Bullying in Open Source Software Is a Massive Security Vulnerability404 Media·Apr 5, 18:40 UTC · Apr 5, 2024Vulnerability42
LibreOffice: Stability, security, and continued developmentHelp Net Security·Sep 7, 00:00 UTC · Sep 7, 2023Vulnerability42
Open Source Flaws Found in 84% of CodebasesInfosecurity Magazine·Feb 22, 17:00 UTC · Feb 22, 2023Vulnerability142
Google touts new tool that scans for malicious packages in popular openThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Tools142
New Google tool reveals dependencies for open source projectsHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2021Vulnerability42
Open Raven raises $15M to accelerate growth through expansion of key functionsHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2020Data breach57
VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSXThe Hacker News·Jan 6, 14:17 UTC · Jan 6, 2026Threat actor57
The Solidity Language open-source package was used in a $500,000 crypto heistKaspersky Securelist·Jul 10, 11:00 UTC · Jul 10, 2025Malware42
Open-source security challenges and complexitiesHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2023Vulnerability42
Open source projects under attack, with enterprises as the ultimate targetsHelp Net Security·Sep 27, 00:00 UTC · Sep 27, 2022Vulnerability42
Google bug bounty program now covers Open Source projectsSecurity Affairs·Aug 30, 16:51 UTC · Aug 30, 2022Vulnerability142
Adversary Infrastructure Report 2020: A Defender’s ViewRecorded Future·Jan 2, 00:00 UTC · Jan 2, 2026Ransomware57
Security Issue in JWT Secret Poisoning (Updated)Palo Alto Unit 42·Jun 5, 17:06 UTC · Jun 5, 2024VulnerabilityCVE-2022-2352947
VMware Telco Cloud Platform RAN enables CSPs to virtualize RAN functionsHelp Net Security·Feb 5, 13:12 UTC · Feb 5, 2024Industry42
Attack on French Diplomat Linked to Operation Lotus BlossomPalo Alto Unit 42·Nov 1, 09:57 UTC · Nov 1, 2018Exploit / PoCCVE-2014-633260
High-Severity Flaw in Open WebUI Affects AI ConnectionsInfosecurity Magazine·Jan 6, 15:30 UTC · Jan 6, 2026VulnerabilityCVE-2025-6449647
Google invites bug hunters to scrutinize its open source projectsHelp Net Security·Aug 31, 00:00 UTC · Aug 31, 2022Vulnerability42
Defcon's new badge is a security key you can see insideArs Technica · Security·Aug 1, 10:05 UTC · Aug 1, 2026Vulnerability42
Multi-patch vulnerability fixes can leave open source exposedHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026VulnerabilityCVE-2012-0038CVE-2023-4226CVE-2022-252247
CVE Lite CLI: Open-source dependency vulnerability scannerHelp Net Security·May 20, 00:00 UTC · May 20, 2026Vulnerability42
HEIDI: Free IDE security plugin for open-source vulnerability checksHelp Net Security·May 12, 00:00 UTC · May 12, 2026Vulnerability42
Global Threat Map: Open-source real-time situational awareness platformHelp Net Security·Feb 4, 00:00 UTC · Feb 4, 2026Malware42
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWormThe Hacker News·Feb 2, 15:31 UTC · Feb 2, 2026Malware42
CISA warns federal agencies of exploited Google Chrome and openThe Record·Jan 3, 21:36 UTC · Jan 3, 2024Advisory in the wildCVE-2023-7101CVE-2023-702460
Rogue npm Package Deploys Open-Source Rootkit in New Supply Chain AttackThe Hacker News·Oct 6, 08:35 UTC · Oct 6, 2023Malware42
SapphireStealer: Open-source information stealer enables credential and data theftCisco Talos·Aug 31, 12:00 UTC · Aug 31, 2023Malware142
The state of open-source software supply chain security in 2022Help Net Security·Jun 26, 09:19 UTC · Jun 26, 2023Industry42
Open Source Repository Attacks Soar 700% in Three YearsInfosecurity Magazine·Sep 21, 09:25 UTC · Sep 21, 2022Vulnerability42
Google Launches Major Open Source Bug Bounty ProgramInfosecurity Magazine·Aug 30, 12:00 UTC · Aug 30, 2022Vulnerability42
Here's a New Tool That Scans Open-Source Repositories for Malicious PackagesThe Hacker News·May 3, 03:59 UTC · May 3, 2022Malware42
Veridas opens new offices in USA and Mexico to facilitate its operationsHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2022Policy & legal42
CyberRes acquires Debricked to expand software supply chain securityHelp Net Security·Mar 16, 00:00 UTC · Mar 16, 2022Vulnerability42
Vulnerability Spotlight: DoS, code execution vulnerabilities in EIP Stack Group OpENerCisco Talos·Dec 2, 21:21 UTC · Dec 2, 2020Vulnerability in the wildCVE-2020-13530CVE-2020-1355660
Number of open source vulnerabilities surged in 2019Help Net Security·Mar 13, 00:00 UTC · Mar 13, 2020Vulnerability42
Hacker held open MongoDB databases for ransomSecurity Affairs·Oct 2, 09:32 UTC · Oct 2, 2017Ransomware57
How software development's speed obsession enabled TeamPCP’s chaos crusadeCyberScoop·Jun 18, 23:03 UTC · Jun 18, 2026Ransomware157
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target DevelopersThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware42
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX ExtensionsThe Hacker News·Feb 4, 06:26 UTC · Feb 4, 2026Malware42
Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz DiscoveryThe Hacker News·Nov 6, 04:40 UTC · Nov 6, 2025Malware42
Villain: Open-source framework for managing and enhancing reverse shellsHelp Net Security·Apr 30, 00:00 UTC · Apr 30, 2025Industry142