A Tumultuous Week for Federal Cybersecurity EffortsKrebs on Security·Jan 28, 20:32 UTC · Jan 28, 2025Vulnerability155
Zero-days dominate top frequently exploited vulnerabilitiesHelp Net Security·Nov 14, 00:00 UTC · Nov 14, 2024Vulnerability in the wildCVE-2023-3519CVE-2023-20198CVE-2021-44228+1 CVEs60
Open-source software: A first attempt at organization after CRAHelp Net Security·Nov 5, 00:00 UTC · Nov 5, 2024Vulnerability30
Sonatype Reports 156% Increase in OSS Malicious PackagesInfosecurity Magazine·Oct 11, 11:00 UTC · Oct 11, 2024Vulnerability55
CUPS vulnerabilities affecting Linux, Unix systems can lead to RCEHelp Net Security·Sep 30, 07:33 UTC · Sep 30, 2024VulnerabilityCVE-2024-47176CVE-2024-47076CVE-2024-47175+1 CVEs60
CISA advisors urge changes to JCDC's goals, operations, membership criteriaThe Record·Jun 6, 00:03 UTC · Jun 6, 2024Vulnerability30
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research ReportPalo Alto Unit 42·Jun 5, 20:14 UTC · Jun 5, 2024VulnerabilityCVE-2017-5638CVE-2017-9841CVE-2018-19986+26 CVEs160
RedTail Crypto-Mining Malware Exploiting Palo Alto Networks Firewall VulnerabilityThe Hacker News·May 31, 04:58 UTC · May 31, 2024VulnerabilityCVE-2024-3400CVE-2023-1389CVE-2018-20062+6 CVEs47
Critical Fluent Bit Bug Impacts All Major Cloud PlatformsInfosecurity Magazine·May 21, 09:30 UTC · May 21, 2024VulnerabilityCVE-2024-432360
Product showcase: Sniper - automatically detect and exploit critical CVEs in minutesHelp Net Security·Mar 14, 11:45 UTC · Mar 14, 2024VulnerabilityCVE-2021-4422860
How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severityCisco Talos·Feb 21, 13:54 UTC · Feb 21, 2024VulnerabilityCVE-2021-4422860
Open-source vulnerability disclosure: Exploitable weak spotsHelp Net Security·Nov 9, 00:00 UTC · Nov 9, 2023Vulnerability30
The hidden costs of Java, and the impact of pricing changesHelp Net Security·Nov 1, 00:00 UTC · Nov 1, 2023Vulnerability130
VMware warns of critical vulnerability affecting vCenter Server productThe Record·Oct 26, 21:12 UTC · Oct 26, 2023VulnerabilityCVE-2023-3404860
CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho VulnerabilitiesThe Hacker News·Sep 11, 05:58 UTC · Sep 11, 2023VulnerabilityCVE-2022-47966CVE-2022-42475CVE-2021-4422860
Top 12 vulnerabilities routinely exploited in 2022Help Net Security·Aug 7, 07:41 UTC · Aug 7, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+23 CVEs147
Major Cybersecurity Agencies Collaborate to Unveil 2022's Most Exploited VulnerabilitiesThe Hacker News·Aug 4, 07:02 UTC · Aug 4, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+9 CVEs160
CISA, FBI, and NSA published the list of 12 most exploited vulnerabilities of 2022Security Affairs·Aug 4, 06:31 UTC · Aug 4, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+8 CVEs60
Fortinet VPN bug tops CISA’s list of most exploited vulnerabilities in 2022The Record·Aug 3, 14:44 UTC · Aug 3, 2023VulnerabilityCVE-2021-44228CVE-2021-40539CVE-2018-13379+8 CVEs60
Vulnerabilities that kept security leaders busy in Q1 2022Help Net Security·Jun 26, 09:19 UTC · Jun 26, 2023Vulnerability55
Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities DetectedThe Hacker News·May 3, 04:08 UTC · May 3, 2023Vulnerability in the wildCVE-2023-1389CVE-2021-45046CVE-2023-21839+1 CVEs60
ThreatX Runtime API & Application Protection goes beyond basic observabilityHelp Net Security·Apr 11, 00:00 UTC · Apr 11, 2023Vulnerability30
CISA ’s JCDC Will Focus on Energy SectorSecurity Affairs·Apr 5, 12:15 UTC · Apr 5, 2023Vulnerability55
Rookout's Snapshots: The fourth pillar of observability for more secure applicationsHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2023Vulnerability55
The potential pitfalls of open source managementHelp Net Security·Feb 23, 00:00 UTC · Feb 23, 2023Vulnerability42
CISA, Claroty warn of two vulnerabilities affecting industrial Rockwell productsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023VulnerabilityCVE-2022-1161CVE-2022-115960
Google touts ‘fuzzing’ open source tool after discovering TinyGLTF bugThe Record·Jan 11, 00:00 UTC · Jan 11, 2023VulnerabilityCVE-2022-300860
CISA urges defenders to update after VMware patches vulnerabilities in multiple productsThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-31656CVE-2022-31659CVE-2021-4422860
Google announces open source vulnerability reward program after Log4j, Codecov issuesThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability55
Suspected Iranian APT accessed federal server via Log4j vulnerabilityThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Vulnerability42
When Being Attractive Gets Risky - How Does Your Attack Surface Look to an Attacker?The Hacker News·Dec 5, 13:50 UTC · Dec 5, 2022Vulnerability55
Following Log4j: Supporting the developer community to secure ITHelp Net Security·Nov 1, 00:00 UTC · Nov 1, 2022Vulnerability30
Experts warn of CVE-2022Security Affairs·Oct 21, 20:51 UTC · Oct 21, 2022Vulnerability in the wildCVE-2022-42889160
Google Launches GUAC Open Source Project to Secure Software Supply ChainThe Hacker News·Oct 20, 17:09 UTC · Oct 20, 2022Vulnerability42
Experts warn of critical flaws in Flexlan devices that provide WiFi on airplanesSecurity Affairs·Sep 19, 05:05 UTC · Sep 19, 2022VulnerabilityCVE-2022-36158CVE-2022-3615960
Hackers Targeting WebLogic Servers and Docker APIs for Mining CryptocurrenciesThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2022Vulnerability in the wildCVE-2022-26134CVE-2020-14882160
Researchers analyzed a JavaScript skimmer used by MagecartSecurity Affairs·Sep 1, 21:10 UTC · Sep 1, 2022Vulnerability30