JFrog receives CNA certification to help security researchers verify and triage their vulnerabilitiesHelp Net Security·Oct 28, 11:40 UTC · Oct 28, 2021Vulnerability55
Researchers Warn of New Log4ShellInfosecurity Magazine·Jan 7, 09:26 UTC · Jan 7, 2022VulnerabilityCVE-2021-4239260
Experts found 14 new flaws in BusyBoxSecurity Affairs·Nov 10, 11:38 UTC · Nov 10, 2021VulnerabilityCVE-2021-42373CVE-2021-42374CVE-2021-42375+11 CVEs60
Critical CVEs in Chaos-Mesh Enable InInfosecurity Magazine·Sep 17, 16:00 UTC · Sep 17, 2025VulnerabilityCVE-2025-59358CVE-2025-59360CVE-2025-59361+1 CVEs60
Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster TakeoverThe Hacker News·Sep 17, 06:14 UTC · Sep 17, 2025VulnerabilityCVE-2025-59358CVE-2025-59359CVE-2025-59360+1 CVEs60
Researchers Uncover Flaws in Popular OpenThe Hacker News·Dec 6, 11:28 UTC · Dec 6, 2024VulnerabilityCVE-2024-27132CVE-2024-6960CVE-2023-524560
High-Severity Access Control Vulnerability Found in Spring WebFluxInfosecurity Magazine·Aug 9, 16:30 UTC · Aug 9, 2023VulnerabilityCVE-2023-3403460
A 10-point plan to improve the security of open source softwareHelp Net Security·Jan 19, 11:46 UTC · Jan 19, 2023Vulnerability55
INFRA:HALT vulnerabilities affect OT devices from more than 200 vendorsThe Record·Jan 18, 00:00 UTC · Jan 18, 2023VulnerabilityCVE-2020-25928CVE-2021-3122660
Popular open-source PJSIP library is affected by critical flawsSecurity Affairs·Mar 2, 22:41 UTC · Mar 2, 2022VulnerabilityCVE-2021-43299CVE-2021-43300CVE-2021-43301+2 CVEs60
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More StoriesThe Hacker News·Jan 19, 06:25 UTC · Jan 19, 2026VulnerabilityCVE-2025-62507CVE-2025-23304CVE-2026-22584160
Critical PickleScan Vulnerabilities Expose AI Model Supply ChainsInfosecurity Magazine·Dec 2, 16:00 UTC · Dec 2, 2025VulnerabilityCVE-2025-10155CVE-2025-10156CVE-2025-1015760
Cybersecurity jobs available right now: May 6, 2025Help Net Security·Aug 28, 10:13 UTC · Aug 28, 2025Vulnerability55
Attackers can bypass middleware auth checks by exploiting critical Next.js flawSecurity Affairs·Mar 24, 11:22 UTC · Mar 24, 2025VulnerabilityCVE-2025-2992760
Experts warn of need to patch critical cryptographic Java bugThe Record·Jan 12, 00:00 UTC · Jan 12, 2023VulnerabilityCVE-2022-2144960
Researchers Find a Way Malicious NPM Libraries Can Evade Vulnerability DetectionThe Hacker News·Dec 1, 09:22 UTC · Dec 1, 2022Vulnerability55
Critical Bugs Reported in Popular Open Source PJSIP SIP and Media StackThe Hacker News·Mar 2, 07:10 UTC · Mar 2, 2022VulnerabilityCVE-2021-43299CVE-2021-43300CVE-2021-43301+2 CVEs60
Log4Shell-like Critical RCE Flaw Discovered in H2 Database ConsoleThe Hacker News·Jan 12, 07:56 UTC · Jan 12, 2022VulnerabilityCVE-2021-4239260
Unauthenticated RCE in H2 Database Console is similar to Log4ShellSecurity Affairs·Jan 8, 19:53 UTC · Jan 8, 2022VulnerabilityCVE-2021-42392CVE-2021-4422860
14 New Security Flaws Found in BusyBox Linux Utility for Embedded DevicesThe Hacker News·Nov 10, 08:08 UTC · Nov 10, 2021VulnerabilityCVE-2021-42373CVE-2021-42386CVE-2021-42374+11 CVEs60
INFRA:HALT flaws impact OT devices from hundreds of vendorsSecurity Affairs·Aug 4, 12:52 UTC · Aug 4, 2021Vulnerability55
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm PackageThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-11953160
Critical and High Severity n8n Sandbox Flaws Allow RCEInfosecurity Magazine·Jan 28, 16:00 UTC · Jan 28, 2026VulnerabilityCVE-2026-1470CVE-2026-086360
Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute CodeThe Hacker News·Dec 3, 11:44 UTC · Dec 3, 2025VulnerabilityCVE-2025-10155CVE-2025-10156CVE-2025-10157+1 CVEs60
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential TheftThe Hacker News·Nov 25, 03:51 UTC · Nov 25, 2025Vulnerability55
Critical React Native CLI Flaw Exposed Millions of Developers to Remote AttacksThe Hacker News·Nov 4, 14:24 UTC · Nov 4, 2025VulnerabilityCVE-2025-1195360
Week in review: Several companies affected by the Salesloft Drift breach, Sitecore 0-day vulnerabilityHelp Net Security·Sep 7, 00:00 UTC · Sep 7, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-24204CVE-2025-48543+2 CVEs60
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ DownloadsThe Hacker News·Jul 11, 04:05 UTC · Jul 11, 2025VulnerabilityCVE-2025-6514CVE-2025-49596CVE-2025-53110+1 CVEs60
Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization ChecksThe Hacker News·Mar 25, 03:16 UTC · Mar 25, 2025VulnerabilityCVE-2025-2992760
New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol SecurityThe Hacker News·Jan 4, 08:25 UTC · Jan 4, 2024VulnerabilityCVE-2023-4879560
Variscite enhances IoT and edge security with over-the-air software updatesHelp Net Security·May 5, 00:00 UTC · May 5, 2022Vulnerability55
HAProxy Found Vulnerable to Critical HTTP Request Smuggling AttackThe Hacker News·Sep 8, 12:33 UTC · Sep 8, 2021VulnerabilityCVE-2021-4034660
Critical Flaws Affect Embedded TCP/IP Stack Widely Used in Industrial Control DevicesThe Hacker News·Aug 4, 09:02 UTC · Aug 4, 2021VulnerabilityCVE-2020-25928CVE-2021-31226CVE-2020-25927+11 CVEs60