FACTUALRISK Cyber Intelligence
Mise à jour : 29 Aug 2026 · 00:03
← Accueil
🗞 Briefing
💥 Menaces
🛡 Vulnérabilités
📋 Conformité
📚 Guides
← Retour FactualRisk
Incidents
22
CVEs SC
52
KEV
4
P0
5
Catégories
Supply Chain14
Backdoor4
Package Compromise4
CVEs supply chain actifs
CVEPrioCVSSEPSSVendorProduitATT&CKSignaux
CVE-2021-23758MAJ P0 9.8 0.891 Ajax.NET ProfessionalAjax.NET Professional T1059, T1203, T1021.004 KEVITW
CVE-2026-64849 P0 9.3 0.164 MLflowMLflow T1090, T1071, T1021.004 KEVITW
CVE-2026-73570MAJ P0 8.9 0.015 SynacorZimbra Collaboration Suite (ZCS) T1059.004, T1190, T1114 KEVITW
CVE-2026-74232NOUVEAU P0 9.8 0.005 T1542, T1495, T1021.004 ITW
CVE-2026-44017MAJ P0 7.5 0.007 pipdocling T1083, T1005, T1021.004 ITW
CVE-2015-3246MAJ P1 5.1 0.071 Red HatLibuser T1195, T1195.002 KEVITW
CVE-2026-55548NOUVEAU P2 4.3 0.004 mavenorg.yamcs:yamcs-core T1021.004, T1133 ITW
CVE-2026-46456MAJ P1 9.8 0.008 mavenorg.apache.camel:camel-aws2-sqs T1190, T1114, T1566
CVE-2026-55565NOUVEAU P1 9.9 0.000 mavenorg.yamcs:yamcs-core T1059, T1190, T1059.007
CVE-2026-55559NOUVEAU P1 9.8 0.000 mavenorg.yamcs:yamcs-core T1059, T1021.004, T1133
CVE-2026-48203MAJ P2 9.1 0.006 mavenorg.apache.camel:camel-solr T1190, T1114, T1566
CVE-2026-46455MAJ P1 9.8 0.007 mavenorg.apache.camel:camel-keycloak
CVE-2026-55511NOUVEAU P2 9.1 0.000 mavenorg.yamcs:yamcs-core T1059, T1190, T1059.007
CVE-2026-46590MAJ P2 8.8 0.008 mavenorg.apache.camel:camel-pqc T1059, T1203, T1190
CVE-2026-66906NOUVEAU P2 9.1 0.005 mavenorg.apache.camel:camel-azure-storage-blob T1021.004, T1133
CVE-2026-55521NOUVEAU P2 8.8 0.000 mavenorg.yamcs:yamcs-core
CVE-2026-55638NOUVEAU P2 8.6 0.006 npm9router T1021.004, T1133, T1195
CVE-2026-55175NOUVEAU P3 7.5 0.011 mavenio.spinnaker.rosco:rosco-manifests T1059, T1203, T1021.004
CVE-2026-46726MAJ P3 7.5 0.009 mavenorg.apache.camel:camel-vertx-websocket T1190, T1114, T1566
CVE-2026-55993MAJ P3 7.5 0.009 mavenorg.apache.camel:camel-atmosphere-websocket T1190, T1114, T1566
CVE-2026-46457MAJ P3 7.5 0.007 mavenorg.apache.camel:camel-nats T1190, T1114, T1566
CVE-2026-46585MAJ P3 7.5 0.006 mavenorg.apache.camel:camel-lucene T1190, T1114, T1566
CVE-2026-55994MAJ P3 7.5 0.006 mavenorg.apache.camel:camel-iggy T1190, T1114, T1566
CVE-2026-46592MAJ P3 7.5 0.006 mavenorg.apache.camel:camel-cxf-soap T1190, T1114, T1566
CVE-2026-66908NOUVEAU P3 7.5 0.004 mavenorg.apache.camel:camel-platform-http-main T1078, T1556, T1566
CVE-2026-55552NOUVEAU P3 7.5 0.000 mavenorg.yamcs:yamcs-core T1083, T1005, T1190
CVE-2026-46591MAJ P2 8.2 0.005 mavenorg.apache.camel:camel-neo4j
CVE-2026-49042MAJ P3 7.3 0.007 mavenorg.apache.camel:camel-langchain4j-tools T1190
CVE-2026-46588MAJ P3 7.3 0.007 mavenorg.apache.camel:camel-couchdb T1190, T1114, T1566
CVE-2026-46587MAJ P3 7.3 0.007 mavenorg.apache.camel:camel-couchbase T1190, T1114, T1566
CVE-2026-55641NOUVEAU P2 8.2 0.003 npm9router T1021.004, T1133, T1195
CVE-2026-55673NOUVEAU P3 7.1 0.000 mavencom.powsybl:powsybl-computation-local T1059.004, T1190, T1210
CVE-2026-66907NOUVEAU P3 7.5 0.006 mavenorg.apache.camel:camel-google-storage T1021.004, T1133
CVE-2026-6322MAJ P3 7.5 0.005 npmfast-uri T1021.004, T1133, T1195
CVE-2026-13676MAJ P3 7.5 0.004 npmfast-uri T1195, T1195.002
CVE-2026-55215NOUVEAU P3 7.5 0.000 npmmariadb T1114, T1566, T1195
CVE-2026-49086MAJ P3 6.5 0.007 mavenorg.apache.camel:camel-dapr T1190, T1114, T1566
CVE-2026-49097MAJ P3 6.5 0.007 mavenorg.apache.camel:camel-irc T1190, T1114, T1566
CVE-2026-59230NOUVEAU P3 6.5 0.004 mavenorg.apache.camel:camel-mail T1190, T1114, T1566
CVE-2026-55549NOUVEAU P3 6.5 0.000 mavenorg.yamcs:yamcs-core T1059.007, T1190, T1189
CVE-2026-55545NOUVEAU P3 6.5 0.000 mavenorg.yamcs:yamcs-core T1021.004, T1133
CVE-2026-49098MAJ P3 5.3 0.006 mavenorg.apache.camel:camel-kafka T1190, T1114, T1566
CVE-2026-48206MAJ P3 5.3 0.006 mavenorg.apache.camel:camel-jira T1190, T1114, T1566
CVE-2026-63621NOUVEAU P3 5.3 0.004 mavenorg.apache.camel:camel-knative T1190
CVE-2026-60093NOUVEAU P3 5.5 0.003 mavenorg.apache.camel:camel-azure-storage-datalake T1021.004, T1133
