Why now
Recent attacks and the EU laws that now apply
Attackers are exploiting common weaknesses in ordinary code and configuration, and EU law now expects you to find them first and prove it. Here is each recent attack, the check in Vulkro that flags its root cause, and the regulation that makes it your problem.
22 recent attacks · 6 EU laws · every one sourced
01Recent attacks
Every one of these started with a weakness Vulkro checks for.
Not exotic zero-days. Over-trusted integrations, missing authorization checks, secrets in code, poisoned packages and exposed agent tools. Each card names the root cause and the check that flags it.
- Sep 2026
Agentforce turned a public lead form into a data leak
Researchers disclosed SalesBleed: hidden instructions submitted through a public Web-to-Lead form could make an Agentforce agent query account data and send it out through a DNS technique that bypassed the Trusted URLs redaction. Salesforce deployed a fix for the redaction bypass on 18 August 2026, before public disclosure on 24 September.
- Root cause
- An agent that reads free text anyone can submit, with read access to more records than the task needs and an output path that can carry data out in a URL.
- Vulkro flags
- Vulkro for Salesforce flags prompt templates that bind a publicly writable field such as a Web-to-Lead description, prompt templates that emit untrusted URLs, and the complete chain when an exit channel exists.
sf-forcedleak-writable-field-in-promptsf-forcedleak-untrusted-url-in-promptsf-forcedleak-exfil-chainSource: Infosecurity Magazine: vulnerabilities in Salesforce Agentforce expose wider AI agent risk
- Aug 2026
A new npm worm spread through keyv and related packages
Singapore's Cyber Security Agency warned of a new Shai-Hulud wave that compromised keyv and related packages, more than 1,300 package versions in all. The malware steals cloud credentials, GitHub tokens, SSH keys and Kubernetes configurations, and spreads by compromising further packages.
- Root cause
- Install-time code that downloads and runs a second stage, reads credentials, and uses a stolen publish token to republish itself.
- Vulkro flags
- Vulkro flags install code that fetches and runs a remote payload, reads credential files, sends credentials out, and pairs a publish token with npm publish.
MAL-LOADER-001MAL-CRED-001MAL-EXFIL-001MAL-WORM-001Source: CSA Singapore: ongoing npm supply chain attack affecting keyv and related packagesRead the analysis →
- Jun 2026
Stolen integration tokens used to read Salesforce data
An attacker used a long-disused but still active credential at Klue to push code that collected the OAuth tokens customers had granted its app, then ran bulk queries against customer Salesforce data through the REST API. Salesforce disabled the Klue integration on 11 June 2026 and said the issue did not arise from a vulnerability in the Salesforce platform.
- Root cause
- A third-party app holding long-lived OAuth tokens with broad access to the org, usable from any network.
- Vulkro flags
- Vulkro for Salesforce flags broad-scope OAuth apps with no IP restriction, refresh tokens that never expire or rotate, and dormant tokens that still work (live-org checks, part of Pro).
SF-OAUTH-APP-002SF-OAUTH-APP-004SF-OAUTH-TOKEN-001Source: The Hacker News: Salesforce disables Klue app integration after OAuth token abuseRead the analysis →
- May 2026
TanStack packages published with malware from its own CI
On 11 May 2026 an attacker published 84 malicious versions across 42 @tanstack/* npm packages under the project's trusted-publisher identity, by chaining a pull_request_target workflow, a GitHub Actions cache shared with fork runs, and an OIDC token read from runner memory. The payload stole cloud, GitHub, npm and SSH credentials.
- Root cause
- A pull_request_target workflow that ran untrusted pull request code with the base repository's trust, including a cache the release job later used.
- Vulkro flags
- Vulkro flags workflows that check out untrusted pull request code under pull_request_target, and flags the malicious @tanstack versions in your lockfile as known-malicious.
