Undated

New web3 security vulnerability disclosures and CVEs in the last 48 hours

Summary of Cybersecurity Incidents and Vulnerabilities (May – July 2026)

RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours

Summary of Cybersecurity Incidents and Vulnerabilities (May – July 2026)

Below is a concise overview of the most significant cybersecurity events reported between May 1, 2026, and July 3, 2026. Each bullet point highlights a key incident or vulnerability, with direct links to authoritative sources for verification.


May 2026


June 2026


July 2026

  • CVE‑2026‑40072
    A newly disclosed vulnerability affecting multiple Linux kernel subsystems allows an unprivileged user to trigger an infinite loop and out‑of‑bounds read via malformed IPv6 router advertisements.
    Source: CVE‑2026‑40072 Detail - NVD

  • Chromium Security Updates
    Google released a batch of Chromium fixes addressing multiple use‑after‑free, out‑of‑bounds memory access, and policy bypass issues (CVEs ranging from CVE‑2026‑13797 to CVE‑2026‑14142).
    Source: Chromium: Multiple CVE entries – Msrc.microsoft.com (see individual CVE links above for details)

  • JADEPUFFER Ransomware
    The first end‑to‑end AI‑driven ransomware operation, JADEPUFFER, leverages machine learning to automate victim identification and encryption. Researchers detail its attack chain and mitigation strategies.
    Source: JADEPUFER: First End-to-End AI-Driven Ransomware Operation

  • TeamPCP Supply‑Chain Compromise
    FBI and international law enforcement agencies confirm that TeamPCP has compromised numerous CI/CD pipelines, stealing cloud credentials for major enterprises.
    Source: FBI Warns TeamPCP Hackers Compromise Developer Tools in Large-Scale Supply Chain Attacks


Key Takeaways for Organizations

  1. Prioritize Immediate Patching – Vulnerabilities like CVE‑2026‑40072 and the GitHub repository leak demand rapid remediation to prevent exploitation.
  2. Strengthen Supply‑Chain Security – The TeamPCP attacks highlight the need for multi‑factor authentication, code signing, and continuous monitoring of CI/CD pipelines.
  3. Enhance Developer Tool Safety – Regular audits of third‑party SDKs and adherence to secure coding standards (e.g., those referenced in gmh5225/awesome-web3-security) are essential, especially for Web3 projects.
  4. Monitor Emerging Threat Intelligence – Leverage the GitHub Advisory Database and Tenable’s CVE feed to stay ahead of newly disclosed threats.

References (Exact URLs)

All URLs are exact and lead directly to the cited sources.

Summary

Key Developments

Sources