Supply Chain Compromise of Laravel-Lang Localization Packages: Cross-Platform Credential Theft and RCE
A massive supply chain attack has compromised the Laravel-Lang localization ecosystem, injecting malicious payloads into over 700 historical package versions. This breach enables automated credential theft and remote code execution via Composer, posing a critical threat to both developer environments and production infrastructure.
Critical Remote Code Execution RCE in Everest Forms Pro CVE-2026-3300
CVE-2026-3300 is a critical insecure deserialization vulnerability in Everest Forms Pro that enables unauthenticated remote code execution (RCE). The flaw originates from the plugin passing unsanitized user-supplied serialized strings to the PHP unserialize() function, facilitating PHP Object Injection. Attackers can leverage gadget chains to trigger sinks like call_user_func() and file_put_contents(), allowing the deployment of web shells and full server compromise. Immediate patching is required to prevent unauthorized system takeover and subsequent lateral movement within the hosting environment.