⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
ChainDrop Worm Hits 400 npm Packages with Two Billion Monthly InstallsInfosecurity Magazine·Aug 5, 10:00 UTC · Aug 5, 2026Malware30
Identity Lifecycle Management Wasn't Built for AI AgentsThe Hacker News·Jul 2, 11:30 UTC · Jul 2, 2026Threat actor45
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn StealerThe Hacker News·Jun 30, 11:18 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-48558260
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4855860
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF RootkitThe Hacker News·Jun 12, 19:35 UTC · Jun 12, 2026Malware55
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Attackers already know the secrets are on your developers' machines. Do you?Help Net Security·Jun 4, 00:00 UTC · Jun 4, 2026Threat actor57
Red Hat npm packages compromised in new Mini Shai-Hulud malware waveHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Malware42
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud SecretsThe Hacker News·May 31, 12:15 UTC · May 31, 2026Data breach157
Laravel-Lang PHP Packages Compromised to Deliver CrossThe Hacker News·May 24, 08:14 UTC · May 24, 2026Malware42
GitLab 19.0 adds AI workflows, secrets management, and self-hosted model supportHelp Net Security·May 22, 00:00 UTC · May 22, 2026Advisory42
Grafana Labs Says Code Breach Stemmed from TanStack AttackInfosecurity Magazine·May 21, 08:00 UTC · May 21, 2026Ransomware157
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromiseHelp Net Security·May 21, 00:00 UTC · May 21, 2026Vulnerability142
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal ReposThe Hacker News·May 20, 16:10 UTC · May 20, 2026Data breach60
Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewalsHelp Net Security·May 20, 00:00 UTC · May 20, 2026Industry30
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supplyCyberScoop·May 12, 21:38 UTC · May 12, 2026Malware155
PCPJack Credential Stealer Exploits 5 CVEs to Spread WormThe Hacker News·May 7, 17:45 UTC · May 7, 2026MalwareCVE-2025-55182CVE-2025-29927CVE-2026-1357+2 CVEs35
AWS Network Firewall: Network protection across all AWS workloadsHelp Net Security·Apr 20, 09:54 UTC · Apr 20, 2026Vulnerability30
Sonrai Dig maps relationships between identities and data inside public cloudsHelp Net Security·Apr 20, 09:44 UTC · Apr 20, 2026Vulnerability55
Brutus: Open-source credential testing tool for offensive securityHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2026Malware42
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & MoreThe Hacker News·Dec 6, 11:14 UTC · Dec 6, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-38352CVE-2025-48543+25 CVEs160
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & MoreThe Hacker News·Nov 3, 17:59 UTC · Nov 3, 2025Threat actorCVE-2025-61932CVE-2025-55315CVE-2025-10680+18 CVEs160
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware ChainsThe Hacker News·Oct 30, 09:40 UTC · Oct 30, 2025Malware142
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT DevicesThe Hacker News·Oct 29, 15:38 UTC · Oct 29, 2025Malware in the wildCVE-2017-9841CVE-2021-3129CVE-2022-47945+2 CVEs160
⚡ Weekly Recap: iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and MoreThe Hacker News·Oct 28, 08:29 UTC · Oct 28, 2025Malware in the wildCVE-2025-43200CVE-2025-32711CVE-2025-33053+24 CVEs260
Why Organizations Are Abandoning Static Secrets for Managed IdentitiesThe Hacker News·Oct 23, 11:00 UTC · Oct 23, 2025AI tools & infra130
⚡ Weekly Recap: BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & MoreThe Hacker News·Aug 12, 04:40 UTC · Aug 12, 2025Ransomware in the wildCVE-2025-54948CVE-2025-54987CVE-2025-8088+30 CVEs60
Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. InfrastructureThe Hacker News·Jul 29, 04:19 UTC · Jul 29, 2025Ransomware60
Leveraging Credentials As Unique Identifiers: A Pragmatic Approach To NHI InventoriesThe Hacker News·Jun 30, 11:00 UTC · Jun 30, 2025Vulnerability30
Non-Human Identities: How to Address the Expanding Security RiskThe Hacker News·Jun 12, 11:00 UTC · Jun 12, 2025Vulnerability30
AI Agents and the Non‑Human Identity Crisis: How to Deploy AI More Securely at ScaleThe Hacker News·May 27, 11:00 UTC · May 27, 2025AI safety & security30
Oasis NHI Provisioning automates the provisioning of NHIs and their credentialsHelp Net Security·Apr 29, 00:00 UTC · Apr 29, 2025Industry55
Why NHIs Are Security's Most Dangerous Blind SpotThe Hacker News·Apr 25, 10:30 UTC · Apr 25, 2025Malware55
End-to-End Secrets Security: Making a Plan to Secure Your Machine IdentitiesThe Hacker News·Mar 7, 14:51 UTC · Mar 7, 2025AI safety & security30
whoAMI attack could allow remote code execution within AWS accountSecurity Affairs·Feb 17, 10:50 UTC · Feb 17, 2025Vulnerability42
New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code ExecutionThe Hacker News·Feb 17, 03:43 UTC · Feb 17, 2025Vulnerability42