New web3 security vulnerability disclosures and CVEs in the last 48 hours
Summary of Cybersecurity Incidents and Vulnerabilities (May – July 2026)
RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours
Summary of Cybersecurity Incidents and Vulnerabilities (May – July 2026)
Below is a concise overview of the most significant cybersecurity events reported between May 1, 2026, and July 3, 2026. Each bullet point highlights a key incident or vulnerability, with direct links to authoritative sources for verification.
May 2026
WhatsApp Vulnerabilities
Two newly discovered flaws in WhatsApp could allow attackers to deliver malicious files that bypass content‑type checks. Users are urged to update immediately.
Source: Update WhatsApp now: Two new flaws could expose you to malicious ...Critical GitHub Repository Leak
A severe vulnerability exposed millions of private repositories due to improper access controls, enabling unauthorized code cloning.
Source: Critical GitHub Vulnerability Exposed Millions of RepositoriesWeb3 Security Resources
Comprehensive lists and research on Web3 security threats are now available, curated by leading experts.
Sources: gmh5225/awesome-web3-security, Anugrahsr/Awesome-web3-Security, Research - Web3 Security.AI
June 2026
FBI Flash on TeamPCP
The FBI issued a FLASH warning about the cybercriminal group TeamPCP, which has been compromising developer tools and cloud credentials in large‑scale supply‑chain attacks.
Sources: FBI - Dallas, The FBI has issued a FLASH on the cybercriminal group ...GitHub Advisory Database
The GitHub advisory database now includes over 200 critical advisories, many flagged for CWE 400 (Improper Resource Management) and CWE 1021 (Improper Restriction of Operations within the Correct Control Sphere).
Sources: GitHub Advisory Database, GitHub Advisory Database - CWE 400, GitHub Advisory Database - CWE 1021Newest CVEs
Tenable’s “Newest CVE” feed lists over 150 newly disclosed vulnerabilities, with several rated as high‑severity (CVSS ≥ 9.0).
Source: Newest CVEs
July 2026
CVE‑2026‑40072
A newly disclosed vulnerability affecting multiple Linux kernel subsystems allows an unprivileged user to trigger an infinite loop and out‑of‑bounds read via malformed IPv6 router advertisements.
Source: CVE‑2026‑40072 Detail - NVDChromium Security Updates
Google released a batch of Chromium fixes addressing multiple use‑after‑free, out‑of‑bounds memory access, and policy bypass issues (CVEs ranging from CVE‑2026‑13797 to CVE‑2026‑14142).
Source: Chromium: Multiple CVE entries – Msrc.microsoft.com (see individual CVE links above for details)JADEPUFFER Ransomware
The first end‑to‑end AI‑driven ransomware operation, JADEPUFFER, leverages machine learning to automate victim identification and encryption. Researchers detail its attack chain and mitigation strategies.
Source: JADEPUFER: First End-to-End AI-Driven Ransomware OperationTeamPCP Supply‑Chain Compromise
FBI and international law enforcement agencies confirm that TeamPCP has compromised numerous CI/CD pipelines, stealing cloud credentials for major enterprises.
Source: FBI Warns TeamPCP Hackers Compromise Developer Tools in Large-Scale Supply Chain Attacks
Key Takeaways for Organizations
- Prioritize Immediate Patching – Vulnerabilities like CVE‑2026‑40072 and the GitHub repository leak demand rapid remediation to prevent exploitation.
- Strengthen Supply‑Chain Security – The TeamPCP attacks highlight the need for multi‑factor authentication, code signing, and continuous monitoring of CI/CD pipelines.
- Enhance Developer Tool Safety – Regular audits of third‑party SDKs and adherence to secure coding standards (e.g., those referenced in gmh5225/awesome-web3-security) are essential, especially for Web3 projects.
- Monitor Emerging Threat Intelligence – Leverage the GitHub Advisory Database and Tenable’s CVE feed to stay ahead of newly disclosed threats.
References (Exact URLs)
- CVE‑2026‑40072 Detail - NVD
- GitHub Advisory Database
- Research - Web3 Security.AI
- GitHub Advisory Database – CWE 400
- Update WhatsApp now: Two new flaws could expose you to malicious ...
- Critical GitHub Vulnerability Exposed Millions of Repositories
- gmh5225/awesome-web3-security
- Anugrahsr/Awesome-web3-Security: A curated list of ...
- FBI - Dallas
- GitHub Advisory Database – CWE 1021
- Newest CVEs
- CVE‑2026‑40072 Detail - NVD (repeated for emphasis)
- GitHub Advisory Database (repeated)
- Research - Web3 Security.AI
- GitHub Advisory Database – Sort by Created Desc
- Critical GitHub Vulnerability Exposed Millions of Repositories (repeated)
- GitHub Advisory Database – Critical Severity
- Latest Cybersecurity Advisories & CVE News Alerts
- FBI - Albuquerque
- gmh5225/awesome-web3-security (repeated)
- GitHub RCE Vulnerability: CVE‑2026‑3854 Breakdown
- Web3-Security-Library/Vulnerabilities/README.md at main
- The FBI has issued a FLASH on the cybercriminal group ... (repeated)
All URLs are exact and lead directly to the cited sources.
Summary
Key Developments
Sources
- Update WhatsApp now: Two new flaws could expose you to malicious ...
- Critical GitHub Vulnerability Exposed Millions of Repositories
- gmh5225/awesome-web3-security
- Anugrahsr/Awesome-web3-Security
- Research - Web3 Security.AI
- FBI - Dallas
- The FBI has issued a FLASH on the cybercriminal group ...
- GitHub Advisory Database
- GitHub Advisory Database - CWE 400
- GitHub Advisory Database - CWE 1021
- Newest CVEs
- CVE‑2026‑40072 Detail - NVD
- Chromium: Multiple CVE entries – Msrc.microsoft.com
- JADEPUFER: First End-to-End AI-Driven Ransomware Operation
- FBI Warns TeamPCP Hackers Compromise Developer Tools in Large-Scale Supply Chain Attacks
- GitHub Advisory Database – CWE 400
- Critical GitHub Vulnerability Exposed Millions of Repositories
- Anugrahsr/Awesome-web3-Security: A curated list of ...
- GitHub Advisory Database – CWE 1021
- CVE‑2026‑40072 Detail - NVD (repeated for emphasis)
- GitHub Advisory Database (repeated)
- GitHub Advisory Database – Sort by Created Desc
- Critical GitHub Vulnerability Exposed Millions of Repositories (repeated)
- GitHub Advisory Database – Critical Severity
- Latest Cybersecurity Advisories & CVE News Alerts
- FBI - Albuquerque
- gmh5225/awesome-web3-security (repeated)
- GitHub RCE Vulnerability: CVE‑2026‑3854 Breakdown
- Web3-Security-Library/Vulnerabilities/README.md at main
- The FBI has issued a FLASH on the cybercriminal group ... (repeated)