logo

Last Week in AppSec for 15. January 2026

ID: 051f2b3e-85a2-5cfb-86e7-e3b3b7f89163

STIX ID: report--051f2b3e-85a2-5cfb-86e7-e3b3b7f89163

Feed Name: Checkmarx Zero

Threat Score
68/100

Date Published: 2026-01-15

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This report summarizes three AppSec issues: a cosign bug in Sigstore that weakened Rekor audit-log verification and could allow forged signatures, a pnpm remote-dependency integrity gap that requires lockfile regeneration to gain protections against tampered tarballs, and a critical n8n webhook vulnerability (CVE-2026-21858) enabling unauthenticated file access and potential remote code execution; it highlights affected versions, mitigation steps, and urgency for patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.