


CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

NPM Sec Analysis

Issue with tough, versions prior to 0.20.0 (Multiple CVEs)

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.


A Java helper to identify log4j in the current classpath

Shell injection in Rebar3

Find binary files not installed through package manager

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

Publish SBOM attestation

VEX Repository Specification

Collect VEX documents and update VEX Hub

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

A vulnerable Boa web server detector.

Extracts all the chart lists from ChartMuseum