Bogdan Deac

Bogdan Deac

yet another Software Engineer

newsletter

PEAKS No 45: Kernel on Fire — Supply Chains Compromised, AI Goes Local, and Pixels Fall

Hi there! 🛡️ Security & Privacy * TanStack supply chain taken down by chained GitHub Actions exploit: An attacker combined a pull_request_target Pwn Request, GitHub Actions cache poisoning across fork/base trust boundaries, and in-memory OIDC token extraction to silently publish 84 malicious versions across 42 @tanstack/* npm packages — stealing
4 min read
newsletter

PEAKS No 42: The Open-Weight Uprising: GPT-5.5, Qwen Beats a 397B Giant, and Your Jira Data Is Now AI Training Fuel

Hi there! 🛡️ Security & Privacy * 🚨 Bitwarden CLI 2026.4.0 compromised in supply chain attack — Attackers abused a GitHub Action in Bitwarden's CI/CD pipeline as part of the ongoing Checkmarx campaign; update immediately and rotate credentials. More * Pack2TheRoot (CVE-2026-41651): cross-distro Linux privilege escalation — CVSS 8.8; exploits
4 min read
newsletter

PEAKS No 39: The Claude Code Files: Source Leaks, AI Emotions, Supply Chain Chaos & Privacy Wars

Hi there! 🛡️ Security & Privacy * Vertex AI vulnerability allowed malicious agents to exfiltrate Google Cloud data and access private Artifact Registry images — exploiting excessive default permissions in the P4SA service agent. Patch by enforcing least privilege and using BYOSA. More * axios supply chain attack: a hijacked npm maintainer account published
4 min read
newsletter

PEAKS No 37: Coding Agents Meet Chrome DevTools, Unicode Malware Returns, Local AI Goes Mainstream

Hi there! 🛡️ Security & Privacy * Glassworm Returns with Unicode Attacks - Invisible PUA Unicode characters exploiting 150+ GitHub repositories, npm packages & VS Code extensions simultaneously using AI-crafted commits. More * DarkSword iOS Exploit in Infostealer Campaign - New vulnerability targeting iPhones via malicious apps stealing credentials and sensitive data at
3 min read
newsletter

PEAKS No 36: Meta-Google AI Deals, AppArmor Meltdown, Glassworm Returns

Hi there! 🛡️ Security & Privacy * Multiple critical AppArmor vulnerabilities enable kernel exploitation, privilege escalation, memory disclosure affecting Ubuntu, Debian systems. More * Glassworm malware returns with invisible Unicode code injection attacking 150+ GitHub repositories, npm packages spreading across ecosystems silently. More * Canada's Bill C-22 mandates metadata retention for telecom
1 min read