SUPPLY-CI-002CVE-2026-45321 (GHSA-g7cv-rxg3-hmpx)MAL-2026-3465 (known-malicious package)Source: GitHub Advisory: malware in @tanstack/* packages (CVE-2026-45321)Read the analysis →
- May 2026
SQL injection in an AI gateway exploited in the wild
CVE-2026-42208 let an unauthenticated attacker send a crafted Authorization header to any LiteLLM proxy model route and reach a key-check query that mixed the caller's value into the query text. CISA added it to its Known Exploited Vulnerabilities catalog on 8 May 2026.
- Root cause
- Request data, here an API key taken from a header, placed into SQL text instead of being passed as a bound parameter.
- Vulkro flags
- Vulkro traces request data into SQL calls and flags queries built from it, and flags the vulnerable litellm version as Critical with a CISA KEV tag.
tainted-source-detected (SQL injection)CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)CISA KEV tagSource: GitHub Advisory: LiteLLM SQL injection in proxy API key verification
- Apr 2026
An unauthenticated MCP endpoint handed over web servers
CVE-2026-33032, rated CVSS 9.8, left the /mcp_message endpoint of nginx-ui's MCP integration without authentication, so anyone who could reach it could invoke tools that create, modify or delete nginx configuration and restart the server. BleepingComputer reported in April 2026 that the flaw was under active exploitation, with about 2,600 instances exposed.
- Root cause
- A route that performs privileged actions registered without the authentication its sibling route enforces.
- Vulkro flags
- Vulkro flags state-changing routes that are registered with no authentication.
no-auth-middleware-detectedSource: BleepingComputer: critical Nginx UI auth bypass flaw now actively exploitedRead the analysis →
- Mar 2026
Public Salesforce sites mass-scanned for guest data
Salesforce warned that threat actors were mass-scanning public Experience Cloud sites with a modified auditing tool that could extract data, and said the activity related to a customer-configured guest user setting, not a platform flaw.
- Root cause
- Guest user profiles and guest-callable Apex that can read records and fields an anonymous visitor should never see.
- Vulkro flags
- Vulkro for Salesforce flags guest-reachable Aura methods that return records without field security or perform privileged actions, and guest access to sensitive fields.
sf-guest-aura-read-no-flssf-guest-aura-class-grantsf-guest-meta-sensitive-field-readSource: Salesforce: securing Experience Cloud guest user access (Mar 2026)Read the analysis →
- Mar 2026
An axios release on npm pulled in a remote access trojan
CISA reported that axios 1.14.1, published to npm on 31 March 2026, pulled in a malicious dependency, plain-crypto-js, which downloads multi-stage payloads including a remote access trojan. It told users to downgrade, delete the dependency and rotate repository, CI, cloud, npm and SSH credentials.
- Root cause
- A trusted dependency version that adds a new package whose install-time code fetches and runs a remote payload.
- Vulkro flags
- Vulkro flags the malicious axios and plain-crypto-js versions in your lockfile as known-malicious, and flags install code that fetches and runs a remote payload.
MAL-2026-2307 (axios 1.14.1)MAL-2026-2306 (plain-crypto-js 4.2.1)MAL-LOADER-001Source: CISA: supply chain compromise impacts axios Node Package ManagerRead the analysis →
- Mar 2026
A popular CI action's tags rewritten to steal secrets
On 19 March 2026 an attacker with compromised credentials force-pushed 76 of 77 version tags of the trivy-action GitHub Action, and every tag of setup-trivy, to commits that stole CI secrets before running the normal scan. CISA added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog, and the advisory tells users to pin actions to full commit SHAs.
- Root cause
- Workflows that use a third-party action by a mutable tag, so whoever controls the tag decides what runs next to the job's secrets.
- Vulkro flags
- Vulkro flags workflow steps that use a third-party action by a tag or branch instead of a commit SHA, and flags secrets passed to such an action.
