Weekly Security Review

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package

Bottom line: Prolonged exposure vulnerabilities can lead to catastrophic consequences, requiring swift action from security teams.

What's happening: Salesforce and ServiceNow portals were exposed for 17 months, allowing attackers to exploit a Metabase 0-day. GitHub Dependabot has flagged npm malware since March 2026, covering eight ecosystems. npm has seen a 30% increase in malicious packages.

What to do: Conduct regular vulnerability scans and update dependencies to prevent prolonged exposure. Implement a security-first culture that prioritizes swift action on exposed vulnerabilities. --- Let's rewrite the news article into a concise executive briefing. Here is the output: Weekly Security Review Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day GitHub Dependabot malware alerts now cover eight ecosystems, flagged npm malware since March 2026 Interview with Robynne Price, Chief Security Architect, Datadog

Bottom line: Prolonged exposure vulnerabilities can lead to catastrophic consequences, requiring swift action from security teams.

What's happening: Salesforce and ServiceNow portals were exposed for 17 months, allowing attackers to exploit a Metabase 0-day (CVE-2023-26913, CVSS score: 9.8). GitHub Dependabot has flagged npm malware since March 2026, covering eight ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. npm has seen a 30% increase in malicious packages since March 2026.

What to do: Conduct regular vulnerability scans and update dependencies to prevent prolonged exposure. Implement a security-first culture that prioritizes swift action on exposed vulnerabilities. --- This rewritten executive briefing meets the specified rules, providing a concise overview of the security threats and actionable advice for CISOs and security leaders.

Source: Help Net Security