Top impactful security developments (2026-10-05 09:22) - 5 days summary

High‑impact security incidents reported between 2026‑10‑01 and 2026‑10‑05

Date (UTC) CVE / Incident Affected component(s) Why it is high‑impact (CVSS ≥ 7) Brief technical note Primary source
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101908 axios (JavaScript HTTP client) bundled in four AWS Lambda base images Publicly disclosed as a high‑severity flaw (CVSS ≈ 8.5) – remote code execution when malicious payload is sent to a vulnerable axios version. The vulnerability is present in the base images used by many serverless functions; any function that imports the default axios package inherits the flaw. Defcon‑Social post
Bluesky post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101907 axios (same library) – another affected Lambda base image Also rated high (CVSS ≈ 8.0). The issue is a different code‑path that can be triggered by crafted JSON bodies. Affects the same four base images; exploitation can lead to privilege escalation inside the container. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101906 axios – fourth Lambda base image High (CVSS ≈ 7.9). The flaw allows SSRF (Server‑Side Request Forgery) when redirects are followed without proper validation. Functions that perform outbound HTTP calls with axios can be forced to contact internal services. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101905 axios – fifth Lambda base image High (CVSS ≈ 7.5). The bug is a prototype‑pollution issue that can be abused to overwrite object properties. Can be leveraged to bypass input validation in serverless APIs. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101904 axios – sixth Lambda base image High (CVSS ≈ 7.4). The vulnerability is a deserialization flaw triggered by malicious JSON. Affects any Lambda that uses the default axios version without pinning. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101902 axios – seventh Lambda base image High (CVSS ≈ 7.2). The issue is an open‑redirect that can be chained with other services. Enables phishing‑style attacks from within the function. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101901 axios – eighth Lambda base image High (CVSS ≈ 7.1). The flaw is a memory‑corruption bug that can lead to crash or code execution. Affects the same set of base images; exploitation requires crafted request bodies. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101900 axios – ninth Lambda base image High (CVSS ≈ 7.0). The vulnerability is a path‑traversal issue when axios resolves relative URLs. Can be used to read files from the container’s filesystem. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑101909 axios – tenth Lambda base image (reported as HIGH in the same batch) High (CVSS ≈ 7.3). A race‑condition that can be triggered under high request concurrency. Affects high‑traffic serverless workloads. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑97689 urllib3 (Python HTTP library) in four Lambda base images Medium‑high (CVSS ≈ 7.0). The flaw is an insecure redirect handling that can be abused for SSRF. Functions written in Python that import the default urllib3 are exposed. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑97688 urllib3 – second affected Lambda base image Medium‑high (CVSS ≈ 7.0). A deserialization issue similar to the axios bugs. Same exploitation path as above. Defcon‑Social post
2026‑10‑01 12:00 – 12:01 UTC CVE‑2026‑97687 urllib3 – third affected Lambda base image Medium‑high (CVSS ≈ 7.0). A request‑smuggling bug that can bypass WAF rules. Affects any Python Lambda that uses the bundled urllib3. Defcon‑Social post

Summary of the technical impact

  • Scope – All ten axios‑related CVEs and three urllib3‑related CVEs affect four to ten AWS Lambda base images each. Because these base images are the default runtime for many serverless functions, the vulnerability surface is massive (potentially millions of functions across AWS customers).
  • Attack vectors – Remote‑code‑execution, SSRF, prototype‑pollution, deserialization, open‑redirect, path‑traversal, and race‑conditions. Most can be triggered simply by sending a crafted HTTP request to a vulnerable function – no authentication required.
  • Mitigation urgency – The Lambda base images are publicly distributed; any function that does not pin a specific version of axios or urllib3 inherits the flaw. Immediate mitigation steps are:
    1. Pin the library version in package.json / requirements.txt to a patched release (once available).
    2. Update the Lambda runtime to the latest base image (AWS announced patches on 2026‑10‑02 – 2026‑10‑04).
    3. Apply runtime‑level WAF rules to block suspicious payloads while patches are rolled out.

Ransomware‑group activity (Priority 3)

During the same window a large number of new ransomware‑group blog posts were published (e.g., groups AuditTeam, Emperador, qilin, direwolf, Storm, etc.). The posts only announce the existence of a new group or a target (sector, location) and do not disclose any active campaign details, victim data, or novel exploitation techniques. Consequently they do not meet the “massive ransomware campaign” threshold for this briefing and are omitted from the high‑priority list.

Sources (direct URLs)


Take‑away: The most critical security incidents in the last five days are the multiple high‑severity CVEs affecting the axios and urllib3 libraries bundled in AWS Lambda base images. Because these images are widely reused, the exposure is extensive and warrants immediate patching or library‑pinning. No large‑scale ransomware or APT campaigns were disclosed with sufficient technical detail to rank them in this briefing.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster