PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and BunSecurity Affairs·Jan 28, 08:43 UTC · Jan 28, 2026Exploit / PoC160
When ‘minimal impact’ isn’t reassuring: lessons from the largest npm supply chain compromiseCyberScoop·Sep 15, 13:21 UTC · Sep 15, 2025Exploit / PoC in the wild60
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
The npm incident frightened everyone, but ended up being nothing to fret aboutCyberScoop·Sep 10, 14:35 UTC · Sep 10, 2025Exploit / PoC in the wild60
Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
Zapier exploit chain shows how known anti-patterns compose into critical riskHelp Net Security·May 28, 00:00 UTC · May 28, 2026Exploit / PoC60
Malicious AI Agent Server Reportedly Steals EmailsInfosecurity Magazine·Sep 25, 16:30 UTC · Sep 25, 2025Exploit / PoC60
A little-known npm package was North Korea’s warmCyberScoop·Jul 29, 21:09 UTC · Jul 29, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AIThe Hacker News·Jan 20, 09:20 UTC · Jan 20, 2026Exploit / PoCCVE-2025-29824CVE-2025-2775CVE-2025-2776+19 CVEs60
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin AccessThe Hacker News·Dec 21, 09:00 UTC · Dec 21, 2024Exploit / PoCCVE-2024-41713CVE-2024-35286CVE-2024-55550+3 CVEs60
Massive supply-chain attack compromises 440 packages under four hoursCyberScoop·Aug 4, 22:07 UTC · Aug 4, 2026Exploit / PoC60
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New StoriesThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2026Exploit / PoCCVE-2026-27175CVE-2026-27174CVE-2025-22952+1 CVEs60
Infosecurity's Top 10 Cybersecurity Stories of 2025Infosecurity Magazine·Jan 1, 08:30 UTC · Jan 1, 2026Exploit / PoC in the wildCVE-2024-5559160
Week in review: Cisco ASA zero-day vulnerabilities exploited, Fortra GoAnywhere instances at riskHelp Net Security·Sep 28, 00:00 UTC · Sep 28, 2025Exploit / PoCCVE-2025-10035CVE-2025-59689CVE-2025-26399+1 CVEs60
Critical Gems Takeover Bug Reported in RubyGems Package ManagerThe Hacker News·May 11, 02:45 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-2917660
Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-dayHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2022Exploit / PoC in the wildCVE-2022-24521CVE-2022-26904CVE-2022-26809+1 CVEs60
Suppliers, logins, and AI tools are all becoming attack pathsHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2026Exploit / PoC in the wild160
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197160
U.S. CISA adds a flaw in n8n to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 12, 08:46 UTC · Mar 12, 2026Exploit / PoC in the wildCVE-2025-6861360
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
Open-source security group pulls out of U.S. grant, citing DEI restrictionsCyberScoop·Oct 29, 20:55 UTC · Oct 29, 2025Exploit / PoC in the wild160
Security Affairs newsletter Round 520 by Pierluigi PaganiniSecurity Affairs·Apr 20, 16:14 UTC · Apr 20, 2025Exploit / PoC in the wildCVE-2025-30406CVE-2025-24054CVE-2021-2003560
U.S. CISA adds Oracle WebLogic Server and Mitel MiCollab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 8, 06:58 UTC · Jan 8, 2025Exploit / PoC in the wildCVE-2020-2883CVE-2024-41713CVE-2024-5555060
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]The Hacker News·Jan 6, 12:05 UTC · Jan 6, 2025Exploit / PoCCVE-2024-49113CVE-2024-49112160
Network Attack Trends: FebruaryPalo Alto Unit 42·Jun 6, 12:33 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-25296CVE-2021-25297CVE-2021-25298+4 CVEs60
Phylum integrates with Sumo Logic to identify software supply chain attacksHelp Net Security·Dec 7, 00:00 UTC · Dec 7, 2023Exploit / PoC60
North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity ResearchersThe Hacker News·Sep 8, 16:50 UTC · Sep 8, 2023Exploit / PoCCVE-2021-34514CVE-2022-2188160
New Nagios Software Bugs Could Let Hackers Take Over IT InfrastructuresThe Hacker News·Sep 27, 04:39 UTC · Sep 27, 2021Exploit / PoCCVE-2021-37344CVE-2021-37346CVE-2021-37350+8 CVEs160
Open Source Supply Chain Attacks Surge 430%Infosecurity Magazine·Aug 13, 09:53 UTC · Aug 13, 2020Exploit / PoC in the wild60
Surge in cyber attacks targeting open source software projectsHelp Net Security·Aug 13, 00:00 UTC · Aug 13, 2020Exploit / PoC in the wild60