Necro Python bot adds new exploits and Tezos mining to its bag of tricksCisco Talos·Jun 3, 12:00 UTC · Jun 3, 2021VulnerabilityCVE-2021-3129CVE-2020-14882CVE-2017-014447
Legacy Python Bootstrap Scripts Create DomainThe Hacker News·Dec 1, 04:21 UTC · Dec 1, 2025VulnerabilityCVE-2023-45311147
PyTorch compromised to demonstrate dependency confusion attack on Python environmentsSecurity Affairs·Jan 2, 18:57 UTC · Jan 2, 2023Vulnerability142
Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of DevelopersThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Vulnerability142
Hackers Distributing Malicious Python Packages via Popular Developer Q&A PlatformThe Hacker News·Aug 3, 03:47 UTC · Aug 3, 2024Vulnerability142
Python URL parsing function flaw can enable command executionSecurity Affairs·Aug 12, 16:40 UTC · Aug 12, 2023VulnerabilityCVE-2023-24329147
Malicious Python Package Uses Unicode Trickery to Evade Detection and Steal DataThe Hacker News·Mar 24, 13:40 UTC · Mar 24, 2023Vulnerability142
Warning: PyPI Feature Executes Code Automatically After Python Package DownloadThe Hacker News·Sep 11, 04:06 UTC · Sep 11, 2022Vulnerability142
Code Execution Bug Affects Yamale Python Package — Used by Over 200 ProjectsThe Hacker News·Oct 7, 11:50 UTC · Oct 7, 2021VulnerabilityCVE-2021-3830547
Severe bug in LibreOffice and OpenOffice suites allows remote code executionSecurity Affairs·Feb 5, 15:14 UTC · Feb 5, 2019VulnerabilityCVE-2018-1685847
Python packages caught attempting to steal Discord tokens, credit card numbersThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Vulnerability42
15-Year-Old Unpatched Python Vulnerability Potentially Affects Over 350,000 ProjectsThe Hacker News·Sep 23, 04:29 UTC · Sep 23, 2022VulnerabilityCVE-2007-4559CVE-2022-30333147
PurpleBravo’s Targeting of the IT Software Supply ChainRecorded Future·Jul 22, 00:00 UTC · Jul 22, 2026Vulnerability42
PlushDaemon APT Targets South Korean VPN Provider in Supply Chain AttackThe Hacker News·Jan 24, 05:24 UTC · Jan 24, 2025Vulnerability42
New Python URL Parsing Flaw Could Enable Command Execution AttacksThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2023VulnerabilityCVE-2023-2432947
Severe RCE Flaw Disclosed in Popular LibreOffice and OpenOffice SoftwareThe Hacker News·Feb 5, 11:28 UTC · Feb 5, 2019VulnerabilityCVE-2018-1685847
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing OpenThe Hacker News·Jun 4, 10:11 UTC · Jun 4, 2025Vulnerability142
How to create SBOMs for container imagesHelp Net Security·Jun 21, 00:00 UTC · Jun 21, 2023Vulnerability42
New Python-Based "Legion" Hacking Tool Emerges on TelegramThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2023Vulnerability42
LibreOffice users have to know that their unpatched computers could be hacked by simply opening a specially crafted document.Security Affairs·Jul 26, 18:10 UTC · Jul 26, 2019VulnerabilityCVE-2019-9848CVE-2019-984947
This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch VulnerabilitiesRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2015-142747
Malicious macros can trigger RCE in LibreOffice, OpenOfficeHelp Net Security·Feb 7, 00:00 UTC · Feb 7, 2019VulnerabilityCVE-2018-1685847
PyRoMineIoT spreads via EternalRomance exploit and targets targets IoT devices in Iran and Saudi Arabia.Security Affairs·Jun 15, 10:03 UTC · Jun 15, 2018Vulnerability42
Energetic Bear/Crouching Yeti: attacks on serversKaspersky Securelist·Apr 23, 10:00 UTC · Apr 23, 2018Vulnerability42
Vulnerability Spotlight: YAML Parsing Remote Code Execution Vulnerabilities in Ansible Vault and TablibCisco Talos·Sep 14, 14:30 UTC · Sep 14, 2017Vulnerability in the wildCVE-2017-2809CVE-2017-2810160
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsThe Hacker News·Apr 6, 06:40 UTC · Apr 6, 2026Vulnerability142
Experts found potential remote code execution in PyPISecurity Affairs·Aug 3, 08:27 UTC · Aug 3, 2021Vulnerability42
Full Analysis of Flame’s Command & Control serversKaspersky Securelist·Sep 17, 17:00 UTC · Sep 17, 2012Vulnerability42
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New StoriesThe Hacker News·Jun 12, 05:36 UTC · Jun 12, 2026Vulnerability142
Two High-Severity n8n Flaws Allow Authenticated Remote Code ExecutionThe Hacker News·Jan 29, 16:54 UTC · Jan 29, 2026VulnerabilityCVE-2026-1470CVE-2026-0863CVE-2026-2185847
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse ConcernsThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Vulnerability in the wild157
Shell No! Adversary Web Shell Trends and Mitigations (Part 1)Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk AnalysisRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2016-3081CVE-2015-2419CVE-2015-4852+1 CVEs47
Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and ProxywareThe Hacker News·Jun 2, 10:07 UTC · Jun 2, 2025VulnerabilityCVE-2025-32432CVE-2021-44228CVE-2022-26134+1 CVEs47
Researchers Identify Over 20 Supply Chain Vulnerabilities in MLOps PlatformsThe Hacker News·Aug 28, 03:53 UTC · Aug 28, 2024VulnerabilityCVE-2024-27132CVE-2023-48022CVE-2023-46229+1 CVEs47
Learn Ethical Hacking From Scratch — 2019 Training BundleThe Hacker News·Jul 23, 13:57 UTC · Jul 23, 2019Vulnerability42
Vulnerability Spotlight: Python.org certificate parsing denial-ofCisco Talos·Jan 28, 19:12 UTC · Jan 28, 2019Vulnerability in the wildCVE-2018-501060