SUPPLY-CI-003SUPPLY-CI-006Source: GitHub Advisory: CI action supply chain compromise (CVE-2026-33634)Read the analysis →
- Feb 2026
React Native development servers exploited
Attackers exploited CVE-2025-11953, rated CVSS 9.8, in the Metro development server of the @react-native-community/cli npm package, which lets remote unauthenticated attackers run operating system commands, and used it to deliver malware. CISA added it to its Known Exploited Vulnerabilities catalog on 5 February 2026.
- Root cause
- A vulnerable version of a development tool in the dependency tree, running a server that the network can reach.
- Vulkro flags
- Vulkro flags the vulnerable @react-native-community/cli version in your lockfile as Critical and tags it as actively exploited from the CISA KEV list.
CVE-2025-11953 (GHSA-399j-vxmf-hjvr)CISA KEV tagSource: The Hacker News: hackers exploit Metro4Shell RCE flaw in React Native CLI npm package
- Jan 2026
Exposed Vite dev servers returned files they should not
CISA added CVE-2025-31125 to its Known Exploited Vulnerabilities catalog on 22 January 2026, based on evidence of active exploitation. The Vite flaw lets crafted import query strings return the contents of arbitrary files through the dev server; fixed versions shipped in March 2025.
- Root cause
- A vulnerable version of a build tool whose development server is reachable from outside the machine.
- Vulkro flags
- Vulkro flags the vulnerable vite version in your lockfile as Critical and tags it as actively exploited from the CISA KEV list.
CVE-2025-31125CISA KEV tagSource: The Hacker News: CISA updates KEV catalog with four actively exploited flaws
- Dec 2025
React Server Components remote code execution
React disclosed CVE-2025-55182, an unauthenticated remote code execution flaw in React Server Components rated CVSS 10.0. CISA added it to its Known Exploited Vulnerabilities catalog two days later, based on evidence of active exploitation.
- Root cause
- A vulnerable version of react-server-dom-webpack, -parcel or -turbopack in the dependency tree of an app that exposes Server Function endpoints.
- Vulkro flags
- Vulkro flags the vulnerable package version in your lockfile as Critical and tags it as actively exploited from the CISA KEV list.
CVE-2025-55182 (GHSA-fv66-9v8q-g76r)CISA KEV tagSource: React: critical security vulnerability in React Server ComponentsRead the analysis →
- Sep 2025
Agentforce prompt injection through a Web-to-Lead field
Researchers disclosed ForcedLeak: instructions planted in a Web-to-Lead description were later followed by Agentforce and could send CRM data to a domain that sat on an allowlist after it had expired. Salesforce began enforcing Trusted URLs for Agentforce on 8 September 2025.
- Root cause
- A prompt template that grounds on a free-text field the public can write, plus an exit channel the agent can use without anyone approving it.
- Vulkro flags
- Vulkro for Salesforce flags prompt templates that bind a publicly writable field, prompt templates that emit untrusted URLs, and the complete chain when an exit channel exists.
sf-forcedleak-writable-field-in-promptsf-forcedleak-untrusted-url-in-promptsf-forcedleak-exfil-chaincsptrustedsite-wildcardSource: The Register: prompt injection and a $5 domain trick AgentforceRead the analysis →
- Sep 2025
A fake MCP server copied every email it sent
An npm package impersonating Postmark built trust over 15 versions, then added a backdoor in version 1.0.16 that blind-copied every email sent through it to an external address. Postmark said it had no involvement with the package.
- Root cause
- An MCP server launched by package name with no version pin, so the host pulls whatever the publisher ships next.
- Vulkro flags
- Vulkro flags MCP servers launched without a pinned version and flags postmark-mcp 1.0.16 as a known-malicious package.
MCP-001AGENT-005MAL-2025-47604 (known-malicious package)Source: Postmark: information regarding the malicious postmark-mcp packageRead the analysis →
- Sep 2025
A self-replicating worm spread through npm
The Shai-Hulud worm entered npm through compromised maintainer accounts and malicious post-install scripts, harvested tokens and cloud keys, and republished itself into other packages. GitHub removed more than 500 compromised packages.
