Experts found binary planting and arbitrary file overwrite flaws in NPMSecurity Affairs·Dec 16, 13:00 UTC · Dec 16, 2019Exploit / PoC145
PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and BunSecurity Affairs·Jan 28, 08:43 UTC · Jan 28, 2026Exploit / PoC160
Developer account body snatchers pose risks to the software supply chainCisco Talos·Oct 4, 12:51 UTC · Oct 4, 2022Exploit / PoC57
Compromised AsyncAPI npm Packages Deliver MultiThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC157
When ‘minimal impact’ isn’t reassuring: lessons from the largest npm supply chain compromiseCyberScoop·Sep 15, 13:21 UTC · Sep 15, 2025Exploit / PoC in the wild60
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain AttacksThe Hacker News·Aug 19, 04:18 UTC · Aug 19, 2025Exploit / PoC157
Over 800 npm Packages Found with Discrepancies, 18 Exploit 'Manifest Confusion'The Hacker News·Mar 26, 04:00 UTC · Mar 26, 2024Exploit / PoC57
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
The npm incident frightened everyone, but ended up being nothing to fret aboutCyberScoop·Sep 10, 14:35 UTC · Sep 10, 2025Exploit / PoC in the wild60
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
Researchers Uncover 700+ Malicious Open Source PackagesInfosecurity Magazine·Feb 13, 10:40 UTC · Feb 13, 2023Exploit / PoC45
Zapier exploit chain shows how known anti-patterns compose into critical riskHelp Net Security·May 28, 00:00 UTC · May 28, 2026Exploit / PoC60
Malicious AI Agent Server Reportedly Steals EmailsInfosecurity Magazine·Sep 25, 16:30 UTC · Sep 25, 2025Exploit / PoC60
A little-known npm package was North Korea’s warmCyberScoop·Jul 29, 21:09 UTC · Jul 29, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AIThe Hacker News·Jan 20, 09:20 UTC · Jan 20, 2026Exploit / PoCCVE-2025-29824CVE-2025-2775CVE-2025-2776+19 CVEs60
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC ExploitsThe Hacker News·Dec 17, 04:40 UTC · Dec 17, 2024Exploit / PoC57
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin AccessThe Hacker News·Dec 21, 09:00 UTC · Dec 21, 2024Exploit / PoCCVE-2024-41713CVE-2024-35286CVE-2024-55550+3 CVEs60
Massive supply-chain attack compromises 440 packages under four hoursCyberScoop·Aug 4, 22:07 UTC · Aug 4, 2026Exploit / PoC60
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New StoriesThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2026Exploit / PoCCVE-2026-27175CVE-2026-27174CVE-2025-22952+1 CVEs60
Infosecurity's Top 10 Cybersecurity Stories of 2025Infosecurity Magazine·Jan 1, 08:30 UTC · Jan 1, 2026Exploit / PoC in the wildCVE-2024-5559160
Week in review: Cisco ASA zero-day vulnerabilities exploited, Fortra GoAnywhere instances at riskHelp Net Security·Sep 28, 00:00 UTC · Sep 28, 2025Exploit / PoCCVE-2025-10035CVE-2025-59689CVE-2025-26399+1 CVEs60
New ChatGPT Attack Technique Spreads Malicious PackagesInfosecurity Magazine·Jun 6, 16:00 UTC · Jun 6, 2023Exploit / PoC45
Researchers Uncover Obfuscated Malicious Code in PyPI Python PackagesThe Hacker News·Feb 11, 10:33 UTC · Feb 11, 2023Exploit / PoC157
Critical Gems Takeover Bug Reported in RubyGems Package ManagerThe Hacker News·May 11, 02:45 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-2917660
Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-dayHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2022Exploit / PoC in the wildCVE-2022-24521CVE-2022-26904CVE-2022-26809+1 CVEs60
Flaw in popular NodeJS 'express-fileupload' module allows DoS attacks and code injectionSecurity Affairs·Aug 5, 08:00 UTC · Aug 5, 2020Exploit / PoCCVE-2020-7699150
Prototype Pollution flaw discovered in all versions of Lodash LibrarySecurity Affairs·Jul 9, 17:50 UTC · Jul 9, 2019Exploit / PoCCVE-2019-1074460
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow SecretsThe Hacker News·Aug 7, 08:18 UTC · Aug 7, 2026Exploit / PoC in the wildCVE-2026-12537CVE-2026-54316160
Suppliers, logins, and AI tools are all becoming attack pathsHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2026Exploit / PoC in the wild160
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another IssuerThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2026-59208CVE-2026-5430550
How security teams are getting credential visibility into developer endpointsHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2026Exploit / PoC57
U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 28, 13:14 UTC · May 28, 2026Exploit / PoC in the wildCVE-2026-8398CVE-2026-45321CVE-2026-4802760
Lyrie: Open-source autonomous pentesting agentHelp Net Security·May 18, 00:00 UTC · May 18, 2026Exploit / PoC45
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197160
U.S. CISA adds a flaw in n8n to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 12, 08:46 UTC · Mar 12, 2026Exploit / PoC in the wildCVE-2025-6861360
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60