logo

Last Week in AppSec for 02. December 2025

ID: a2bbba62-d4d5-52b9-802a-d714e1f960b8

STIX ID: report--a2bbba62-d4d5-52b9-802a-d714e1f960b8

Feed Name: Checkmarx Zero

Threat Score
75/100

Date Published: 2025-12-01

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This Checkmarx AppSec weekly report highlights a resurgence of the Shai-Hulud self-replicating NPM worm (a more aggressive variant that steals GitHub/NPM credentials and can delete files if theft fails), a high-severity node-forge signature validation bypass (CVE-2025-12816), an Apache Syncope hard-coded AES key allowing decryption of stored passwords (CVE-2025-65998), memory-safety vulnerabilities in libxml2/libxslt affecting many XML/XSLT consumers, and multiple GitLab security fixes; the report lists affected versions and provides patching and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.