- Root cause
- Install-time scripts that read credentials and send them out, run with publish tokens that let the code republish itself.
- Vulkro flags
- Vulkro flags code that reads credentials next to a network call, code that pairs a publish token with npm publish or a workflow write, risky install scripts, and the compromised versions themselves.
MAL-EXFIL-001MAL-WORM-001MAL-PKG-001SUPPLY-CI-001known-malicious package (OSV MAL advisory)Source: CISA: widespread supply chain compromise impacting npm ecosystemRead the analysis →
- Sep 2025
debug, chalk and other npm packages hijacked after phishing
The npm publishing account behind debug was taken over after a phishing attack, and malicious versions of debug, chalk and other packages were published. The advisory describes a browser payload that tried to redirect cryptocurrency transactions; npm removed the debug version on 8 September 2025.
- Root cause
- A browser payload that wraps fetch and wallet APIs to rewrite crypto addresses, shipped inside a trusted dependency version.
- Vulkro flags
- Vulkro flags the hijacked versions in your lockfile as known-malicious and flags code that overrides network primitives to rewrite crypto addresses.
MAL-2025-46969 (chalk 5.6.1)MAL-2025-46974 (debug 4.4.2)MAL-WALLET-003Source: GitHub Advisory: debug 4.4.2 contains malware after npm account takeoverRead the analysis →
- Aug 2025
Nx build tool published with a credential stealer
A GitHub Actions workflow that printed pull request titles unsanitised let an attacker steal the Nx npm token and publish malicious versions. Their post-install script hunted for secrets, reportedly by driving local AI coding CLIs with their permission prompts turned off.
- Root cause
- Untrusted pull request text expanded into a shell under pull_request_target, and an install script that runs AI coding agents with guardrails disabled.
- Vulkro flags
- Vulkro flags workflow expressions that inject event text into a shell, AI agent CLIs launched with permission-bypass flags, and the malicious Nx versions.
CICD-001AGENT-AUTONOMY-001GHSA-cxm3-wv7p-598c (known-malicious package)Source: Nx security advisory GHSA-cxm3-wv7p-598cRead the analysis →
- Jul 2025
Job-applicant records reachable by changing one number
Researchers reported that a hiring platform used by McDonald's exposed applicant records through a default admin login and an API that returned any applicant by a sequential id, with up to 64 million records reachable. The vendor said only the researchers accessed applicant data, and the issue was closed within a day of disclosure.
- Root cause
- An API handler that loads a record by a caller-supplied id without checking that the caller may see it.
- Vulkro flags
- Vulkro flags handlers that look up a record by a caller-supplied id with no ownership or tenant check.
idor-authn-no-ownershipAUTHZ-001Source: Ian Carroll: McHire disclosure write-upRead the analysis →
- May 2025
Generated web apps shipped databases readable by anyone
CVE-2025-48757 describes sites generated by an AI app builder whose Supabase tables could be read or written by unauthenticated users because Row Level Security was missing or insufficient. The platform supplier disputes the CVE, saying each customer is responsible for protecting their own data.
- Root cause
- Browser code querying database tables directly with a public key while no Row Level Security policy restricts what that key can read.
- Vulkro flags
- Vulkro flags client code that reaches Supabase tables with no Row Level Security evidence in the repo, service-role keys in browser code, and wide-open Firebase rules.
SUPA-RLS-003SUPA-RLS-002SUPA-RLS-001Source: CVE-2025-48757 write-up by the reporting researcherRead the analysis →
- Mar 2025
AI assistants invent package names attackers can register
A USENIX Security 2025 study of 576,000 generated code samples found that models recommend packages that do not exist: 5.2% on average for commercial models and 21.7% for open-source ones, with 205,474 unique invented names.
- Root cause
- A dependency list written by an assistant and installed without checking that each name is real and the one intended.
