Besu2026-08-22 01:40:09Besu Discloses Five Fixed Vulnerabilities, Thanks CertiK for Responsible DisclosureBesu has published four security notices covering five vulnerabilities that CertiK identified and reported. The issues were fixed in Besu 26.7.1, released on July 27, and the technical details were made public on August 14. The bugs affected block announcement handling, caching for future block height consensus proposals, WebSocket subscription limits, and unbounded JSON-RPC filter creation. Besu said the flaws could, under specific configurations, let an attacker keep consuming memory or thread resources and affect node availability or consensus processing. CertiK found the issues through its Chain Scan adversarial research on a private multi-node Besu test network, submitted the vulnerabilities with reproducible proof-of-concept test frameworks, and coordinated confidentially with Besu before the fix was released. Besu thanked CertiK and EF Security in the release notes for responsible disclosure.1370
npm supply-ch2026-08-05 03:52:02SlowMist Warns of Large-Scale npm Supply-Chain Attack on Keyv/Cacheable EcosystemSlowMist disclosed on August 5 that it has detected a large-scale npm supply-chain attack affecting the Keyv/Cacheable ecosystem. Attackers have published more than 2,000 malicious package versions, including keyv@6.0.0. Keyv is a widely used key-value storage abstraction layer supporting Redis, SQLite, PostgreSQL, MongoDB and other backends, with roughly 127 million weekly downloads, creating potentially broad downstream supply-chain risk. The attack closely resembles the Shai-Hulud npm worm campaign, indicating strong automation and self-propagation. Potential malicious behaviors include credential theft, environment variable exfiltration, CI/CD secret leakage, remote payload delivery, and lateral movement through compromised development environments. SlowMist recommends security teams immediately identify and remove affected versions, upgrade to verified safe versions, review dependency lock files and build logs, monitor anomalous outbound connections, rotate potentially exposed credentials, and rebuild environments from trusted sources if compromise is suspected.1870