The 18:00 First Watch led with the LiquidJS template-engine RCE and two malicious npm packages quietly harvesting Claude artifacts and OpenAI tokens. The 21:00 Last Watch arrived to find CISA had put the federal seal on the day's npm campaign — Nx Console and TanStack went onto the Known Exploited Vulnerabilities list with a 2026-06-10 due date, and Daemon Tools Lite came along on a tighter 3-day clock. The day's narrative is now federally mandated.
Late escalation at 21:00 ET: GHSA shipped its largest single batch of the day in the same hour CISA was publishing. Yamcs — the mission-control framework used by ESA and the CCSDS reference stack — caught two RCEs in its script-algorithm engines, one of them (CVE-2026-46562, CVSS 9.8) effectively unauthenticated in the default deploy because the bundled `guest` user is `superuser=true`. Kata Containers runtime-rs disclosed a guest-root-to-host-root escape that uses raw FUSE_SYMLINK against a virtiofsd running `--sandbox none --seccomp none` to drop a payload into `/etc/cron.d`. IBM's `compliance-trestle` turns a malicious OSCAL profile into arbitrary file write via cache path traversal, FUXA SCADA leaks full server-side scripts and device configs to an unauthenticated guest, and Pimcore adds a CustomReports share-bypass. Symfony followed its First Watch triple with four more advisories from the same hardening pass — including a real SQL injection in `PdoAdapter::doClear`.
→ Operational priority for the night if you run Nx Console on any developer workstation or TanStack packages anywhere in a CI/CD lockfile, treat the trusted-publisher chain as compromised and rotate every npm, GitHub, GitLab, AWS, and Anthropic credential that touched a build in the last week — the KEV deadline is 2026-06-10. If you run Yamcs anywhere, take the MDB Override API off the network and check you have a real `security.yaml` before morning; the default deploy is an unauthenticated RCE. If you run Kata runtime-rs with virtio-fs and treat your guests as less trusted than your host, upgrade past commit `ffa59ce3aa78` tonight.