- Vulkro flags
- Vulkro flags documented hallucinated names, typosquats of popular packages and decoy suffixes before you install them.
slopcheck: hallucinatedslopcheck: typosquat-ofpackage-risk: slopsquatSource: Spracklen et al., We Have a Package for You! (USENIX Security 2025)Read the analysis →
- Oct 2024
Credentials stolen from exposed Git and .env files
Researchers reported a campaign that scanned the internet for exposed .git/config and Laravel .env files and collected more than 15,000 cloud credentials, then used them to clone private repositories and hunt for more secrets.
- Root cause
- Live credentials written into configuration files and repositories, where one exposure hands over everything they unlock.
- Vulkro flags
- Vulkro flags credentials in source and config files, and on Pro, credentials that were committed and later removed from git history.
literal-string-secretprovider-format-matchgit-history-secrets (Pro)Source: BleepingComputer: hackers steal 15,000 cloud credentials from exposed Git config filesRead the analysis →
- Mar 2024
CISA and the FBI: SQL injection is still shipping
CISA and the FBI issued a Secure by Design alert after a widely exploited SQL injection in a managed file transfer product, saying software manufacturers continue to ship the defect and urging parameterized queries.
- Root cause
- Request data concatenated into a SQL string instead of being passed as a bound parameter.
- Vulkro flags
- Vulkro traces request data into SQL calls and flags the ones that build the query by concatenation, in application code and in Apex.
js-taint-sql-001GO-SQLI-001apex-taint-soql-injectionSource: CISA and FBI: Secure by Design alert on eliminating SQL injectionRead the analysis →
What no scanner does: stop an employee from approving a malicious app on a phone call. What Vulkro does is shrink what that approval can reach: the over-privileged users, the integrations with org-wide access and the code that hands out data.
02EU law
EU law now requires security evidence, with set dates
The Cyber Resilience Act, NIS2, DORA, the new Product Liability Directive and the AI Act move software security from good practice to duty. Vulkro produces the evidence these laws ask for, continuously.
- 11 Sep 2026Vulnerability and incident reporting applies
Cyber Resilience Act Regulation (EU) 2024/2847
Manufacturers of products with digital elements, software included, made available on the EU market; the reporting duty also covers products already on the market.
- Report an actively exploited vulnerability or severe incident: early warning within 24 hours, notification within 72 hours, then a final report.
- Draw up a machine-readable software bill of materials covering at least the top-level dependencies.
- Ship without known exploitable vulnerabilities and fix them through security updates for a support period of at least five years (or the expected use time, if shorter).
- Meet the full essential requirements from 11 December 2027.
Penalty: Up to EUR 15 000 000 or 2.5% of total worldwide annual turnover, whichever is higher, for the essential requirements and Articles 13 and 14 (Art. 64(2)).
What Vulkro provides. Generates CycloneDX and SPDX SBOMs, reachability-backed VEX statements and a CRA readiness bundle from a local scan, and can fail a release on new findings: evidence toward vulnerability handling, not a conformity assessment.
Source: Regulation (EU) 2024/2847 on EUR-LexRead the guide →
- 18 Oct 2024National measures apply (transposition still uneven)
NIS2 Directive Directive (EU) 2022/2555
Medium-sized and larger entities in the sectors of Annexes I and II, including cloud computing and managed service providers, under each Member State's national law.
- Take risk-management measures that include supply chain security and secure development with vulnerability handling.
- Enforce access control and multi-factor authentication where appropriate.
- Report significant incidents: early warning within 24 hours, notification within 72 hours, final report within a month.
- Management bodies approve and oversee the measures and can be held liable.
Penalty: Member States must set maximum fines of at least EUR 10 000 000 or 2% of worldwide turnover for essential entities, and at least EUR 7 000 000 or 1.4% for important entities, whichever is higher (Art. 34).
What Vulkro provides. Finds secure-development flaws in code and audits Salesforce access, MFA, packages and connected apps, then maps the findings to Article 21(2) and Article 23 with the checks behind each control.
- 17 Jan 2025Applies to EU financial entities
Digital Operational Resilience Act Regulation (EU) 2022/2554
Twenty types of EU financial entity, from banks and insurers to investment and payment firms, which stay fully responsible for the ICT services, SaaS included, that they rely on.
