ENISA Technical Advisory on Secure Package Managers: Essential DevSecOps GuidanceSecurity Affairs·Mar 12, 08:49 UTC · Mar 12, 2026AdvisoryCVE-2025-5518260
Critical flaw in Linux APT package manager could allow remote hackSecurity Affairs·Jan 22, 21:00 UTC · Jan 22, 2019Exploit / PoCCVE-2019-346260
Critical Gems Takeover Bug Reported in RubyGems Package ManagerThe Hacker News·May 11, 02:45 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-2917660
Researchers find hidden vulnerabilities in hundreds of Docker containersHelp Net Security·Feb 23, 00:00 UTC · Feb 23, 2023Vulnerability in the wildCVE-2021-42013CVE-2021-41773CVE-2019-17558160
Critical RCE Bug Found in Homebrew Package Manager for macOS and LinuxThe Hacker News·Apr 26, 07:33 UTC · Apr 26, 2021Vulnerability55
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-26127160
New Linux Privilege Escalation Flaw Uncovered in Snap Package ManagerThe Hacker News·Feb 18, 08:37 UTC · Feb 18, 2022VulnerabilityCVE-2021-44731CVE-2021-3995CVE-2021-3996+4 CVEs60
The serpent’s tongue: Luring the Python out of its denCisco Talos·Jul 14, 10:00 UTC · Jul 14, 2026Malware155
PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and BunSecurity Affairs·Jan 28, 08:43 UTC · Jan 28, 2026Exploit / PoC160
Flaw in the Packagist PHP repository could have allowed a supply chain attackSecurity Affairs·Oct 4, 20:19 UTC · Oct 4, 2022Exploit / PoC in the wildCVE-2022-24828CVE-2021-2947260
Developer Workstations Are Now Part of the Software Supply ChainThe Hacker News·May 18, 11:23 UTC · May 18, 2026Threat actor160
Zero-day Exploit Found in Adobe Experience ManagerInfosecurity Magazine·Jun 28, 17:18 UTC · Jun 28, 2021Exploit / PoC60
The Linux Foundation's Census of OSS app libraries helps prioritize security workHelp Net Security·Mar 3, 00:00 UTC · Mar 3, 2022Industry55
GitHub flaw could have allowed attackers to takeover repositories of other usersSecurity Affairs·Oct 31, 12:11 UTC · Oct 31, 2022Vulnerability55
Critical RCE flaw patched in Packagist PHP package repositorySecurity Affairs·Sep 3, 13:28 UTC · Sep 3, 2018Vulnerability55
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
Google Fixes GCP Composer Flaw That Could've Led to Remote Code ExecutionThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2024Vulnerability55
Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm serversHelp Net Security·Apr 24, 00:00 UTC · Apr 24, 2026Vulnerability55
CISA and OpenSSF Release Framework for Package Repository SecurityThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability55
Sonatype Reports 156% Increase in OSS Malicious PackagesInfosecurity Magazine·Oct 11, 11:00 UTC · Oct 11, 2024Vulnerability55
Debunking myths about open-source securityHelp Net Security·Nov 20, 00:00 UTC · Nov 20, 2024Vulnerability55
Pileup flaws in Android PMS menace more than 1 Billion devicesSecurity Affairs·Mar 25, 07:54 UTC · Mar 25, 2014Data breach60
Wormable bash DarkRadiation Ransomware targets Linux distrosSecurity Affairs·Jun 22, 20:59 UTC · Jun 22, 2021Ransomware60
Researchers uncover remote code execution flaw in abandoned Rust code libraryCyberScoop·Oct 21, 20:25 UTC · Oct 21, 2025VulnerabilityCVE-2025-62518160
Traefik Labs introduces Distro Zero secure runtime for API and AI gatewaysHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2026Vulnerability55
PyPI Blocks 1,800 Expired-Domain Emails to Prevent Account Takeovers and Supply Chain AttacksThe Hacker News·Aug 19, 17:29 UTC · Aug 19, 2025Threat actor160
Software vulnerabilities push credential abuse aside in cloud intrusionsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2026Vulnerability in the wild60
Shai-Hulud worm returns stronger and more automated than ever beforeCyberScoop·Nov 24, 22:45 UTC · Nov 24, 2025Data breach in the wild60
Threat Brief: OMI Vulnerabilities (CVE-2021-38645, CVE-2021-38647, CVE-2021-38648 and CVE-2021Palo Alto Unit 42·Jun 6, 01:21 UTC · Jun 6, 2024VulnerabilityCVE-2021-38645CVE-2021-38647CVE-2021-38648+1 CVEs160
Grinch Bug Could be worse than Shellshock, Says ExpertsSecurity Affairs·Nov 5, 23:20 UTC · Nov 5, 2018Exploit / PoC in the wild60
A New PHP Composer Bug Could Enable Widespread SupplyThe Hacker News·Apr 29, 15:27 UTC · Apr 29, 2021VulnerabilityCVE-2021-2947260
ShiftLeft announces code-informed runtime protection for Microsoft’s .Net FrameworkHelp Net Security·Sep 27, 00:00 UTC · Sep 27, 2018Vulnerability155
Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal CredentialsThe Hacker News·May 15, 00:00 UTC · May 15, 2025Malware155
Hackers target AI and crypto as software supply chain risks growHelp Net Security·Dec 3, 14:29 UTC · Dec 3, 2025Vulnerability in the wild60
Critical RCE Bug Affects Millions of OpenWrtThe Hacker News·Mar 24, 20:06 UTC · Mar 24, 2020VulnerabilityCVE-2020-798260
Dozens of Vulnerable NuGet Packages Allow Attackers to Target .NET PlatformThe Hacker News·Jul 8, 07:40 UTC · Jul 8, 2021Vulnerability in the wildCVE-2021-3331CVE-2016-9840CVE-2016-9841+2 CVEs60
Software supply chain attacks are getting easierHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2024Malware55
WatchGuard Firebox T Series firewalls: Heightened HTTPS throughput, security services, SD-WANHelp Net Security·Jun 11, 00:00 UTC · Jun 11, 2020Ransomware60
phpMyAdmin Releases Critical Software Update — Patch Your Sites Now!The Hacker News·Dec 11, 15:49 UTC · Dec 11, 2018VulnerabilityCVE-2018-19968CVE-2018-19969CVE-2018-1997060
10 Credential Stealing Python Libraries Found on PyPI RepositoryThe Hacker News·Aug 10, 05:22 UTC · Aug 10, 2022Malware55