RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
GitHub dismissed security reports on flaws now exploited by supplyThe Record·Jun 17, 08:52 UTC · Jun 17, 2026Vulnerability42
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New StoriesThe Hacker News·Jun 12, 05:36 UTC · Jun 12, 2026Vulnerability142
Fresh Wave of Malicious npm Packages Threaten Kubernetes Configs and SSH KeysThe Hacker News·Sep 21, 03:53 UTC · Sep 21, 2023Vulnerability42
Open source vulnerabilities add to security debtHelp Net Security·Dec 19, 00:00 UTC · Dec 19, 2022Vulnerability42
Malicious NPM Package Caught Mimicking Material Tailwind CSS PackageThe Hacker News·Sep 24, 04:54 UTC · Sep 24, 2022Vulnerability42
Code Execution Bug Affects Yamale Python Package — Used by Over 200 ProjectsThe Hacker News·Oct 7, 11:50 UTC · Oct 7, 2021VulnerabilityCVE-2021-3830547
Dependency Confusion: Another Supply-Chain VulnerabilitySchneier on Security·Mar 15, 13:39 UTC · Mar 15, 2021Vulnerability42
Dependency Confusion Supply-Chain Attack Hit Over 35 HighThe Hacker News·Feb 10, 12:57 UTC · Feb 10, 2021Vulnerability42