Developer account body snatchers pose risks to the software supply chainCisco Talos·Oct 4, 12:51 UTC · Oct 4, 2022Exploit / PoC57
Compromised AsyncAPI npm Packages Deliver MultiThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC157
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain AttacksThe Hacker News·Aug 19, 04:18 UTC · Aug 19, 2025Exploit / PoC157
Over 800 npm Packages Found with Discrepancies, 18 Exploit 'Manifest Confusion'The Hacker News·Mar 26, 04:00 UTC · Mar 26, 2024Exploit / PoC57
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC ExploitsThe Hacker News·Dec 17, 04:40 UTC · Dec 17, 2024Exploit / PoC57
Researchers Uncover Obfuscated Malicious Code in PyPI Python PackagesThe Hacker News·Feb 11, 10:33 UTC · Feb 11, 2023Exploit / PoC157
Prototype Pollution flaw discovered in all versions of Lodash LibrarySecurity Affairs·Jul 9, 17:50 UTC · Jul 9, 2019Exploit / PoCCVE-2019-1074460
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow SecretsThe Hacker News·Aug 7, 08:18 UTC · Aug 7, 2026Exploit / PoC in the wildCVE-2026-12537CVE-2026-54316160
How security teams are getting credential visibility into developer endpointsHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2026Exploit / PoC57
U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 28, 13:14 UTC · May 28, 2026Exploit / PoC in the wildCVE-2026-8398CVE-2026-45321CVE-2026-4802760
Severe Security Flaw Found in "jsonwebtoken" Library Used by 22,000+ ProjectsThe Hacker News·Jan 31, 03:01 UTC · Jan 31, 2023Exploit / PoCCVE-2022-2352960