build1 publisherOne report GitHub flagged six npm typosquats of Angular that claimed the live 22.2.1 version, five pulling a payload through the Wayback Machine. With the version number now correct, the defence has to sit at the package name and at whether install scripts run at all.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence50
CVE-2026-94545 lets attacker-supplied text in an Open Graph image reach Next.js dependencies. Vercel shipped the fix on September 22 in 16.3.6; a day later, npm audit still passed affected builds.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence60
build1 publisherOne report AWS's Java extended clients for large SQS and SNS messages pull Jackson versions with seven known advisories via a library last released in March 2024. Kotlin services now have ports on Maven Central that take Jackson out of that code path.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence45
build1 publisherOne report AgentGate read the shipped code behind 30-plus OSV and GHSA flags, verified 19 npm packages as malicious, and found 18 still resolvable on publication day. Removal, not detection, is where the chain stopped.
Reality
- Evidence48
- Adoption20
- Hype gap+22
- Incentives78
- Confidence55
The Erlang Ecosystem Foundation's CNA published the entry on August 30, 2026, and ash_sqlite 0.2.18 escapes the path segments. Exposure comes down to whether your callers get to name the JSON field.
Reality
- Evidence64
- Adoption18
- Hype gap−6
- Incentives30
- Confidence58
CVE-2026-48519 lets anyone holding a shared Langflow playground link supply their own Python inside the build request. The exposure follows a user clicking share, so it lives in flow state rather than in server config.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap−10
- Incentives35
- Confidence66
Sysdig logged a pre-auth SQL injection probe against CVE-2026-42208 from an operator who already had the Prisma schema casing right, which is the argument for putting LLM gateways on the same patch clock as edge appliances.
Reality
- Evidence64
- Adoption38
- Hype gap+12
- Incentives66
- Confidence58
Kaspersky's Q2 2026 figures credit AI with both writing the bugs and finding them. The disclosures carrying working exploit code never got a CVE identifier at all.
Reality
- Evidence48
- Adoption44
- Hype gap+30
- Incentives66
- Confidence45
Two 2026 studies put AI-generated deployment infrastructure at worse than a coin flip, and the gates most CI pipelines run were built for application source, not config.
Reality
- Evidence58
- Adoption52
- Hype gap+12
- Incentives66
- Confidence57
build1 publisherOne report JFrog found that 54 of 55 advisories from one new GitHub account were machine-generated fiction. They reached enterprise scanners by the normal route, which is the problem.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives60
- Confidence48