Friday Squid Blogging: Firefly Squid MuseumSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Vulnerability30
Researchers disclosed a remote code execution flaw in Fastjson LibrarySecurity Affairs·Jun 16, 10:14 UTC · Jun 16, 2022VulnerabilityCVE-2022-2584547
Apache Struts 2.3.x vulnerable to two year old RCE flawHelp Net Security·Dec 15, 12:31 UTC · Dec 15, 2023VulnerabilityCVE-2016-100003160
Repairnator bot finds software bugs, successfully submits patchesHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2018Vulnerability30
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableThe Hacker News·Jul 25, 12:54 UTC · Jul 25, 2026Vulnerability in the wildCVE-2026-1672360
Zero trust: How the ‘Jia Tan’ hack complicated openCyberScoop·Aug 15, 13:00 UTC · Aug 15, 2024Vulnerability42
Hackers Started Exploiting Critical "Text4Shell" Apache Commons Text VulnerabilityThe Hacker News·Oct 24, 05:48 UTC · Oct 24, 2022Vulnerability in the wildCVE-2022-42889CVE-2022-3398060
Software Supply Chain Attacks Soar 742% in Three YearsInfosecurity Magazine·Oct 19, 09:30 UTC · Oct 19, 2022Vulnerability42
More than 35,000 Java packages impacted by Log4j flaw, Google warnsSecurity Affairs·Dec 21, 09:46 UTC · Dec 21, 2021VulnerabilityCVE-2021-4504660
Dependency-Track: Open-source component analysis platformHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2025Vulnerability42
Vet: Open-source software supply chain security toolHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2025Vulnerability42
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerThe Hacker News·Jun 30, 11:18 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-48558260
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4855860
New Google tool reveals dependencies for open source projectsHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2021Vulnerability42
Open Source Updates Have 75% Chance of Breaking AppsInfosecurity Magazine·Sep 12, 10:00 UTC · Sep 12, 2024Vulnerability30
Unauthenticated RCE in H2 Database Console is similar to Log4ShellSecurity Affairs·Jan 8, 19:53 UTC · Jan 8, 2022VulnerabilityCVE-2021-42392CVE-2021-4422860
Open source cyberattacks increasing by 650%, popular projects more vulnerableHelp Net Security·Sep 17, 00:00 UTC · Sep 17, 2021Vulnerability55
Google Launches New Open Source Bug Bounty to Tackle Supply Chain AttacksThe Hacker News·Sep 1, 03:01 UTC · Sep 1, 2022Vulnerability55
The Log4j saga: New vulnerabilities and attack vectors discoveredHelp Net Security·Dec 20, 00:00 UTC · Dec 20, 2021VulnerabilityCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs47
GitLab 18 increases developer productivity by integrating AI throughout the platformHelp Net Security·May 15, 00:00 UTC · May 15, 2025Vulnerability155
Google delivers secure open source software packagesHelp Net Security·Apr 13, 00:00 UTC · Apr 13, 2023Vulnerability55
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security·May 17, 00:00 UTC · May 17, 2026Vulnerability in the wildCVE-2026-44413CVE-2026-41940CVE-2026-46300+2 CVEs160
Software Supply Chain Attacks Surge 650% in a YearInfosecurity Magazine·Sep 15, 14:00 UTC · Sep 15, 2021Vulnerability55
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent PatchThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025VulnerabilityCVE-2025-66516CVE-2025-5498860
OpenSSF adds new members from around the globe to improve OSS securityHelp Net Security·Apr 17, 12:42 UTC · Apr 17, 2026Vulnerability55
OpenSSF announces 15 new members to tackle supply chain security challengesHelp Net Security·May 11, 00:00 UTC · May 11, 2022Vulnerability55
Upstream Supply Chain Attacks Triple in a YearInfosecurity Magazine·Oct 3, 14:00 UTC · Oct 3, 2023Vulnerability55
Transitive Dependencies Account for 95% of BugsInfosecurity Magazine·Dec 12, 11:35 UTC · Dec 12, 2022Vulnerability55