deeply, map code to the broader system, and revolutionize secure code analysis for developers and security teams.</description><pubDate>Wed, 09 Oct 2024 00:00:00 GMT</pubDate></item><item><title>The Future of SAST: A Shift to AI-Powered Security</title><link>https://corgea.com/blog/the-future-of-sast-a-shift-to-ai-powered-security/</link><guid isPermaLink="true">https://corgea.com/blog/the-future-of-sast-a-shift-to-ai-powered-security/</guid><description>Static Application Security Testing (SAST) has long been a foundational tool in the arsenal of software security. Designed to scrutinize codebases and identify vulnerabilities b...</description><pubDate>Tue, 08 Oct 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Announces Integration with Fortify to Enhance Application Security for Enterprises</title><link>https://corgea.com/blog/corgea-announces-integration-with-fortify-to-enhance-application-security-for-enterprises/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-announces-integration-with-fortify-to-enhance-application-security-for-enterprises/</guid><description>Corgea partners with Fortify to bring AI-driven triage and remediation to enterprise SAST, helping complex organizations strengthen app security at scale.</description><pubDate>Wed, 18 Sep 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Recognized as an IDC Innovator for DevSecOps Automated Remediation</title><link>https://corgea.com/blog/corgea-recognized-as-an-idc-innovator-for-devsecops-automated-remediation/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-recognized-as-an-idc-innovator-for-devsecops-automated-remediation/</guid><description>Corgea named an IDC Innovator for DevSecOps Automated Remediation, recognized for pioneering AI-driven secure code automation and innovation.</description><pubDate>Wed, 18 Sep 2024 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea&apos;s New Visual Studio 2022 Plugin: AI-Generated Fixes for Developers</title><link>https://corgea.com/blog/introducing-corgea-s-new-visual-studio-2022-plugin-ai-generated-fixes-for-developers/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-s-new-visual-studio-2022-plugin-ai-generated-fixes-for-developers/</guid><description>Corgea for Visual Studio 2022: Identify, analyze, and fix code vulnerabilities seamlessly with powerful in-editor security management.</description><pubDate>Wed, 04 Sep 2024 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea&apos;s AppSec LLM: Precision, Privacy, and Performance for Enterprise Security</title><link>https://corgea.com/blog/introducing-corgea-s-appsec-llm-precision-privacy-and-performance-for-enterprise-security/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-s-appsec-llm-precision-privacy-and-performance-for-enterprise-security/</guid><description>Introducing Corgea’s AppSec LLM: a private, enterprise-grade language model delivering precise vulnerability detection and secure, privacy-focused remediation.</description><pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate></item><item><title>New Product: BLAST - Business Logic Application Security Testing</title><link>https://corgea.com/blog/new-product-blast-business-logic-application-security-testing/</link><guid isPermaLink="true">https://corgea.com/blog/new-product-blast-business-logic-application-security-testing/</guid><description>Corgea launches BLAST: Business Logic Application Security Testing to help devs and security teams uncover critical business logic flaws in apps.</description><pubDate>Tue, 27 Aug 2024 00:00:00 GMT</pubDate></item><item><title>Fine-Tuning for Precision and Privacy: How Corgea&apos;s LLM Enhances Enterprise Application Security</title><link>https://corgea.com/blog/fine-tuning-for-precision-and-privacy-how-corgea-s-llm-enhances-enterprise-application-security/</link><guid isPermaLink="true">https://corgea.com/blog/fine-tuning-for-precision-and-privacy-how-corgea-s-llm-enhances-enterprise-application-security/</guid><description>Corgea: AI-powered AppSec engineer for enterprises, cutting false positives by 30% and speeding remediation by 80% with secure, private fine-tuned models.</description><pubDate>Fri, 23 Aug 2024 00:00:00 GMT</pubDate></item><item><title>How Corgea Improves Fix Accuracy and Coverage?</title><link>https://corgea.com/blog/how-corgea-improve-fix-accuracy-and-coverage/</link><guid isPermaLink="true">https://corgea.com/blog/how-corgea-improve-fix-accuracy-and-coverage/</guid><description>Corgea explains how its AI-driven platform improves SAST fix accuracy and coverage, delivering precise code fixes and reducing false positives for developers.</description><pubDate>Thu, 18 Jul 2024 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea Reporting</title><link>https://corgea.com/blog/introducing-corgea-reporting/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-reporting/</guid><description>Corgea launches a powerful reporting feature for AppSec and software engineers to track security posture, spot patterns, and drive measurable savings.</description><pubDate>Mon, 15 Jul 2024 00:00:00 GMT</pubDate></item><item><title>Introducing: Corgea&apos;s Advanced False Positive Detection</title><link>https://corgea.com/blog/introducing-corgea-s-new-feature-detecting-false-positives/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-s-new-feature-detecting-false-positives/</guid><description>Corgea introduces Advanced False Positive Detection for SAST, helping developers and security teams save time by reducing noise and focusing on real issues.