logo

Last Week in AppSec for 08. January 2026

ID: 299d4872-a71d-5446-8135-33d8d875551c

STIX ID: report--299d4872-a71d-5446-8135-33d8d875551c

Feed Name: Checkmarx Zero

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

**Executive summary:** This Checkmarx Last Week In AppSec bulletin summarizes multiple security issues: active exploitation of the React2Shell deserialization flaw (observed payloads and exploitation in the wild), MongoBleed (a MongoDB memory disclosure allowing secret leakage), an AdonisJS multipart file write vulnerability enabling arbitrary/overwrite file writes, a RustFS hardcoded gRPC token enabling authentication bypass, and a modest malicious npm package related to Shai-Hulud with published IOCs; the report includes detection guidance, patches, and mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.