logo

BlueNoroff npm supply chain attack; WordPress Gravity SMTP exploited on 100k sites

ID: 42f6026c-9687-5df8-ae0b-e3d5c475a8e7

STIX ID: report--42f6026c-9687-5df8-ae0b-e3d5c475a8e7

Feed Name: defend.network – Daily Threat Briefings

Threat Score
85/100

Date Published: 2026-06-21

Date Updated: 2026-06-21

...
...

TL;DR: Multiple high-severity incidents reported — a North Korean-linked supply-chain compromise of 140+ npm packages via Mastra AI, active exploitation of Gravity SMTP (CVE-2026-4020) exposing API keys across many WordPress sites, Microsoft-disclosed AutoJack RCE against AI browsing agents, a Klue OAuth breach leaking Salesforce tokens, and a multinational disruption of SocGholish; urgent actions recommended include patching/removing vulnerable plugins, auditing dependencies, rotating tokens, and tightening network/local service controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.