Skip to main content

Why now

Recent attacks and the EU laws that now apply

Attackers are exploiting common weaknesses in ordinary code and configuration, and EU law now expects you to find them first and prove it. Here is each recent attack, the check in Vulkro that flags its root cause, and the regulation that makes it your problem.

22 recent attacks · 6 EU laws · every one sourced

01Recent attacks

Every one of these started with a weakness Vulkro checks for.

Not exotic zero-days. Over-trusted integrations, missing authorization checks, secrets in code, poisoned packages and exposed agent tools. Each card names the root cause and the check that flags it.

  1. Sep 2026Vulkro for SalesforceFree

    Agentforce turned a public lead form into a data leak

    Researchers disclosed SalesBleed: hidden instructions submitted through a public Web-to-Lead form could make an Agentforce agent query account data and send it out through a DNS technique that bypassed the Trusted URLs redaction. Salesforce deployed a fix for the redaction bypass on 18 August 2026, before public disclosure on 24 September.

    Root cause
    An agent that reads free text anyone can submit, with read access to more records than the task needs and an output path that can carry data out in a URL.
    Vulkro flags
    Vulkro for Salesforce flags prompt templates that bind a publicly writable field such as a Web-to-Lead description, prompt templates that emit untrusted URLs, and the complete chain when an exit channel exists.

    sf-forcedleak-writable-field-in-promptsf-forcedleak-untrusted-url-in-promptsf-forcedleak-exfil-chain

  2. Aug 2026Vulkro CoreFree

    A new npm worm spread through keyv and related packages

    Singapore's Cyber Security Agency warned of a new Shai-Hulud wave that compromised keyv and related packages, more than 1,300 package versions in all. The malware steals cloud credentials, GitHub tokens, SSH keys and Kubernetes configurations, and spreads by compromising further packages.

    Root cause
    Install-time code that downloads and runs a second stage, reads credentials, and uses a stolen publish token to republish itself.
    Vulkro flags
    Vulkro flags install code that fetches and runs a remote payload, reads credential files, sends credentials out, and pairs a publish token with npm publish.

    MAL-LOADER-001MAL-CRED-001MAL-EXFIL-001MAL-WORM-001

  3. Jun 2026Vulkro for SalesforcePro

    Stolen integration tokens used to read Salesforce data

    An attacker used a long-disused but still active credential at Klue to push code that collected the OAuth tokens customers had granted its app, then ran bulk queries against customer Salesforce data through the REST API. Salesforce disabled the Klue integration on 11 June 2026 and said the issue did not arise from a vulnerability in the Salesforce platform.

    Root cause
    A third-party app holding long-lived OAuth tokens with broad access to the org, usable from any network.
    Vulkro flags
    Vulkro for Salesforce flags broad-scope OAuth apps with no IP restriction, refresh tokens that never expire or rotate, and dormant tokens that still work (live-org checks, part of Pro).

    SF-OAUTH-APP-002SF-OAUTH-APP-004SF-OAUTH-TOKEN-001

  4. May 2026Vulkro CoreFree

    TanStack packages published with malware from its own CI

    On 11 May 2026 an attacker published 84 malicious versions across 42 @tanstack/* npm packages under the project's trusted-publisher identity, by chaining a pull_request_target workflow, a GitHub Actions cache shared with fork runs, and an OIDC token read from runner memory. The payload stole cloud, GitHub, npm and SSH credentials.

    Root cause
    A pull_request_target workflow that ran untrusted pull request code with the base repository's trust, including a cache the release job later used.
    Vulkro flags
    Vulkro flags workflows that check out untrusted pull request code under pull_request_target, and flags the malicious @tanstack versions in your lockfile as known-malicious.

    SUPPLY-CI-002CVE-2026-45321 (GHSA-g7cv-rxg3-hmpx)MAL-2026-3465 (known-malicious package)

  5. May 2026Vulkro CoreFree

    SQL injection in an AI gateway exploited in the wild

    CVE-2026-42208 let an unauthenticated attacker send a crafted Authorization header to any LiteLLM proxy model route and reach a key-check query that mixed the caller's value into the query text. CISA added it to its Known Exploited Vulnerabilities catalog on 8 May 2026.

