Saturday I already wrote about 415 Windows patches and another NetScaler door.[9] The rest of the weekend did not wait for that pile.

The AI supply-chain story people keep repeating is a 40-minute PyPI window. The new row-level numbers say 95 percent of the organizations were already in the dataset before that window opened.[1][2]

The 40 minutes were the closing act

SOCRadar went back through the LiteLLM / Trivy mess and reconstructed 2,188 organizations with timestamps. Collection stops before March 24 for 2,085 of them. That is 95 percent. The earliest record is March 19 at 18:05 UTC, which lines up with the malicious Trivy build, not the PyPI hour everyone screenshot.[1][2]

They are careful about the word victim. This is reconstructed exposure from captured CI files, not a confirmed breach census. The headline is still “2,500+.” The record-level set is 2,188 organizations and about 434,000 CI/CD files. Six platforms show up: GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite.[1]

The payload was a .pth file. Python runs those at interpreter start, so nobody had to import LiteLLM. An unpinned transitive pull through DSPy, MLflow, CrewAI, OpenHands, or Arize Phoenix was enough. Official LiteLLM Docker and LiteLLM Cloud were not on that path.[1]

I am not going to pretend I know whether your runners pulled Trivy 0.69.4 or a poisoned LiteLLM 1.82.7. I am going to pretend you can still rotate the secrets those runners could see. Uninstalling the package does not revoke an AWS key. Hunt for repos named tpcp-docs or docs-tpcp. The stolen set is already being brokered.[1]

The ecosystem hole is CVE-2026-33634. CISA put it in KEV on March 26. What changed this weekend is the timeline, not a new CVE.[1]

Port 5900 is not a hobby

Apple shipped an out-of-band macOS fix on August 6 for CVE-2026-65400 in Screen Sharing. The impact line is plain: an attacker on the network may authenticate without valid credentials. Fixed in Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.[4]

On August 12 the Dutch NCSC updated the advisory. They had a report of active abuse on multiple systems where port 5900 was reachable from the internet. In those cases the attacker got root and dropped a Monero miner. A public proof of concept is out.[3][6]

Calif’s write-up is the one I keep sending. Naming an account is the one thing the bug needs. A username is not a secret. macOS prints them on the login window. screensharingd runs as root, so this is not “they got the help-desk account."[5]

One researcher’s last scan found about 40,000 internet-facing Screen Sharing hosts. Treat that as a scan, not a census. A lot of residential addresses, some universities, some shops that left a Mac mini in a closet and never thought about it again.[5]

If Screen Sharing is on and 5900 answers from the internet, that is this morning. Not a ticket for Thursday.

Three days on a CVSS 10 storefront

SAP patched CVE-2026-58231 on August 11. Commerce Cloud, Data Hub Adapter, CVSS 10. Unauthenticated. Abuse a default authentication client, send crafted input, get code execution on internal components. The affected line they list is COM_CLOUD 2211 and 2211-JDK21.[7][8]

Defused and KEVIntel saw exploitation attempts on August 14. No public proof of concept that day. One showed up August 15. CISA has not put this CVE in KEV yet. They already have an older Commerce Cloud hole from 2019.[7][8]

I do not know how many live storefronts are still sitting on the August 11 build. I know three days is the current gap between “we shipped a 10” and “honeypots lit up.” If you run Commerce Cloud on the internet, check the note, then check the version. Do not wait for the KEV mail.

What I am doing this morning

  1. Ask CI whether Trivy, LiteLLM, DSPy, CrewAI, MLflow, OpenHands, or Phoenix ever ran unpinned between March 19 and March 24. If the answer is “maybe,” rotate the runner secrets. Taking the package out is hygiene. Rotation is the actual containment.[1]
  2. Inventory Macs with Screen Sharing on. Patch to 26.6.1 / 15.7.9 / 14.8.9. If 5900 answers from the internet, pull it now.[3][4]
  3. Confirm SAP Commerce Cloud Data Hub Adapter is past the August 11 patch. If you cannot find the adapter, say that in the ticket instead of marking it N/A.[7]

The Windows pile and the NetScaler door from Saturday are still the other half of this week.[9] I am not rewriting that post. The weekend added a scanner a lot of pipelines trust, a Mac port people forget, and a storefront that did not get three quiet days.


Sources

[1] https://socradar.io/blog/litellm-supply-chain-attack — SOCRadar LiteLLM/Trivy supply chain [2] https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise — SecurityWeek Trivy not LiteLLM [3] https://advisories.ncsc.nl/2026/ncsc-2026-0280.html — NCSC-2026-0280 macOS Screen Sharing [4] https://support.apple.com/en-us/148170 — Apple macOS Tahoe 26.6.1 Screen Sharing [5] https://blog.calif.io/p/no-country-for-old-passwords — Calif CVE-2026-65400 [6] https://www.securityweek.com/recent-macos-screen-sharing-vulnerability-exploited-in-attacks — SecurityWeek macOS Screen Sharing exploited [7] https://kevintel.com/CVE-2026-58231 — KEVIntel CVE-2026-58231 [8] https://www.securityweek.com/critical-sap-commerce-cloud-vulnerability-exploited-3-days-after-disclosure — SecurityWeek SAP Commerce Cloud exploited [9] https://blog.darkpixeltech.com/posts/weekend-wrap-415-patches-and-another-netscaler — DPT Aug 15 weekend wrap

Drafted at the Dark Pixel Tech desk.