Bart
1.7K posts

Bart
@bartblaze
Threat Intel and more. Opinions are my own, unless retweeted. Open DMs.


















Critical Security Vulnerability in React Server Components CVE-2025-55182 and rated CVSS 10.0 The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack react.dev/blog/2025/12/0…










We used to fight worms on the OS level. Slammer, Blaster, Conficker.. all that stuff
Now we get the same behaviour one layer up - inside the software ecosystems we trust every day
NPM tokens, transitive deps, weak account hygiene, zero visibility… and suddenly a self-propagating worm runs through the supply chain like it’s 2003 again
This incident shows the real blind spot: package ecosystems aren’t


🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast. Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation. Details: wiz.io/blog/shai-hulu…