    Root cause
    Request data, here an API key taken from a header, placed into SQL text instead of being passed as a bound parameter.
    Vulkro flags
    Vulkro traces request data into SQL calls and flags queries built from it, and flags the vulnerable litellm version as Critical with a CISA KEV tag.

    tainted-source-detected (SQL injection)CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)CISA KEV tag

  6. Apr 2026Vulkro CoreFree

    An unauthenticated MCP endpoint handed over web servers

    CVE-2026-33032, rated CVSS 9.8, left the /mcp_message endpoint of nginx-ui's MCP integration without authentication, so anyone who could reach it could invoke tools that create, modify or delete nginx configuration and restart the server. BleepingComputer reported in April 2026 that the flaw was under active exploitation, with about 2,600 instances exposed.

    Root cause
    A route that performs privileged actions registered without the authentication its sibling route enforces.
    Vulkro flags
    Vulkro flags state-changing routes that are registered with no authentication.

    no-auth-middleware-detected

  7. Mar 2026Vulkro for SalesforceFree

    Public Salesforce sites mass-scanned for guest data

    Salesforce warned that threat actors were mass-scanning public Experience Cloud sites with a modified auditing tool that could extract data, and said the activity related to a customer-configured guest user setting, not a platform flaw.

    Root cause
    Guest user profiles and guest-callable Apex that can read records and fields an anonymous visitor should never see.
    Vulkro flags
    Vulkro for Salesforce flags guest-reachable Aura methods that return records without field security or perform privileged actions, and guest access to sensitive fields.

    sf-guest-aura-read-no-flssf-guest-aura-class-grantsf-guest-meta-sensitive-field-read

  8. Mar 2026Vulkro CoreFree

    An axios release on npm pulled in a remote access trojan

    CISA reported that axios 1.14.1, published to npm on 31 March 2026, pulled in a malicious dependency, plain-crypto-js, which downloads multi-stage payloads including a remote access trojan. It told users to downgrade, delete the dependency and rotate repository, CI, cloud, npm and SSH credentials.

    Root cause
    A trusted dependency version that adds a new package whose install-time code fetches and runs a remote payload.
    Vulkro flags
    Vulkro flags the malicious axios and plain-crypto-js versions in your lockfile as known-malicious, and flags install code that fetches and runs a remote payload.

    MAL-2026-2307 (axios 1.14.1)MAL-2026-2306 (plain-crypto-js 4.2.1)MAL-LOADER-001

  9. Mar 2026Vulkro CoreFree

    A popular CI action's tags rewritten to steal secrets

    On 19 March 2026 an attacker with compromised credentials force-pushed 76 of 77 version tags of the trivy-action GitHub Action, and every tag of setup-trivy, to commits that stole CI secrets before running the normal scan. CISA added CVE-2026-33634 to its Known Exploited Vulnerabilities catalog, and the advisory tells users to pin actions to full commit SHAs.

    Root cause
    Workflows that use a third-party action by a mutable tag, so whoever controls the tag decides what runs next to the job's secrets.
    Vulkro flags
    Vulkro flags workflow steps that use a third-party action by a tag or branch instead of a commit SHA, and flags secrets passed to such an action.

    SUPPLY-CI-003SUPPLY-CI-006

  10. Feb 2026Vulkro CoreFree

    React Native development servers exploited

    Attackers exploited CVE-2025-11953, rated CVSS 9.8, in the Metro development server of the @react-native-community/cli npm package, which lets remote unauthenticated attackers run operating system commands, and used it to deliver malware. CISA added it to its Known Exploited Vulnerabilities catalog on 5 February 2026.

    Root cause
    A vulnerable version of a development tool in the dependency tree, running a server that the network can reach.
    Vulkro flags
    Vulkro flags the vulnerable @react-native-community/cli version in your lockfile as Critical and tags it as actively exploited from the CISA KEV list.

    CVE-2025-11953 (GHSA-399j-vxmf-hjvr)CISA KEV tag

  11. Jan 2026Vulkro CoreFree

    Exposed Vite dev servers returned files they should not

    CISA added CVE-2025-31125 to its Known Exploited Vulnerabilities catalog on 22 January 2026, based on evidence of active exploitation. The Vite flaw lets crafted import query strings return the contents of arbitrary files through the dev server; fixed versions shipped in March 2025.

    Root cause
    A vulnerable version of a build tool whose development server is reachable from outside the machine.
    Vulkro flags
    Vulkro flags the vulnerable vite version in your lockfile as Critical and tags it as actively exploited from the CISA KEV list.

    CVE-2025-31125CISA KEV tag

  12. Dec 2025Vulkro CoreFree

    React Server Components remote code execution

    React disclosed CVE-2025-55182, an unauthenticated remote code execution flaw in React Server Components rated CVSS 10.0. CISA added it to its Known Exploited Vulnerabilities catalog two days later, based on evidence of active exploitation.

