logo

Keyv npm worm hits 353 packages; device-code phishing surges 1,500%; TP-Link Omada RCE

ID: aa3d78c6-b781-5720-8aa2-58a554e2ff4d

STIX ID: report--aa3d78c6-b781-5720-8aa2-58a554e2ff4d

Feed Name: defend.network

Threat Score
80/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: defend.network

...
...

High‑risk briefing describing multiple active threats: a credential‑stealing Keyv npm worm that poisoned 353 package versions across 79 package names and implants hooks into developer tools; a 1,500% surge in OAuth device‑code phishing driven by the Greatness PhaaS enabling MFA bypass; Google ADK agent prompt‑injection issues that could escalate privileges; TP‑Link Omada ZTP vulnerabilities enabling potential RCE; confirmed misuse of OpenAI/Anthropic models in unauthorized penetration testing; and active exploitation of N‑able N‑central (CVE‑2026‑18577). The report includes recommended mitigations (dependency audits, credential rotation, disabling device‑authorization flows, patching Omada devices, isolating AI agent workflows, and reviewing third‑party testing scope) and cites CISA KEV and multiple security news sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.