North Korea-Linked Hackers Target Developers via Malicious VS Code ProjectsThe Hacker News·Feb 26, 10:15 UTC · Feb 26, 2026Vulnerability42
Data-stealing VS Code extensions removed from official MarketplaceHelp Net Security·May 21, 00:00 UTC · May 21, 2025Vulnerability42
VS Code extensions with 125M+ installs expose users to cyberattacksSecurity Affairs·Feb 18, 15:14 UTC · Feb 18, 2026VulnerabilityCVE-2025-65715CVE-2025-65716CVE-2025-65717160
Over 70 Malicious npm and VS Code Packages Found Stealing Data and CryptoThe Hacker News·May 26, 15:12 UTC · May 26, 2025Vulnerability55
Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth TokensThe Hacker News·Jun 6, 08:09 UTC · Jun 6, 2026Vulnerability130
Open VSX Bug Let Malicious VS Code Extensions Bypass PreThe Hacker News·Mar 27, 13:57 UTC · Mar 27, 2026Vulnerability30
Flaws in Popular IDE Extensions Allow Data ExfiltrationInfosecurity Magazine·Feb 19, 10:45 UTC · Feb 19, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-6571560
Critical Flaws Found in Four VS Code Extensions with Over 125 Million InstallsThe Hacker News·Feb 18, 13:16 UTC · Feb 18, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-65715160
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsThe Hacker News·Apr 6, 06:40 UTC · Apr 6, 2026Vulnerability142
Taking over millions of developers exploiting an Open VSX Registry flawSecurity Affairs·Jun 27, 19:37 UTC · Jun 27, 2025Vulnerability55
Microsoft Expands Sentinel Into Agentic Security Platform With Unified Data LakeThe Hacker News·Oct 2, 04:51 UTC · Oct 2, 2025Vulnerability130
Reporting from Vegas: Networking, AI, and good boysCisco Talos·Jun 4, 18:00 UTC · Jun 4, 2026Vulnerability42
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromiseHelp Net Security·May 21, 00:00 UTC · May 21, 2026Vulnerability142
#DEFCON: Electrovolt Exploits Against Electron Desktop Apps ExposedInfosecurity Magazine·Aug 16, 15:00 UTC · Aug 16, 2022VulnerabilityCVE-2021-4390847
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package AdoptionThe Hacker News·Jul 27, 08:01 UTC · Jul 27, 2026Vulnerability142
Miasma Supply Chain Attack Compromises Red Hat npm Packages with CredentialThe Hacker News·Jun 2, 08:55 UTC · Jun 2, 2026Vulnerability42
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News·Jun 9, 05:50 UTC · Jun 9, 2026Vulnerability142
Product Walkthrough: How Mesh CSMA Reveals and Breaks Attack Paths to Crown JewelsThe Hacker News·Mar 18, 14:49 UTC · Mar 18, 2026Vulnerability55
GitLab Duo Agent Platform solves the AI paradox in software deliveryHelp Net Security·Jan 16, 00:00 UTC · Jan 16, 2026Vulnerability130
Patch Tuesday, February 2026 EditionKrebs on Security·Feb 11, 03:47 UTC · Feb 11, 2026VulnerabilityCVE-2026-21510CVE-2026-21513CVE-2026-21514+7 CVEs160
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security·Feb 15, 00:00 UTC · Feb 15, 2026Vulnerability in the wildCVE-2026-1731CVE-2024-12356CVE-2026-1281+2 CVEs60
Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain AttacksThe Hacker News·Jun 27, 05:04 UTC · Jun 27, 2025Vulnerability55
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs60
Microsoft Patches Record 622 Flaws, Including Two ZeroThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2026-56164CVE-2026-56155CVE-2026-50661+6 CVEs60
CodeBuild Flaw Put AWS Console Supply Chain At RiskInfosecurity Magazine·Jan 15, 15:00 UTC · Jan 15, 2026Vulnerability in the wild160
Behind the code: How developers work in 2025Help Net Security·Jul 11, 00:00 UTC · Jul 11, 2025Vulnerability130
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacksHelp Net Security·Mar 27, 10:18 UTC · Mar 27, 2026Vulnerability42
Side-Channel Attacks Against LLMsSchneier on Security·Mar 14, 11:28 UTC · Mar 14, 2026Vulnerability30
Unpatched SolarWinds WHD instances under active attackHelp Net Security·Mar 9, 17:22 UTC · Mar 9, 2026Vulnerability in the wildCVE-2025-2639960
An XSS flaw in GitLab allows attackers to take over accountsSecurity Affairs·May 24, 20:39 UTC · May 24, 2024Vulnerability in the wildCVE-2024-4835CVE-2023-7028160
42Crunch launches new self-registration feature for its API Security PlatformHelp Net Security·Feb 26, 00:00 UTC · Feb 26, 2020Vulnerability30
Paid open-source maintainers spend more time on securityHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2024Vulnerability55
Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious RepositoriesThe Hacker News·Sep 12, 04:49 UTC · Sep 12, 2025VulnerabilityCVE-2025-52882CVE-2025-48757247
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Why Patch Management Isn’t Enough: SharePoint, Webshells & the Modern Threat LandscapeRecorded Future·Aug 11, 00:00 UTC · Aug 11, 2025VulnerabilityCVE-2023-4724660
Azul Vulnerability Detection uncovers known vulnerabilities in Java applicationsHelp Net Security·Nov 3, 00:00 UTC · Nov 3, 2022Vulnerability155
Dynamic binary instrumentation (DBI) with DynamoRioCisco Talos·Oct 30, 09:59 UTC · Oct 30, 2025Vulnerability55
Kazakhstan-associated YoroTrooper disguises origin of attacks as AzerbaijanCisco Talos·Oct 25, 12:01 UTC · Oct 25, 2023Vulnerability30
New Relic empowers IT and engineering teams to focus on real application security problemsHelp Net Security·Mar 13, 00:00 UTC · Mar 13, 2024Vulnerability30