Last Week in AppSec for 15. January 2026
ID: 051f2b3e-85a2-5cfb-86e7-e3b3b7f89163
STIX ID: report--051f2b3e-85a2-5cfb-86e7-e3b3b7f89163
Feed Name: Checkmarx Zero
Threat Score
This report summarizes three AppSec issues: a cosign bug in Sigstore that weakened Rekor audit-log verification and could allow forged signatures, a pnpm remote-dependency integrity gap that requires lockfile regeneration to gain protections against tampered tarballs, and a critical n8n webhook vulnerability (CVE-2026-21858) enabling unauthenticated file access and potential remote code execution; it highlights affected versions, mitigation steps, and urgency for patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
