Researchers stop ‘credible takeover attempt’ similar to XZ Utils backdoor incidentThe Record·Apr 15, 19:44 UTC · Apr 15, 2024Malware55
Malicious Open Source Packages Surge 188% AnnuallyInfosecurity Magazine·Jul 8, 11:00 UTC · Jul 8, 2025Malware55
Old certificate, new signature: Open-source tools forge signature timestamps on Windows driversCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
New open-source infostealer, and reflections on 2023 so farCisco Talos·Aug 31, 18:00 UTC · Aug 31, 2023Malware55
Kunai: Open-source threat hunting tool for LinuxHelp Net Security·Feb 19, 00:00 UTC · Feb 19, 2025Malware55
Week in review: MOVEit auth bypass flaws quitely fixed, open-source Rafel RAT targets AndroidsHelp Net Security·Jun 30, 00:00 UTC · Jun 30, 2024MalwareCVE-2024-5805CVE-2024-5806CVE-2024-527660
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023Help Net Security·Mar 1, 00:00 UTC · Mar 1, 2026Malware in the wildCVE-2026-25108CVE-2026-20127160
Putting Data in Perspective With Web IntelligenceRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Malware55
Lazarus Group's infrastructure reuse leads to discovery of new malwareCisco Talos·Aug 24, 12:04 UTC · Aug 24, 2023MalwareCVE-2022-4796660
Backdoor in XZ Utils That Almost HappenedSchneier on Security·Apr 15, 00:00 UTC · Apr 15, 2024Malware155
SkillSpector: NVIDIA's open-source security scanner for AI agent skillsHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2026Malware55
Sprout: Open-source bootloader built for speed and securityHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2025Malware55
Microsoft Application Inspector: Check open source components for unwanted featuresHelp Net Security·Jan 17, 00:00 UTC · Jan 17, 2020Malware55
Week in review: 0-days exploited in Palo Alto Networks firewalls, two unknown Linux backdoors identifiedHelp Net Security·Nov 24, 00:00 UTC · Nov 24, 2024Malware in the wildCVE-2024-0012CVE-2024-9474CVE-2024-44309+2 CVEs60
Cryptomining Malware Found in Popular Open Source PackagesInfosecurity Magazine·Dec 23, 16:30 UTC · Dec 23, 2024Malware55
Growing reliance on open source libraries leaves many companies vulnerableHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2019Malware55
Balancing proprietary and open-source tools in cyber threat researchHelp Net Security·Jan 6, 00:00 UTC · Jan 6, 2025Malware55
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supplyCyberScoop·May 12, 21:38 UTC · May 12, 2026Malware155
EU Offering Bug Bounties on Critical Open-Source SoftwareSchneier on Security·Jan 27, 14:38 UTC · Jan 27, 2020Malware55
Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHelp Net Security·May 31, 00:00 UTC · May 31, 2026Malware in the wildCVE-2026-45659CVE-2026-34926CVE-2026-3561660
New malware from North Korea’s Lazarus used against healthcare industryThe Record·Aug 25, 13:47 UTC · Aug 25, 2023MalwareCVE-2022-4796660
How GitHub untangled itself from the ‘Octopus’ malware that infected 26 software projectsCyberScoop·May 29, 19:51 UTC · May 29, 2020Malware in the wild160
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for ItselfThe Hacker News·Aug 5, 07:53 UTC · Aug 5, 2026Malware55
Undocumented driver-based browser hijacker RedDriver targets Chinese speakers and internet cafesCisco Talos·Jul 11, 17:04 UTC · Jul 11, 2023Malware55
IBM Cloud Pak for Security hunts threats across security tools and clouds without moving dataHelp Net Security·Nov 21, 00:00 UTC · Nov 21, 2019Malware55
Week in review: Cybersecurity job openings, hackers use 1-day flaws to drop custom Linux malwareHelp Net Security·Mar 17, 00:00 UTC · Mar 17, 2024Malware in the wildCVE-2024-0799CVE-2024-0800CVE-2023-4878860
Week in review: Actively exploited Windows SMB flaw, trusted OAuth apps turned into cloud backdoorsHelp Net Security·Oct 26, 00:00 UTC · Oct 26, 2025Malware in the wildCVE-2025-59287CVE-2025-61932CVE-2025-54236+2 CVEs60
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News·Jun 29, 14:42 UTC · Jun 29, 2026Malware in the wildCVE-2026-43503CVE-2026-12569CVE-2026-47729+19 CVEs60
⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreThe Hacker News·May 7, 10:33 UTC · May 7, 2025MalwareCVE-2025-29927CVE-2025-23120CVE-2024-56346+13 CVEs60
Experts observed Magecart 5 hacker group targeting L7 RoutersSecurity Affairs·Sep 27, 12:37 UTC · Sep 27, 2019Malware55
New versions of Chaos RAT target Windows and Linux systemsSecurity Affairs·Jun 5, 20:29 UTC · Jun 5, 2025Malware55
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
StrongKey launches FIDO server, enabling rapid application development and integrationHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2019Malware55
Software supply chain attacks are getting easierHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2024Malware55
What we know about the xz Utils backdoor that almost infected the worldArs Technica · Security·Apr 1, 06:55 UTC · Apr 1, 2024Malware55
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-26127160
CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360