North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm PackagesThe Hacker News·Jun 25, 09:20 UTC · Jun 25, 2025Vulnerability42
Over 70 Malicious npm and VS Code Packages Found Stealing Data and CryptoThe Hacker News·May 26, 15:12 UTC · May 26, 2025Vulnerability55
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat ActorsRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-5518260
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182)Help Net Security·Dec 4, 00:00 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Admins and defenders gird themselves against maximumArs Technica · Security·Dec 3, 23:16 UTC · Dec 3, 2025VulnerabilityCVE-2025-55182CVE-2025-6647847
Developers scramble as critical React flaw threatens major appsCyberScoop·Dec 3, 19:23 UTC · Dec 3, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-6647860