logo

Last Week in AppSec for 12. Feb 2026

ID: 5a5e4225-6d0f-598c-a4c9-e854857aa85e

STIX ID: report--5a5e4225-6d0f-598c-a4c9-e854857aa85e

Feed Name: Checkmarx Zero

Threat Score
78/100

Date Published: 2026-02-12

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This AppSec briefing highlights several active and high-risk issues: malicious dYdX packages published to npm and PyPI that harvest wallet credentials and include a Remote Access Trojan; a critical pre-auth OS command injection (RCE) in BeyondTrust Remote Support/Privileged Remote Access requiring immediate patching; emerging risks from AI memory poisoning and malicious agent "skills" that can steer assistants or reach tools and credentials; and a Docker Desktop for Windows local privilege escalation—each accompanied by concise remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.