<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/sources/csoonline/best-of/2026/05" -->

---
title: Best CSO Online posts — May 2026 | daily.dev
description: The most upvoted CSO Online posts from May 2026, curated by the daily.dev community.
canonical: https://daily.dev/sources/csoonline/best-of/2026/05
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:url: https://daily.dev/sources/csoonline/best-of/2026/05
og:type: website
og:site_name: daily.dev
og:title: Best CSO Online posts — May 2026 | daily.dev
og:description: The most upvoted CSO Online posts from May 2026, curated by the daily.dev community.
og:image: https://media.daily.dev/image/upload/s--VAY5ToZt--/f_auto/v1724209435/public/daily.dev%20-%20open%20graph
---

# Best of CSO Online — May 2026

1. 1  
[](https://daily.dev/posts/ai-finds-20-year-old-bugs-in-postgresql-and-mariadb-zvvo8yix8 "AI finds 20-year-old bugs in PostgreSQL and MariaDB")  
Article  
![Avatar of csoonline](https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd)CSO Online · 19w  
AI finds 20-year-old bugs in PostgreSQL and MariaDB  
AI-powered security tool Xint Code, used at Wiz's zeroday.cloud hacking event, uncovered critical vulnerabilities in PostgreSQL and MariaDB. In PostgreSQL, a heap-based buffer overflow in the pgcrypto extension (CVE-2026-2005, CVSS 8.8) has existed since 2005, and a missing validation bug (CVE-2026-2006, CVSS \~9) was also found — both enabling remote code execution. In MariaDB, a buffer overflow in the JSON\_SCHEMA\_VALID() function (CVE-2026-32710, CVSS 9.9 per NIST) can be exploited by any authenticated SQL user. All flaws have been patched, and maintainers urge immediate upgrades. A Wiz analysis found 80% of cloud PostgreSQL environments affected, with 45% directly internet-exposed.  
132  
3
2. 2  
[](https://daily.dev/posts/expired-domain-leads-to-supply-chain-attack-on-node-ipc-npm-package-cek2g6opk "Expired domain leads to supply chain attack on node-ipc npm package")  
Article  
![Avatar of csoonline](https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd)CSO Online · 17w  
Expired domain leads to supply chain attack on node-ipc npm package  
The node-ipc npm package was compromised via a supply chain attack after attackers registered an expired domain to hijack a dormant maintainer's email account and perform a password reset. Three malicious versions (9.1.6, 9.2.3, 12.0.1) were published containing an 80KB obfuscated credential-stealing payload inside node-ipc.cjs. The malware collects credentials from over 100 sources including cloud providers (AWS, Azure, GCP), SSH keys, Kubernetes, Docker, CI/CD tools, and AI coding agents, then exfiltrates data via DNS TXT queries to evade detection. With \~700K weekly downloads and 424 dependent packages, the blast radius is significant. Users should scan for compromised versions and rotate all secrets on affected machines. The attack vector — expired custom-domain email addresses on dormant maintainer accounts — may affect other npm packages as well.  
11  
2
3. 3  
[](https://daily.dev/posts/ai-agent-finds-18-year-old-remote-code-execution-flaw-in-nginx-ogqskl35h "AI agent finds 18-year-old remote code execution flaw in Nginx")  
Article  
![Avatar of csoonline](https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd)CSO Online · 17w  
AI agent finds 18-year-old remote code execution flaw in Nginx  
Security startup DepthFirst AI used an LLM-powered platform to discover four vulnerabilities in Nginx, including a critical 18-year-old heap buffer overflow (CVE-2026-42945, CVSS 9.2) in the URL rewrite module. The flaw affects Nginx versions 0.6.27 through 1.30.0 and Nginx Plus, and can cause denial of service or remote code execution on systems with ASLR disabled. Nginx's multi-process architecture makes ASLR bypass theoretically feasible by allowing repeated exploit attempts without changing memory layout. Patches are available in Nginx 1.31.0 and 1.30.1, and Nginx Plus R36 P4, R32 P6, and 37.0.0\. A public PoC exploit has been released on GitHub, making urgent patching critical.  
11  
2

[See all CSO Online archives](/sources/csoonline/best-of)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@graph":[{"@type":"CollectionPage","@id":"https://daily.dev/sources/csoonline/best-of/2026/05#page","url":"https://daily.dev/sources/csoonline/best-of/2026/05","name":"Best CSO Online Posts — May 2026","description":"The most upvoted CSO Online posts from May 2026, curated by the daily.dev community.","isPartOf":{"@type":"WebSite","url":"https://daily.dev"}},{"@type":"ItemList","@id":"https://daily.dev/sources/csoonline/best-of/2026/05#items","numberOfItems":3,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://daily.dev/posts/ai-finds-20-year-old-bugs-in-postgresql-and-mariadb-zvvo8yix8","name":"AI finds 20-year-old bugs in PostgreSQL and MariaDB"},{"@type":"ListItem","position":2,"url":"https://daily.dev/posts/expired-domain-leads-to-supply-chain-attack-on-node-ipc-npm-package-cek2g6opk","name":"Expired domain leads to supply chain attack on node-ipc npm package"},{"@type":"ListItem","position":3,"url":"https://daily.dev/posts/ai-agent-finds-18-year-old-remote-code-execution-flaw-in-nginx-ogqskl35h","name":"AI agent finds 18-year-old remote code execution flaw in Nginx"}]},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Sources","item":"https://daily.dev/sources"},{"@type":"ListItem","position":3,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":4,"name":"Best of","item":"https://daily.dev/sources/csoonline/best-of"},{"@type":"ListItem","position":5,"name":"May 2026"}]}]}
```

