CISA warns of supply chain attacks on TanStack, Daemon Tools, and Nx Console (heise.de)
0xBASE INTEL BRIEF
- CISA warns of three supply chain attacks with critical CVEs (CVSS 9.8).
- Daemon Tools Lite: infected installers distributed April–May 2026.
- TanStack: 42 packages compromised in 20 minutes; credentials should be renewed.
- Nx Console: version 18.95.0 affected; postmortem published.
- US federal agencies must patch by May 30, 2026.
"The US CISA issued a warning about three supply chain attacks distributing malware via TanStack, Daemon Tools Lite, and Nx Console. All have critical CVSS 9.8 scores. US federal agencies must patch by May 30."
no comments yet.