RubyGems 2.7.6 addresses several flaws and implements some improvementsSecurity Affairs·Feb 20, 18:08 UTC · Feb 20, 2018Vulnerability30
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
Cybercriminals Target Ethereum Developers with Fake Hardhat npm PackagesThe Hacker News·Jan 6, 11:09 UTC · Jan 6, 2025Vulnerability55
Week in review: Cloud migration and cybersecurity, data trending on the dark web, Zoom securityHelp Net Security·Apr 19, 00:00 UTC · Apr 19, 2020Vulnerability in the wildCVE-2020-395260
What public money does to open-source projectsHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026Vulnerability55
GitHub dismissed security reports on flaws now exploited by supplyThe Record·Jun 17, 08:52 UTC · Jun 17, 2026Vulnerability42
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New StoriesThe Hacker News·Jun 12, 05:36 UTC · Jun 12, 2026Vulnerability142
Hackers target AI and crypto as software supply chain risks growHelp Net Security·Dec 3, 14:29 UTC · Dec 3, 2025Vulnerability in the wild60
Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH KeysThe Hacker News·Sep 21, 03:53 UTC · Sep 21, 2023Vulnerability42
Open source vulnerabilities add to security debtHelp Net Security·Dec 19, 00:00 UTC · Dec 19, 2022Vulnerability42
Malicious NPM Package Caught Mimicking Material Tailwind CSS PackageThe Hacker News·Sep 24, 04:54 UTC · Sep 24, 2022Vulnerability42
Google Launches New Open Source Bug Bounty to Tackle Supply Chain AttacksThe Hacker News·Sep 1, 03:01 UTC · Sep 1, 2022Vulnerability55
Code Execution Bug Affects Yamale Python Package — Used by Over 200 ProjectsThe Hacker News·Oct 7, 11:50 UTC · Oct 7, 2021VulnerabilityCVE-2021-3830547
Dependency Confusion: Another Supply-Chain VulnerabilitySchneier on Security·Mar 15, 13:39 UTC · Mar 15, 2021Vulnerability42
Dependency Confusion Supply-Chain Attack Hit Over 35 HighThe Hacker News·Feb 10, 12:57 UTC · Feb 10, 2021Vulnerability42
Backdoor vulnerability in open source tool exposes thousands of apps to remote code executionCyberScoop·Apr 4, 20:51 UTC · Apr 4, 2019Vulnerability in the wild60