</description><pubDate>Wed, 12 Jun 2024 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea&apos;s New Visual Studio Code Plugin: AI-Generated Fixes</title><link>https://corgea.com/blog/introducing-corgea-s-new-visual-studio-code-plugin-ai-generated-fixes/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-s-new-visual-studio-code-plugin-ai-generated-fixes/</guid><description>Boost productivity &amp; secure your code with Corgea&apos;s Visual Studio IDE Plugin. Detect &amp; fix vulnerabilities automatically with AI-generated fixes.</description><pubDate>Mon, 10 Jun 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Integration with Azure DevOps: Enhancing Code Security Through AI</title><link>https://corgea.com/blog/corgea-integration-with-azure-devops-enhancing-code-security-through-ai/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-integration-with-azure-devops-enhancing-code-security-through-ai/</guid><description>Corgea now integrates with Azure DevOps, enabling seamless, AI-powered code correction and security directly in your DevOps workflows.</description><pubDate>Mon, 29 Apr 2024 00:00:00 GMT</pubDate></item><item><title>Announcing Corgea&apos;s GitHub App for automated PR fixes</title><link>https://corgea.com/blog/announcing-corgea-s-github-app/</link><guid isPermaLink="true">https://corgea.com/blog/announcing-corgea-s-github-app/</guid><description>Corgea’s GitHub app brings enterprise-level security to small teams by detecting vulnerabilities and suggesting fixes—like your own in-house security engineer</description><pubDate>Thu, 21 Mar 2024 00:00:00 GMT</pubDate></item><item><title>Corgea&apos;s New GitHub Action</title><link>https://corgea.com/blog/corgea-s-new-github-action/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-s-new-github-action/</guid><description>Corgea now integrates with GitHub Actions, empowering developers to detect and fix vulnerable code seamlessly within their CI/CD workflow.</description><pubDate>Tue, 27 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Announcing New Language Support: C# and .Net for Automated Vulnerability Fixes</title><link>https://corgea.com/blog/announcing-new-language-support-c-and-net-for-automated-vulnerability-fixes/</link><guid isPermaLink="true">https://corgea.com/blog/announcing-new-language-support-c-and-net-for-automated-vulnerability-fixes/</guid><description>Corgea now supports automated code fixes for C# and .NET apps, extending our commitment to secure development across popular languages and frameworks.</description><pubDate>Sat, 24 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Announces New Integration with CodeQL Reports to Streamline Security Fixes</title><link>https://corgea.com/blog/corgea-announces-new-integration-with-codeql-reports-to-streamline-security-fixes/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-announces-new-integration-with-codeql-reports-to-streamline-security-fixes/</guid><description>Corgea now supports fixing CodeQL-detected vulnerabilities with seamless, automated remediation integrated directly into your workflow.</description><pubDate>Mon, 12 Feb 2024 00:00:00 GMT</pubDate></item><item><title>Corgea Now Supports Vulnerability Fixes in Java, Go, and Ruby</title><link>https://corgea.com/blog/corgea-now-supports-vulnerability-fixes-in-java-go-and-ruby/</link><guid isPermaLink="true">https://corgea.com/blog/corgea-now-supports-vulnerability-fixes-in-java-go-and-ruby/</guid><description>Corgea expands automated code fixes to Java, Go, and Ruby, ensuring comprehensive security coverage for widely-used programming languages.</description><pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate></item><item><title>Introducing &quot;Corgea&apos;s GitHub App&quot;</title><link>https://corgea.com/blog/introducing-corgea-s-github-app/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea-s-github-app/</guid><description>Corgea launches its GitHub App, delivering automated vulnerability patches via pull requests—seamlessly integrated into your team’s development workflow.</description><pubDate>Fri, 12 Jan 2024 00:00:00 GMT</pubDate></item><item><title>Introducing &quot;Download Fix&quot;</title><link>https://corgea.com/blog/introducing-download-fix/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-download-fix/</guid><description>Corgea’s new &apos;Download Fix&apos; feature lets developers instantly download patches for vulnerabilities detected by SAST tools like Snyk and Semgrep.&quot;</description><pubDate>Mon, 08 Jan 2024 00:00:00 GMT</pubDate></item><item><title>How does Corgea work?</title><link>https://corgea.com/blog/how-does-corgea-work/</link><guid isPermaLink="true">https://corgea.com/blog/how-does-corgea-work/</guid><description>Corgea connects to SAST tools like Snyk &amp; Semgrep, writes AI-powered fixes with explanations, saving security teams 80% effort &amp; speeding up patching.</description><pubDate>Fri, 15 Dec 2023 00:00:00 GMT</pubDate></item><item><title>Introducing Corgea</title><link>https://corgea.com/blog/introducing-corgea/</link><guid isPermaLink="true">https://corgea.com/blog/introducing-corgea/</guid><description>Corgea launches! Automatically secure vulnerable source code with AI-powered fixes, reducing effort by 80% and accelerating secure development.</description><pubDate>Wed, 13 Dec 2023 00:00:00 GMT</pubDate></item></channel></rss>