Software supply chain hacks trigger wave of intrusions, data theftHelp Net Security·Apr 2, 00:00 UTC · Apr 2, 2026Ransomware57
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI CredentialsThe Hacker News·Mar 25, 06:34 UTC · Mar 25, 2026Data breachCVE-2026-33634160
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD SecretsThe Hacker News·Mar 24, 06:31 UTC · Mar 24, 2026Data breach57
‘CanisterWorm’ Springs Wiper Attack Targeting IranKrebs on Security·Mar 23, 19:04 UTC · Mar 23, 2026Malware42
Cybersecurity jobs available right now: April 23, 2025Help Net Security·Jan 30, 10:27 UTC · Jan 30, 2026Ransomware57
U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 12, 21:55 UTC · Jan 12, 2026Exploit / PoC in the wildCVE-2025-8110CVE-2024-5594760
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation WorldwideThe Hacker News·Dec 30, 07:59 UTC · Dec 30, 2025Vulnerability in the wildCVE-2025-1484760
Admins and defenders gird themselves against maximumArs Technica · Security·Dec 3, 23:16 UTC · Dec 3, 2025VulnerabilityCVE-2025-55182CVE-2025-6647847
Supply Chain Worm Prowls npm to Steal Hundreds of SecretsInfosecurity Magazine·Sep 17, 10:20 UTC · Sep 17, 2025Vulnerability42
U.S. CISA adds Sitecore CMS and XP, and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 27, 12:31 UTC · Mar 27, 2025Exploit / PoC in the wildCVE-2019-9875CVE-2019-9874CVE-2025-3015460
CISA Warns of Active Exploitation in GitHub Action Supply Chain CompromiseThe Hacker News·Mar 19, 06:31 UTC · Mar 19, 2025Advisory in the wildCVE-2025-30066160
GitHub Action tj-actions/changed-files was compromised in supply chain attackSecurity Affairs·Mar 18, 10:17 UTC · Mar 18, 2025VulnerabilityCVE-2025-30066147
DeepSeek iOS app sends data unencrypted to ByteDanceArs Technica · Security·Feb 6, 22:06 UTC · Feb 6, 2025Vulnerability42
Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code ExecutionThe Hacker News·Jan 4, 14:29 UTC · Jan 4, 2025VulnerabilityCVE-2024-4340547
SAP AI Core Vulnerabilities Expose Customer Data to Cyber AttacksThe Hacker News·Jul 18, 13:58 UTC · Jul 18, 2024Vulnerability42
GameOver(lay): Two Severe Linux Vulnerabilities Impact 40% of Ubuntu UsersThe Hacker News·Jul 31, 05:54 UTC · Jul 31, 2023VulnerabilityCVE-2023-2640CVE-2023-32629CVE-2016-1576+3 CVEs47
Bugs in Managed DNS Services Cloud Let Attackers Spy On DNS TrafficThe Hacker News·Aug 11, 11:57 UTC · Aug 11, 2021Vulnerability42
Compromised AsyncAPI npm Packages Deliver MultiThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC157
Miasma Worm Compromises 73 Microsoft GitHub RepositoriesSecurity Affairs·Jun 9, 16:08 UTC · Jun 9, 2026Malware142
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)Help Net Security·May 18, 13:54 UTC · May 18, 2026Vulnerability in the wildCVE-2026-46300CVE-2026-4328460
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-31431CVE-2022-27666CVE-2026-43284+1 CVEs60
Trellix Reveals Unauthorized Access to Source CodeInfosecurity Magazine·May 5, 08:55 UTC · May 5, 2026Ransomware57
Google Introduces Unique AI Agent Identities in New Gemini EnterpriseInfosecurity Magazine·Apr 23, 12:00 UTC · Apr 23, 2026Vulnerability142
Vercel Breach Tied to Context AI Hack Exposes Limited Customer CredentialsThe Hacker News·Apr 22, 15:14 UTC · Apr 22, 2026Data breach157
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069The Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Ransomware57
Trivy supply chain attack enabled European Commission cloud breachHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2026Ransomware57
Axios npm packages backdoored in supply chain attackHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2026Malware42
TeamPCP Targets Telnyx Package in Latest Software Supply Chain AttackInfosecurity Magazine·Mar 27, 15:06 UTC · Mar 27, 2026Ransomware57
LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacksHelp Net Security·Mar 27, 10:18 UTC · Mar 27, 2026Vulnerability142
Malicious LiteLLM versions linked to TeamPCP supply chain attackSecurity Affairs·Mar 25, 08:50 UTC · Mar 25, 2026Data breach57
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm PackagesThe Hacker News·Mar 23, 07:53 UTC · Mar 23, 2026Malware42
Widely used Trivy scanner compromised in ongoing supplyArs Technica · Security·Mar 20, 20:50 UTC · Mar 20, 2026Vulnerability42
Infosecurity Europe Announces 2026 Keynote Line UpInfosecurity Magazine·Mar 11, 16:20 UTC · Mar 11, 2026Ransomware57
Stellar Cyber expands Autonomous SOC capabilities with agentic AIHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2026Ransomware57
A ransomware attack disrupted operations at South Korean conglomerate KyowonSecurity Affairs·Jan 15, 21:25 UTC · Jan 15, 2026Ransomware57
US, Australia say ‘MongoBleed’ bug being exploitedThe Record·Dec 29, 22:07 UTC · Dec 29, 2025Data breachCVE-2025-1484760