8 Top SAST Tools for Polyglot Monorepos and Platform Engineering in 2026
2026-06-27T08:51:45Z•5be53fdd53cbd82fac18f2812049f9d35fa598e974bf9b10d38a25f869dcf23b
AmadeyChrome-passwordsCrowdStrikeGhostShellKandjiMisticOperation EndgamePostCSSRATSocGholish','law-enforcement-disruption'StealCUkraineWoodgnatXPCaccess-brokercredential-theftdrone-defenceendpoint-securitymacOSmalwarenpmpatchransomwaresupply-chainvulnerability
What happened
Feed of cybersecurity news (26 Jun 2026) highlighting multiple active malware campaigns, supply-chain and endpoint security issues, and law-enforcement disruption actions. Key incidents: Woodgnat operators deploying the stealthy Mistic RAT to broker access for ransomware groups; a macOS XPC vulnerability that allowed standard users to disable CrowdStrike and Kandji agents (vendor patches issued after XM Cyber disclosure); malicious fake npm packages impersonating PostCSS that drop a Windows RAT and steal Chrome passwords; GhostShell targeting Ukraine’s drone-defence sector with credential-thef
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 5be53fdd53cbd82fac18f2812049f9d35fa598e974bf9b10d38a25f869dcf23b
- Enrichment time
- 2026-06-27T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.