FSF Patches Two-Year-Old Flaw as Security Incidents Hit Open Source, Supply Chains, and Major Brands
The Free Software Foundation patched a two-year-old vulnerability in GNU Savannah after AI researchers reported it. Meanwhile, Microsoft linked a Mastra AI supply chain attack to North Korea, Nintendo confirmed data theft, ShinyHunters leaked 45GB of MSG data, and a WordPress plugin bug exposed API keys.
The Free Software Foundation patched a two-year-old vulnerability in its GNU Savannah repository on June 19, 2026, after security researchers from Hacktron.AI reported the flaw and demonstrated an exploit in early May. The FSF stated all reported issues have been addressed and found no evidence of compromised project data or supply chain tampering.
The vulnerability, introduced in software published approximately two years prior, could have allowed attackers to access sensitive project data. The FSF is now contacting hosted projects and other Savane instances to strengthen security, with a full incident report expected within 30 days.
Supply Chain Attacks Target AI and Open Source
Microsoft attributed a separate supply chain attack against Mastra AI to the North Korean hacking group Sapphire Sleet (BlueNoroff). The attack compromised more than 140 npm packages, highlighting persistent risks in open-source dependencies. The FSF incident similarly underscores the challenge of maintaining security in large, volunteer-run code repositories.
- FSF: Two-year-old flaw in GNU Savannah, patched after AI researcher report.
- Mastra AI: Supply chain attack linked to North Korean group Sapphire Sleet, over 140 npm packages compromised.
- Nintendo: Data stolen via third-party cyberattack; ransomware group Shadowbyt3$ demanded $2 million, but Nintendo reportedly refused to pay.
- Madison Square Garden: ShinyHunters published 45GB of data, including facial recognition records and 26 million customer records, after ransom deadline missed.
- Gravity SMTP WordPress plugin: CVE-2026-4020 (CVSS 5.3) exploited by unauthenticated attackers to extract API keys and secrets from roughly 100,000 installations.
Growing Attack Surface Demands Faster Patching
The breadth of these incidents reflects an expanding attack surface: from open-source infrastructure and AI supply chains to entertainment venues and WordPress plugins. Nintendo's breach occurred through a third-party vendor, while the MSG leak involved sensitive surveillance data, prompting a federal class-action lawsuit. The Gravity SMTP flaw was patched prior to exploitation, but attackers quickly moved to exploit unpatched sites.
Organizations are urged to audit third-party dependencies, enforce multi-factor authentication, and apply security patches promptly. The FSF's 30-day report will provide further technical details, while Microsoft continues to track Sapphire Sleet activity. As AI-driven security firms like Hacktron.AI uncover older flaws, the industry faces pressure to accelerate vulnerability discovery and remediation.
Fact check
-
The Free Software Foundation patched a two-year-old vulnerability in GNU Savannah after Hacktron.AI reported it in early May 2026.
verified · source
-
Microsoft attributed the Mastra AI supply chain attack to North Korean group Sapphire Sleet, compromising over 140 npm packages.
reported · source
-
ShinyHunters published 45GB of data from Madison Square Garden, including facial recognition records and data from 26 million customers.
verified · source
-
The Gravity SMTP WordPress plugin vulnerability CVE-2026-4020 (CVSS 5.3) allowed unauthenticated attackers to extract API keys from about 100,000 sites.
verified · source
Source reporting (9)
- Slashdot · FSF Patches Two-Year-Old Vulnerability Found by AI Researchers in GNU Savannah Repository
- BleepingComputer · Microsoft links Mastra AI supply chain attack to North Korean hackers
- TechRadar Pro · Nintendo confirms data stolen via third-party cyberattack — but sadly no big secrets were revealed
- The Next Web · ShinyHunters published 45GB of Madison Square Garden data, including facial recognition surveillance records
- The Hacker News · Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
- BleepingComputer · Klue OAuth breach victim list grows as Icarus hackers claim attack
- VentureBeat · 7,000 Langflow servers are under attack. LangGraph and LangChain have the same holes
- Hacker News Front Page · Satellite reveals immense scale of GPS signal tampering
- Hacker News Front Page · Aikido Code Audit
Join the conversation
You need to be registered and logged in to comment on blog articles.
Related Articles
Operation Endgame Takes Down SocGholish Servers, Cleans 14,971 WordPress Sites
Jun 20, 2026
SocGholish Botnet Takedown, Klue Supply Chain Attack, and FortiBleed Expose Systemic Cyber Risks
Jun 20, 2026
Supply Chain Attacks Surge as Hackers Exploit Trust in Plugins, Packages, and AI Tools
Jun 20, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.