    Root cause
    A vulnerable version of react-server-dom-webpack, -parcel or -turbopack in the dependency tree of an app that exposes Server Function endpoints.
    Vulkro flags
    Vulkro flags the vulnerable package version in your lockfile as Critical and tags it as actively exploited from the CISA KEV list.

    CVE-2025-55182 (GHSA-fv66-9v8q-g76r)CISA KEV tag

  13. Sep 2025Vulkro for SalesforceFree

    Agentforce prompt injection through a Web-to-Lead field

    Researchers disclosed ForcedLeak: instructions planted in a Web-to-Lead description were later followed by Agentforce and could send CRM data to a domain that sat on an allowlist after it had expired. Salesforce began enforcing Trusted URLs for Agentforce on 8 September 2025.

    Root cause
    A prompt template that grounds on a free-text field the public can write, plus an exit channel the agent can use without anyone approving it.
    Vulkro flags
    Vulkro for Salesforce flags prompt templates that bind a publicly writable field, prompt templates that emit untrusted URLs, and the complete chain when an exit channel exists.

    sf-forcedleak-writable-field-in-promptsf-forcedleak-untrusted-url-in-promptsf-forcedleak-exfil-chaincsptrustedsite-wildcard

  14. Sep 2025Vulkro CoreFree

    A fake MCP server copied every email it sent

    An npm package impersonating Postmark built trust over 15 versions, then added a backdoor in version 1.0.16 that blind-copied every email sent through it to an external address. Postmark said it had no involvement with the package.

    Root cause
    An MCP server launched by package name with no version pin, so the host pulls whatever the publisher ships next.
    Vulkro flags
    Vulkro flags MCP servers launched without a pinned version and flags postmark-mcp 1.0.16 as a known-malicious package.

    MCP-001AGENT-005MAL-2025-47604 (known-malicious package)

  15. Sep 2025Vulkro CoreFree

    A self-replicating worm spread through npm

    The Shai-Hulud worm entered npm through compromised maintainer accounts and malicious post-install scripts, harvested tokens and cloud keys, and republished itself into other packages. GitHub removed more than 500 compromised packages.

    Root cause
    Install-time scripts that read credentials and send them out, run with publish tokens that let the code republish itself.
    Vulkro flags
    Vulkro flags code that reads credentials next to a network call, code that pairs a publish token with npm publish or a workflow write, risky install scripts, and the compromised versions themselves.

    MAL-EXFIL-001MAL-WORM-001MAL-PKG-001SUPPLY-CI-001known-malicious package (OSV MAL advisory)

  16. Sep 2025Vulkro CoreFree

    debug, chalk and other npm packages hijacked after phishing

    The npm publishing account behind debug was taken over after a phishing attack, and malicious versions of debug, chalk and other packages were published. The advisory describes a browser payload that tried to redirect cryptocurrency transactions; npm removed the debug version on 8 September 2025.

    Root cause
    A browser payload that wraps fetch and wallet APIs to rewrite crypto addresses, shipped inside a trusted dependency version.
    Vulkro flags
    Vulkro flags the hijacked versions in your lockfile as known-malicious and flags code that overrides network primitives to rewrite crypto addresses.

    MAL-2025-46969 (chalk 5.6.1)MAL-2025-46974 (debug 4.4.2)MAL-WALLET-003

  17. Aug 2025Vulkro CoreFree

    Nx build tool published with a credential stealer

    A GitHub Actions workflow that printed pull request titles unsanitised let an attacker steal the Nx npm token and publish malicious versions. Their post-install script hunted for secrets, reportedly by driving local AI coding CLIs with their permission prompts turned off.

    Root cause
    Untrusted pull request text expanded into a shell under pull_request_target, and an install script that runs AI coding agents with guardrails disabled.
    Vulkro flags
    Vulkro flags workflow expressions that inject event text into a shell, AI agent CLIs launched with permission-bypass flags, and the malicious Nx versions.

    CICD-001AGENT-AUTONOMY-001GHSA-cxm3-wv7p-598c (known-malicious package)

  18. Jul 2025Vulkro CoreFree

    Job-applicant records reachable by changing one number

    Researchers reported that a hiring platform used by McDonald's exposed applicant records through a default admin login and an API that returned any applicant by a sequential id, with up to 64 million records reachable. The vendor said only the researchers accessed applicant data, and the issue was closed within a day of disclosure.

