MEDIUMVulnerability
Global

Fake Open VSX Extensions Harvest Private Repo and CI Data

·Source: Infosecurity Magazine

Updated:

Executive Summary

77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity

Analysis

77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
Source Attribution

Originally published by Infosecurity Magazine on Aug 5, 2026.

Related Threats

HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-8400 — IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv...

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

CVE-2026-8400
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-39923 — Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability...

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset processing endpoint. The SavePasswordController::handle() method calls PasswordToken::findOrFail() without performing any expiry validation, allowing attackers to bypass the 24-hour token lifetime enfo

CVE-2026-39923
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-16442 — A flaw was found in the SAML broker component of Keycloak, which is used to mana...

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user ac

CVE-2026-16442
NIST NVD