Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/Trending Threats
Trending Threats

What's dangerous right now

The newest confirmed exploited-in-the-wild vulnerabilities (CISA KEV), ransomware-linked CVEs, and the latest malicious open-source package incidents.

Newly added to CISA KEV

CVE-2026-85046Google Chromium V82026-09-04CVE-2026-59822BerriAI LiteLLM2026-09-02CVE-2026-48710Kludex Starlette2026-09-02CVE-2026-49869Kestra Kestra OSS2026-09-02CVE-2026-82329JFrog Artifactory2026-09-02CVE-2026-9586Sangoma Switchvox2026-09-02CVE-2026-83548SonicWall SMA1000 Appliances2026-09-02CVE-2026-83549SonicWall SMA1000 Appliances2026-09-02CVE-2026-82078PaperCut NG/MF2026-08-31CVE-2026-81578PaperCut NG/MF2026-08-31
All 1,695 actively-exploited CVEs

Latest supply-chain attacks

@solana/web3.jscompromise · 2024polyfill.io (polyfill-service)compromise · 2024xz / liblzmabackdoor · 2024@ledgerhq/connect-kitcompromise · 2023PyTorch / discordpydebug & similarmalicious · 2023web3-essential / crypto typosquatstyposquat · 2023colors / fakerprotestware · 2022ctxcompromise · 2022node-ipcprotestware · 2022torchtriton (pytorch-nightly)dependency-confusion · 2022
All malicious packages

Ransomware-linked

CVE-2026-15409CVE-2026-15410CVE-2026-45659CVE-2026-12569CVE-2026-35273CVE-2026-50751CVE-2026-0257CVE-2026-48027CVE-2026-45321CVE-2026-41940

Get alerted the moment a threat hits your stack

Don’t watch a feed — let Safeguard match new exploited CVEs and malicious packages against your actual dependencies and tell you if you’re affected.

Monitor my stack free See pricing

Sources: CISA Known Exploited Vulnerabilities catalog and Safeguard's curated malicious-package index. See Credits & Data Sources.