    Root cause
    An API handler that loads a record by a caller-supplied id without checking that the caller may see it.
    Vulkro flags
    Vulkro flags handlers that look up a record by a caller-supplied id with no ownership or tenant check.

    idor-authn-no-ownershipAUTHZ-001

  19. May 2025Vulkro CoreFree

    Generated web apps shipped databases readable by anyone

    CVE-2025-48757 describes sites generated by an AI app builder whose Supabase tables could be read or written by unauthenticated users because Row Level Security was missing or insufficient. The platform supplier disputes the CVE, saying each customer is responsible for protecting their own data.

    Root cause
    Browser code querying database tables directly with a public key while no Row Level Security policy restricts what that key can read.
    Vulkro flags
    Vulkro flags client code that reaches Supabase tables with no Row Level Security evidence in the repo, service-role keys in browser code, and wide-open Firebase rules.

    SUPA-RLS-003SUPA-RLS-002SUPA-RLS-001

  20. Mar 2025Vulkro CoreFree

    AI assistants invent package names attackers can register

    A USENIX Security 2025 study of 576,000 generated code samples found that models recommend packages that do not exist: 5.2% on average for commercial models and 21.7% for open-source ones, with 205,474 unique invented names.

    Root cause
    A dependency list written by an assistant and installed without checking that each name is real and the one intended.
    Vulkro flags
    Vulkro flags documented hallucinated names, typosquats of popular packages and decoy suffixes before you install them.

    slopcheck: hallucinatedslopcheck: typosquat-ofpackage-risk: slopsquat

  21. Oct 2024Vulkro CoreFree

    Credentials stolen from exposed Git and .env files

    Researchers reported a campaign that scanned the internet for exposed .git/config and Laravel .env files and collected more than 15,000 cloud credentials, then used them to clone private repositories and hunt for more secrets.

    Root cause
    Live credentials written into configuration files and repositories, where one exposure hands over everything they unlock.
    Vulkro flags
    Vulkro flags credentials in source and config files, and on Pro, credentials that were committed and later removed from git history.

    literal-string-secretprovider-format-matchgit-history-secrets (Pro)

  22. Mar 2024Vulkro CoreFree

    CISA and the FBI: SQL injection is still shipping

    CISA and the FBI issued a Secure by Design alert after a widely exploited SQL injection in a managed file transfer product, saying software manufacturers continue to ship the defect and urging parameterized queries.

    Root cause
    Request data concatenated into a SQL string instead of being passed as a bound parameter.
    Vulkro flags
    Vulkro traces request data into SQL calls and flags the ones that build the query by concatenation, in application code and in Apex.

    js-taint-sql-001GO-SQLI-001apex-taint-soql-injection

What no scanner does: stop an employee from approving a malicious app on a phone call. What Vulkro does is shrink what that approval can reach: the over-privileged users, the integrations with org-wide access and the code that hands out data.

02EU law

EU law now requires security evidence, with set dates

The Cyber Resilience Act, NIS2, DORA, the new Product Liability Directive and the AI Act move software security from good practice to duty. Vulkro produces the evidence these laws ask for, continuously.

  1. 11 Sep 2026Vulnerability and incident reporting applies

    Cyber Resilience Act Regulation (EU) 2024/2847

    Manufacturers of products with digital elements, software included, made available on the EU market; the reporting duty also covers products already on the market.

    • Report an actively exploited vulnerability or severe incident: early warning within 24 hours, notification within 72 hours, then a final report.
    • Draw up a machine-readable software bill of materials covering at least the top-level dependencies.
    • Ship without known exploitable vulnerabilities and fix them through security updates for a support period of at least five years (or the expected use time, if shorter).
    • Meet the full essential requirements from 11 December 2027.

    Penalty: Up to EUR 15 000 000 or 2.5% of total worldwide annual turnover, whichever is higher, for the essential requirements and Articles 13 and 14 (Art. 64(2)).

    What Vulkro provides. Generates CycloneDX and SPDX SBOMs, reachability-backed VEX statements and a CRA readiness bundle from a local scan, and can fail a release on new findings: evidence toward vulnerability handling, not a conformity assessment.

  2. 18 Oct 2024National measures apply (transposition still uneven)

    NIS2 Directive Directive (EU) 2022/2555

    Medium-sized and larger entities in the sectors of Annexes I and II, including cloud computing and managed service providers, under each Member State's national law.

    • Take risk-management measures that include supply chain security and secure development with vulnerability handling.
    • Enforce access control and multi-factor authentication where appropriate.
    • Report significant incidents: early warning within 24 hours, notification within 72 hours, final report within a month.
    • Management bodies approve and oversee the measures and can be held liable.

