.NET 8/9 support ends Nov 10, 2026; Windows Server 2012 ESU ends Oct 13. What each deadline covers, the 2012 R2 to 2025 direct in-place upgrade, and how to track both.
One Application Password per integration, CORS is not authorization, rate limits before PHP: how to harden /wp-json/ for headless and AI-era WordPress.
IEEE S&P 2026 study of 2.7M arXiv submissions: 265 API tokens, 7,326 GPS-tagged papers, 699 editable Google Docs, and why withdrawn versions stay online.
JFrog found 6 npm packages posing as Rollup polyfills. They install a second-stage package via CJS require(), not postinstall, then pull a RAT through JSONKeeper.
npm CLI 11.15.0 stages a tarball for maintainer 2FA approval before it hits the registry. Plus --allow-* install controls and how they differ from release-age gates and allowScripts.
Ghost 3.24.0–6.19.0 Content API SQLi leaked Admin API keys and injected ClickFix loaders into posts. Patch to 6.19.1+, rotate keys, and grep post bodies.
postcss, nanoid and browserslist all ship from one npm account: 964M downloads/week, no provenance. Not a breach but a single-publisher risk — what moved to staged releases, and what to check in your lockfile.
Actively exploited unauth RCE (CVSS 10.0) in Joomla JCE ≤2.9.99.4 via profile import, now in CISA KEV. Patch to 2.9.99.7, then hunt rogue profiles and webshells.
google-cloud-aiplatform 1.139.0/1.140.0 had a predictable Model.upload staging bucket: pre-create that GCS bucket and you get model-swap RCE with no victim creds. Fixed in 1.148.0.
Chainguard has blocked 52,000+ npm packages as malware or greyware, scanning 100,000+ a day, catching README-honest credential CLIs that release-age gates and npm v12 miss.
On June 17, 2026 Mastra's @mastra/* packages were re-published with an added easy-day-js dependency whose postinstall runs a RAT at install. Counts: 116 official vs 143–144 external.