Python Foundation rejects US government grant earmarked for security improvementsHelp Net Security·Oct 29, 00:00 UTC · Oct 29, 2025Vulnerability30
Python team fixes bug that allowed takeover of PyPI repositoryThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Vulnerability155
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to SupplyThe Hacker News·Jun 24, 12:48 UTC · Jun 24, 2026Vulnerability55
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
PyPI hardens package security with new upload restrictionsHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026Vulnerability130
Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF BugsThe Hacker News·Jan 21, 16:08 UTC · Jan 21, 2026VulnerabilityCVE-2026-22218CVE-2026-2221947
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of DevelopersThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Vulnerability142
Red Hat Trusted Software Supply Chain enhances an organization’s resilience to vulnerabilitiesHelp Net Security·May 23, 00:00 UTC · May 23, 2023Vulnerability55
Popular Django web framework affected by a SQL Injection flawSecurity Affairs·Jul 4, 14:49 UTC · Jul 4, 2022VulnerabilityCVE-2022-3426547
How to Start a Career in Cybersecurity: All You Need to KnowThe Hacker News·Oct 8, 13:01 UTC · Oct 8, 2018Vulnerability30
NSA and CISA Urge Adoption of Memory Safe Languages for SafetyInfosecurity Magazine·Jun 25, 16:00 UTC · Jun 25, 2025Vulnerability55
Security Risks Persist in Open Source EcosystemInfosecurity Magazine·Dec 4, 14:00 UTC · Dec 4, 2024Vulnerability55
Researchers Find Bugs in Over A Dozen Widely Used URL Parser LibrariesThe Hacker News·Aug 2, 11:07 UTC · Aug 2, 2022VulnerabilityCVE-2021-33056CVE-2021-23414CVE-2021-37352+5 CVEs160
Symbiotic Security v1 empowers developers to write secure codeHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2025Vulnerability30
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More StoriesThe Hacker News·Jan 19, 06:25 UTC · Jan 19, 2026VulnerabilityCVE-2025-62507CVE-2025-23304CVE-2026-22584160
Transitioning to memory-safe languages: Challenges and considerationsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2024Vulnerability155
Bridging the AI model governance gap: Key findings for CISOsHelp Net Security·Aug 18, 00:00 UTC · Aug 18, 2025Vulnerability55
When transparency is also obscurity: The conundrum that is open-source securityHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2022Vulnerability55
Sonatype Reports 156% Increase in OSS Malicious PackagesInfosecurity Magazine·Oct 11, 11:00 UTC · Oct 11, 2024Vulnerability55
Open-source maintainers still work underfunded as sponsorship crosses $100 millionHelp Net Security·Jul 21, 00:00 UTC · Jul 21, 2026Vulnerability55
Google to create security team for open source projectsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability55
Exploits for unauthenticated FortiWeb RCE are public, so patch quickly! (CVE-2025-25257)Help Net Security·Jul 19, 15:00 UTC · Jul 19, 2025Vulnerability in the wildCVE-2025-2525760
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
Week in review: Attackers use phishing emails to steal NTLM hashes, Patch Tuesday forecastHelp Net Security·Mar 10, 00:00 UTC · Mar 10, 2024Vulnerability in the wildCVE-2024-20337CVE-2024-23225CVE-2024-23296+6 CVEs60
May 2020 Patch Tuesday: Microsoft fixes 111 flaws, Adobe 36Help Net Security·May 14, 12:22 UTC · May 14, 2020Vulnerability in the wildCVE-2020-1135CVE-2020-1118CVE-2020-1192+5 CVEs60
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
White House, CISA call for help with security of open source softwareThe Record·Aug 11, 14:54 UTC · Aug 11, 2023Vulnerability55
Protecting Your Software Supply Chain: Assessing the Risks Before DeploymentThe Hacker News·Feb 25, 04:15 UTC · Feb 25, 2025Vulnerability55
Supply chain attack sends shockwaves through openCyberScoop·Apr 5, 21:51 UTC · Apr 5, 2024VulnerabilityCVE-2024-309447
40 Open-Source Tools Redefining How Security Teams Secure The StackHelp Net Security·Dec 11, 00:00 UTC · Dec 11, 2025Vulnerability42
Week in review: Electronic warfare, cybersecurity career plan, Patch Tuesday forecastHelp Net Security·Oct 10, 00:00 UTC · Oct 10, 2021Vulnerability55