    Penalty: Member States must set maximum fines of at least EUR 10 000 000 or 2% of worldwide turnover for essential entities, and at least EUR 7 000 000 or 1.4% for important entities, whichever is higher (Art. 34).

    What Vulkro provides. Finds secure-development flaws in code and audits Salesforce access, MFA, packages and connected apps, then maps the findings to Article 21(2) and Article 23 with the checks behind each control.

  3. 17 Jan 2025Applies to EU financial entities

    Digital Operational Resilience Act Regulation (EU) 2022/2554

    Twenty types of EU financial entity, from banks and insurers to investment and payment firms, which stay fully responsible for the ICT services, SaaS included, that they rely on.

    • Limit access to what each function needs, use strong authentication and run controlled, recorded change management.
    • Manage ICT third-party risk and keep a register of every ICT service arrangement.
    • Test regularly, including vulnerability scans and source code reviews where feasible.
    • Report major ICT incidents: initial notice within 4 hours of classification and 24 hours of awareness.

    Penalty: Administrative penalties for financial entities are set by each Member State (Art. 50); critical ICT third-party providers face periodic penalty payments of up to 1% of average daily worldwide turnover (Art. 35(8)).

    What Vulkro provides. Audits a Salesforce org for least privilege, authentication, third-party packages and connected apps, and change, and maps each finding to the DORA article it bears on, marking the articles a scan cannot evidence.

  4. 9 Dec 2026Transposition deadline; applies to products placed on the market after it

    Product Liability Directive Directive (EU) 2024/2853

    Manufacturers and other economic operators of products, now expressly including software, for damage suffered by natural persons.

    • Treat software as a product: defectiveness is judged against safety-relevant cybersecurity requirements.
    • Keep shipping updates: no defence where the defect comes from software, an update or a missing update needed to maintain safety, within your control.
    • Expect claims for destroyed or corrupted personal data, not only injury and property.

    What Vulkro provides. Saved scan history, a per-release SBOM and a release gate give a dated record of what shipped, which findings it carried and what was blocked: evidence of what a manufacturer knew and fixed.

  5. 2 Dec 2027High-risk requirements apply (Annex III), as amended in 2026

    AI Act Regulation (EU) 2024/1689

    Providers and deployers of AI systems in the EU; the cybersecurity duties bind high-risk systems, and product-embedded (Annex I) systems follow on 2 August 2028.

    • Build high-risk systems to an appropriate level of accuracy, robustness and cybersecurity across their lifecycle.
    • Resist attempts to alter a system's use or outputs by exploiting its vulnerabilities, including data poisoning and adversarial inputs.
    • Prohibited practices have applied since 2 February 2025; most coding assistants and model API calls are not high-risk systems.

    Penalty: Up to EUR 35 000 000 or 7% of worldwide turnover for prohibited practices, and up to EUR 15 000 000 or 3% for other operator obligations, whichever is higher (Art. 99).

    What Vulkro provides. Lists the AI SDKs, models and MCP servers in a codebase as an AI bill of materials and maps code findings to the OWASP Top 10 for LLM and Agentic Applications, one input to the cybersecurity part of Article 15.

  6. 25 May 2018Applies: security of processing is the baseline

    GDPR, Article 32 Regulation (EU) 2016/679

    Every controller and processor of personal data within its reach, which includes most software that stores customer records.

    • Implement security appropriate to the risk, including encryption and the ongoing confidentiality, integrity and availability of systems.
    • Regularly test, assess and evaluate whether those measures work.
    • Notify a personal data breach to the supervisory authority within 72 hours where feasible.

    Penalty: Up to EUR 10 000 000 or 2% of worldwide turnover for Article 32 and other controller and processor duties, and up to EUR 20 000 000 or 4% for the basic principles, whichever is higher (Art. 83).

    What Vulkro provides. Flags personal-data exposure, missing encryption and access gaps in code and Salesforce orgs on every scan, and writes an Article 30 record of processing for Salesforce data.

This is a plain-language summary of EU law for software teams, not legal advice: check the official text and your counsel before you rely on it.

03What to do now

What to do this week, this month and every quarter

  • This week

    Scan the org and the code

    Run Vulkro for Salesforce on your Salesforce project and org, and Vulkro Core on the services around it. Every check is free.

  • This month

    Check every change

    Put the check in the editor and the pipeline, so a new weakness never reaches production unnoticed.

  • Every quarter

    Keep the evidence

    Vulkro Cloud keeps every scan, every fix and every exception with its approver: the record a regulator or auditor asks for.

Find these weaknesses in your code and org.