The brief

Wednesday, August 5, 2026

ChainDrop worm compromised 1,300+ npm packages (2B monthly downloads including Keyv, flat-cache) in active supply chain attack. Critical RCE vulnerabilities exist in Flowise (CVSS 9.4-9.5), HPE SD-WAN Orchestrator (CVSS 9.8), and GL.iNet routers—patch immediately.

12 stories · 3 podcasts · get this by email each weekday

Today's stories

Worth a listen

  • OpenAI's Joshua Achiam: Did We Already Reach AGI?

  • NPM? Not my problem.

  • Why AI Washing Won’t Work Much Longer

← All editions