Malicious Open Source Packages Surge 188% AnnuallyInfosecurity Magazine·Jul 8, 11:00 UTC · Jul 8, 2025Malware55
OpenSSF adds new members from around the globe to improve OSS securityHelp Net Security·Apr 17, 12:42 UTC · Apr 17, 2026Vulnerability55
ENISA Technical Advisory on Secure Package Managers: Essential DevSecOps GuidanceSecurity Affairs·Mar 12, 08:49 UTC · Mar 12, 2026AdvisoryCVE-2025-5518260
GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious CodeThe Hacker News·Sep 9, 12:05 UTC · Sep 9, 2024Malware142
Popular PyPI Package 'ctx' and PHP Library 'phpass' Hijacked to Steal AWS KeysThe Hacker News·May 26, 02:35 UTC · May 26, 2022Malware155
CI Fuzz CLI: Open-source tool to test Java apps for unexpected behaviorsHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2022Exploit / PoC60
OpenSSF announces 15 new members to tackle supply chain security challengesHelp Net Security·May 11, 00:00 UTC · May 11, 2022Vulnerability55
This Sicko Caterpillar Wears the Bones of Its Victims404 Media·Apr 26, 13:00 UTC · Apr 26, 2025Industry30
Who exactly benefits from Kaspersky’s ICSCyberScoop·Oct 21, 19:50 UTC · Oct 21, 2016Exploit / PoC in the wild60
Upstream Supply Chain Attacks Triple in a YearInfosecurity Magazine·Oct 3, 14:00 UTC · Oct 3, 2023Vulnerability55
Transitive Dependencies Account for 95% of BugsInfosecurity Magazine·Dec 12, 11:35 UTC · Dec 12, 2022Vulnerability55
Critical flaw in Pivotal's Spring Data REST allows to hack any machine that runs an application built on its componentsSecurity Affairs·Mar 5, 18:00 UTC · Mar 5, 2018Data breachCVE-2017-8046160
Friday Squid Blogging: Increased Squid Population in the FalklandsSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2026Policy & legal130
Friday Squid Blogging: Roasted Squid with Tomatillo SalsaSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Malware55