Week in review: PoC for FortiSIEM flaw released, Rakuten Viber CISO/CTO on messaging risksHelp Net Security·Jan 18, 00:00 UTC · Jan 18, 2026Exploit / PoCCVE-2025-64155CVE-2025-20393160
Python team fixes bug that allowed takeover of PyPI repositoryThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Vulnerability155
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
Week in review: WSUS vulnerability exploited to drop Skuld infostealer, PoC for BIND 9 DNS flaw publishedHelp Net Security·Nov 2, 00:00 UTC · Nov 2, 2025Exploit / PoCCVE-2025-2783CVE-2025-40778CVE-2025-59287+1 CVEs160
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to SupplyThe Hacker News·Jun 24, 12:48 UTC · Jun 24, 2026Vulnerability55
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
Infosecurity's Top 10 Cybersecurity Stories of 2025Infosecurity Magazine·Jan 1, 08:30 UTC · Jan 1, 2026Exploit / PoC in the wildCVE-2024-5559160
Package hallucination: LLMs may deliver malicious code to careless devsHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2025Data breach160
PyPI Repository Makes 2FA Security Mandatory for Critical Python ProjectsThe Hacker News·Jul 11, 05:23 UTC · Jul 11, 2022Industry155
PyPI Blocks 1,800 Expired-Domain Emails to Prevent Account Takeovers and Supply Chain AttacksThe Hacker News·Aug 19, 17:29 UTC · Aug 19, 2025Threat actor60
Week in review: LLM package hallucinations harm supply chains, Nagios Log Server flaws fixedHelp Net Security·Apr 20, 00:00 UTC · Apr 20, 2025RansomwareCVE-2025-31200CVE-2025-31201CVE-2025-24054+1 CVEs60
Red Hat Trusted Software Supply Chain enhances an organization’s resilience to vulnerabilitiesHelp Net Security·May 23, 00:00 UTC · May 23, 2023Vulnerability55
The Update Framework graduates from the Linux Foundation's Cloud Native Computing FoundationHelp Net Security·Dec 23, 00:00 UTC · Dec 23, 2019Industry55
Databricks Delta Sharing protocol secures real time data sharing between organizationsHelp Net Security·Apr 20, 09:39 UTC · Apr 20, 2026Policy & legal55
Experts warn of possible attacks after PoC code for CVE-2018Security Affairs·Aug 27, 15:13 UTC · Aug 27, 2018Exploit / PoCCVE-2018-11776CVE-2017-563860
PoC exploit for critical Apache Struts flaw found onlineHelp Net Security·Nov 20, 11:02 UTC · Nov 20, 2023Exploit / PoCCVE-2018-11776CVE-2017-563860
NSA and CISA Urge Adoption of Memory Safe Languages for SafetyInfosecurity Magazine·Jun 25, 16:00 UTC · Jun 25, 2025Vulnerability55
Security Risks Persist in Open Source EcosystemInfosecurity Magazine·Dec 4, 14:00 UTC · Dec 4, 2024Vulnerability55
Researchers Find Bugs in Over A Dozen Widely Used URL Parser LibrariesThe Hacker News·Aug 2, 11:07 UTC · Aug 2, 2022VulnerabilityCVE-2021-33056CVE-2021-23414CVE-2021-37352+5 CVEs160
Wind River unveils new VxWorks release to redefine embedded software developmentHelp Net Security·Oct 10, 00:00 UTC · Oct 10, 2019Exploit / PoC60
How the Cult of the Dead Cow plans to save the internetCyberScoop·Sep 25, 15:52 UTC · Sep 25, 2023Exploit / PoC in the wild60
NVIDIA Forms 37-Member Open Secure AI Alliance and OpenThe Hacker News·Jul 27, 18:10 UTC · Jul 27, 2026Exploit / PoC60
Researchers Uncover WatchGuard VPN Bug That Could Let Attackers Take Over DevicesThe Hacker News·Oct 22, 04:20 UTC · Oct 22, 2025RansomwareCVE-2025-9242CVE-2025-3600CVE-2025-3660460
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More StoriesThe Hacker News·Jan 19, 06:25 UTC · Jan 19, 2026VulnerabilityCVE-2025-62507CVE-2025-23304CVE-2026-22584160
Transitioning to memory-safe languages: Challenges and considerationsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2024Vulnerability155
Bridging the AI model governance gap: Key findings for CISOsHelp Net Security·Aug 18, 00:00 UTC · Aug 18, 2025Vulnerability55
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AIThe Hacker News·Jun 2, 03:39 UTC · Jun 2, 2026Ransomware in the wildCVE-2026-0257CVE-2026-8732CVE-2026-27771+31 CVEs60
When transparency is also obscurity: The conundrum that is open-source securityHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2022Vulnerability55
Sonatype Reports 156% Increase in OSS Malicious PackagesInfosecurity Magazine·Oct 11, 11:00 UTC · Oct 11, 2024Vulnerability55
⚡ Weekly Recap: WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach WidensThe Hacker News·Oct 27, 14:16 UTC · Oct 27, 2025Ransomware in the wildCVE-2025-59287CVE-2025-54957CVE-2025-6950+21 CVEs60
Open-source maintainers still work underfunded as sponsorship crosses $100 millionHelp Net Security·Jul 21, 00:00 UTC · Jul 21, 2026Vulnerability55
Google to create security team for open source projectsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability55
Exploits for unauthenticated FortiWeb RCE are public, so patch quickly! (CVE-2025-25257)Help Net Security·Jul 19, 15:00 UTC · Jul 19, 2025Vulnerability in the wildCVE-2025-2525760
Week in review: Attackers use phishing emails to steal NTLM hashes, Patch Tuesday forecastHelp Net Security·Mar 10, 00:00 UTC · Mar 10, 2024Vulnerability in the wildCVE-2024-20337CVE-2024-23225CVE-2024-23296+6 CVEs60
Apple did not disable Intel Manufacturing Mode in its laptopsSecurity Affairs·Oct 4, 14:20 UTC · Oct 4, 2018Exploit / PoCCVE-2018-425160
Cybersecurity jobs available right now: December 23, 2025Help Net Security·Mar 27, 12:20 UTC · Mar 27, 2026Exploit / PoC60
May 2020 Patch Tuesday: Microsoft fixes 111 flaws, Adobe 36Help Net Security·May 14, 12:22 UTC · May 14, 2020Vulnerability in the wildCVE-2020-1135CVE-2020-1118CVE-2020-1192+5 CVEs60