- Limit access to what each function needs, use strong authentication and run controlled, recorded change management.
- Manage ICT third-party risk and keep a register of every ICT service arrangement.
- Test regularly, including vulnerability scans and source code reviews where feasible.
- Report major ICT incidents: initial notice within 4 hours of classification and 24 hours of awareness.
Penalty: Administrative penalties for financial entities are set by each Member State (Art. 50); critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover (Art. 35(8)).
What Vulkro provides. Audits a Salesforce org for least privilege, authentication, third-party packages and connected apps, and change, and maps each finding to the DORA article it bears on, marking the articles a scan cannot evidence.
Source: Regulation (EU) 2022/2554 on EUR-LexRead the guide →
- 9 Dec 2026Transposition deadline; applies to products placed on the market after it
Product Liability Directive Directive (EU) 2024/2853
Manufacturers and other economic operators of products, now expressly including software, for damage suffered by natural persons.
- Treat software as a product: defectiveness is judged against safety-relevant cybersecurity requirements.
- Keep shipping updates: no defence where the defect comes from software, an update or a missing update needed to maintain safety, within your control.
- Expect claims for destroyed or corrupted personal data, not only injury and property.
What Vulkro provides. Saved scan history, a per-release SBOM and a release gate give a dated record of what shipped, which findings it carried and what was blocked: evidence of what a manufacturer knew and fixed.
- 2 Dec 2027High-risk requirements apply (Annex III), as amended in 2026
AI Act Regulation (EU) 2024/1689
Providers and deployers of AI systems in the EU; the cybersecurity duties bind high-risk systems, and product-embedded (Annex I) systems follow on 2 August 2028.
- Build high-risk systems to an appropriate level of accuracy, robustness and cybersecurity across their lifecycle.
- Resist attempts to alter a system's use or outputs by exploiting its vulnerabilities, including data poisoning and adversarial inputs.
- Prohibited practices have applied since 2 February 2025; most coding assistants and model API calls are not high-risk systems.
Penalty: Up to EUR 35 000 000 or 7% of worldwide turnover for prohibited practices, and up to EUR 15 000 000 or 3% for other operator obligations, whichever is higher (Art. 99).
What Vulkro provides. Lists the AI SDKs, models and MCP servers in a codebase as an AI bill of materials and maps code findings to the OWASP Top 10 for LLM and Agentic Applications, one input to the cybersecurity part of Article 15.
Source: Regulation (EU) 2024/1689 on EUR-LexRead the guide →
- 25 May 2018Applies: security of processing is the baseline
GDPR, Article 32 Regulation (EU) 2016/679
Every controller and processor of personal data within its reach, which includes most software that stores customer records.
- Implement security appropriate to the risk, including encryption and the ongoing confidentiality, integrity and availability of systems.
- Regularly test, assess and evaluate whether those measures work.
- Notify a personal data breach to the supervisory authority within 72 hours where feasible.
Penalty: Up to EUR 10 000 000 or 2% of worldwide turnover for Article 32 and other controller and processor duties, and up to EUR 20 000 000 or 4% for the basic principles, whichever is higher (Art. 83).
What Vulkro provides. Flags personal-data exposure, missing encryption and access gaps in code and Salesforce orgs on every scan, and writes an Article 30 record of processing for Salesforce data.
This is a plain-language summary of EU law for software teams, not legal advice: check the official text and your counsel before you rely on it.
03What to do now
What to do this week, this month and every quarter
This week
Scan the org and the code
Run Vulkro for Salesforce on your Salesforce project and org, and Vulkro Core on the services around it. Every check is free.
This month
Check every change
Put the check in the editor and the pipeline, so a new weakness never reaches production unnoticed.
Every quarter
Keep the evidence
Vulkro Cloud keeps every scan, every fix and every exception with its approver: the record a regulator or auditor asks for.