EarlyTerms

Security & Privacy

9 researched emerging terms in Security & Privacy. Sorted by detection date — newest first.

Security / Supply Chain / Developer Tools
Nascent
Keyv

Keyv is a widely used open-source npm caching library — simple key-value storage with pluggable backends — maintained by developer Jaredwray and installed transitively by tools like ESLint. In current…

Emerged · 7d ago View →
Cybersecurity / Vulnerabilities / WordPress
Emergent
wp2shell

wp2shell is the nickname for [CVE-2026-63030](https://wp2shell.com/), a WordPress Core exploit chain that lets an anonymous attacker run arbitrary code on a stock install with no plugins and no accoun…

Emerged · 25d ago View →
Security / Vulnerabilities / Virtualization
Validating
Januscape

Januscape is the branded name for [CVE-2026-53359](https://www.openwall.com/lists/oss-security/2026/07/06/7), a use-after-free bug in the shadow MMU code KVM shares between Intel and AMD x86 hosts, le…

Emerged · 36d ago View →
Security / Supply Chain / AI Developer Tools
Validating
Miasma (worm)

Miasma is a self-propagating supply-chain worm that steals developer credentials and cloud secrets by hijacking npm packages, PyPI packages, and GitHub repository configuration files. Built on the pub…

Emerged · 71d ago View →
Privacy / Email / Infrastructure
Validating
RootShell

RootShell is a new end-to-end encrypted email service hosted in Iceland, positioning itself as a privacy-first alternative to Proton Mail and Tuta by combining Iceland's outside-14-Eyes jurisdiction w…

Emerged · 69d ago View →
Security / Supply Chain / AI Agents
Validating
protestware

Protestware is open-source software that a maintainer intentionally sabotages to deliver a political or social message, targeting users rather than doing what the package advertises. The technique ran…

Emerged · 78d ago View →
Security / Supply Chain / Developer Tools
Rising
Mini Shai-Hulud

Mini Shai-Hulud is the fourth-generation variant of the Shai-Hulud supply-chain worm family, built by threat group TeamPCP to self-propagate across npm, PyPI, and Packagist by stealing CI/CD credentia…

Emerged · 104d ago View →
Security / Linux / Exploit Research
Rising
Universal Linux LPE

Universal Linux LPE describes a local privilege escalation exploit that gains root access across every major Linux distribution — no race condition required, no kernel-version-specific offsets, no ele…

Emerged · 96d ago View →
Security / DevOps / Incident Response
Rising
Webhook Secrets

A webhook secret is a shared string used to authenticate webhook deliveries: the sender computes an HMAC signature over the payload with the secret and sends it in a header like `X-Hub-Signature-256`;…

Emerged · 119d ago View →
Other categories

EarlyTerms Weekly

5–8 new terms every Tuesday. Research, story angles, buildable ideas — straight to your inbox.