CVE-2026-49365MAJ P3 5.3 0.006 mavenorg.apache.camel:camel-netty-http T1190, T1059.007
CVE-2026-56139MAJ P3 5.3 0.006 mavenorg.apache.camel:camel-undertow T1190, T1059.007
CVE-2026-49099MAJ P3 5.3 0.005 mavenorg.apache.camel:camel-salesforce T1114, T1566, T1021.004
CVE-2026-55566NOUVEAU P3 4.3 0.000 mavenorg.yamcs:yamcs-core T1059.007, T1190, T1189
CVE-2026-55425NOUVEAU P3 5.0 0.000 mavenorg.graylog2:graylog2-server
CVE-2026-46584MAJ P3 3.7 0.006 mavenorg.apache.camel:camel-mail T1190, T1114, T1566
CVE-2026-55547NOUVEAU P3 4.3 0.000 mavenorg.yamcs:yamcs-core
📰 Incidents récents
Supply Chain GitHub Security Wed, 29 Ju
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your u
Supply Chain OpenSSF Wed, 26 Au
Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes
Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security
Backdoor TheHackerNews Wed, 26 Au
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published
Backdoor TheHackerNews Wed, 26 Au
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
Supply Chain DarkReading Wed, 26 Au
'HTTP Terminator' Hunts for Novel Desync Attacks
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
Package Compromise GitHub Security Tue, 28 Ju
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog .
Supply Chain OpenSSF Tue, 25 Au
What’s in the SOSS? Podcast #70 – S3E22 Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo
In this episode of What's in the SOSS, host Sally Cooper and Red Hat's Dave Russo unpack the European Union’s Cyber Resilience Act (CRA). Discover the hidden financial toll of private forks, the crucial legal distinction between manufacturers and open source stewards, and actiona
Package Compromise TheHackerNews Tue, 25 Au
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downl
Supply Chain DarkReading Tue, 25 Au
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Supply Chain OpenSSF Tue, 18 Au
What’s in the SOSS? Podcast #69 – S3E21 Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov
Supply Chain OpenSSF Tue, 11 Au
What’s in the SOSS? Podcast #68 – S3E20 CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight
Join Megan Knight on the What's in the SOSS podcast as she breaks down the upcoming EU Cyber Resilience Act (CRA) and shares practical compliance strategies for open source maintainers and organizations.
Supply Chain OpenSSF Tue, 04 Au
What’s in the SOSS? Podcast #67 – S3E19 Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou
Supply Chain Snyk Blog Tue, 04 Au
A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense
Explore Snyk’s first Agentic AppSec capabilities: an autonomous Remediation Agent that fixes vulnerabilities and Malicious Code Defense that blocks risky packages before they ship.
Package Compromise Snyk Blog Tue, 04 Au
Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
keyv 6.0.0 and ten related npm releases shipped install-time malware. See affected versions, hashes, detection steps, and safe remediation order.
Supply Chain BleepingComputer Thu, 27 Au
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. [...]
Supply Chain TheHackerNews Thu, 27 Au
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gatew
Backdoor DarkReading Thu, 27 Au
Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Supply Chain GitHub Security Thu, 13 Au
What 50 open source projects taught us about security in the AI era
See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about sec
Package Compromise GitHub Security Thu, 06 Au
How we took malware advisories beyond npm
GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malware advisories beyond npm appeared first on The GitHub Blog .
Supply Chain TheHackerNews Mon, 24 Au
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never bu
Supply Chain TheHackerNews Mon, 24 Au
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks t
Backdoor TheHackerNews Fri, 28 Au
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a p

L'écosystème

Digimoove ESN Paris — Cyber · Cloud · Automatisation IA · Observabilité NAIvigate Veille & formation IA FactualRisk est une marque de l'écosystème Digimoove