36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsThe Hacker News·Apr 6, 06:40 UTC · Apr 6, 2026Vulnerability142
The AI security crisis no one is preparing forHelp Net Security·Aug 20, 00:00 UTC · Aug 20, 2025Vulnerability55
Azure AD Credentials Exposed in Public App Settings FileInfosecurity Magazine·Sep 2, 16:00 UTC · Sep 2, 2025Vulnerability30
Crickets from Chirp Systems in Smart Lock Key LeakKrebs on Security·Apr 15, 00:00 UTC · Apr 15, 2024Vulnerability55
The Secret Vulnerability Finance Execs are MissingThe Hacker News·Feb 23, 14:40 UTC · Feb 23, 2023Vulnerability55
Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025Security Affairs·Jun 10, 13:37 UTC · Jun 10, 2026VulnerabilityCVE-2025-8088CVE-2018-2025047
New Cyber Operation Targets Italy: Digging Into the Netwire Attack ChainSecurity Affairs·Jun 5, 18:26 UTC · Jun 5, 2020Vulnerability30
Expert found multiple critical issues in MoFi routersSecurity Affairs·Sep 8, 15:13 UTC · Sep 8, 2020VulnerabilityCVE-2020-15835CVE-2020-1583660
MDhex vulnerabilities open GE Healthcare patient monitoring devices to attackersHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2020VulnerabilityCVE-2020-6961CVE-2020-6962CVE-2020-6963+3 CVEs60
TP-Link Tapo L530E smart bulb flaws allow hackers to steal user passwordsSecurity Affairs·Aug 23, 07:09 UTC · Aug 23, 2023Vulnerability42
21,786 Home Cameras, No Password, No WarningSecurity Affairs·Jun 12, 08:35 UTC · Jun 12, 2026Vulnerability42
Chinese APT Weaver Ant infiltrated a telco for over four yearsSecurity Affairs·Mar 24, 20:36 UTC · Mar 24, 2025Vulnerability55
“Red October” Diplomatic Cyber Attacks InvestigationKaspersky Securelist·Jan 14, 17:00 UTC · Jan 14, 2013VulnerabilityCVE-2009-3129CVE-2010-3333CVE-2012-0158+1 CVEs47
Auto-Color Backdoor Malware Exploits SAP VulnerabilityInfosecurity Magazine·Jul 29, 15:10 UTC · Jul 29, 2025VulnerabilityCVE-2025-3132460
reNgine: Open-source automated reconnaissance framework for web applicationsHelp Net Security·May 2, 00:00 UTC · May 2, 2024Vulnerability30
Cycode’s new software supply chain features identify vulnerabilities in all phases of the SDLCHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2022Vulnerability42
Popular fintech apps expose valuable, exploitable secretsHelp Net Security·Apr 23, 13:38 UTC · Apr 23, 2026Vulnerability55
Widely used Trivy scanner compromised in ongoing supplyArs Technica · Security·Mar 20, 20:50 UTC · Mar 20, 2026Vulnerability42
The Fundamentals of Cloud Security Stress TestingThe Hacker News·May 8, 11:01 UTC · May 8, 2024Vulnerability55
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a PasswordSecurity Affairs·Jun 1, 11:36 UTC · Jun 1, 2026Vulnerability in the wildCVE-2026-873260
China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit HintsSecurity Affairs·Jun 17, 08:10 UTC · Jun 17, 2026VulnerabilityCVE-2023-2493247
RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)Help Net Security·Apr 14, 16:25 UTC · Apr 14, 2025Vulnerability in the wildCVE-2025-30406CVE-2025-3116160
Exposed training apps are showing up in active cloud attacksHelp Net Security·Jan 22, 00:00 UTC · Jan 22, 2026Vulnerability in the wild60
COMpfun successor Reductor infects files on the fly to compromise TLS trafficKaspersky Securelist·Oct 3, 10:00 UTC · Oct 3, 2019Vulnerability42
Over Half of Security Leaders Lack Confidence in Protecting App Secrets, Study RevealsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2023Vulnerability55
How exploit packs are concealed in a Flash objectKaspersky Securelist·Apr 22, 11:00 UTC · Apr 22, 2015VulnerabilityCVE-2013-2551CVE-2014-6332CVE-2014-0569+2 CVEs35
Quarian: Reversing the C&C ProtocolCisco Talos·Dec 6, 14:41 UTC · Dec 6, 2012VulnerabilityCVE-2010-018835
Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breachHelp Net Security·Sep 8, 11:32 UTC · Sep 8, 2025Vulnerability30
Cycldek: Bridging the (air) gapKaspersky Securelist·Jun 3, 10:00 UTC · Jun 3, 2020VulnerabilityCVE-2012-0158CVE-2017-11882CVE-2018-0802135
Hacker Runs Hermes AI Agent Unattended for PostThe Hacker News·Jul 24, 10:15 UTC · Jul 24, 2026VulnerabilityCVE-2026-31431CVE-2026-43284CVE-2026-43500+2 CVEs35
Securing modern web apps: A case for framework-aware SASTHelp Net Security·Jul 22, 00:00 UTC · Jul 22, 2019Vulnerability30
How to avoid the 4 main pitfalls of cloud identity managementHelp Net Security·Sep 28, 00:00 UTC · Sep 28, 2023Vulnerability55