Hackers target AI and crypto as software supply chain risks growHelp Net Security·Dec 3, 14:29 UTC · Dec 3, 2025Vulnerability in the wild60
Security Affairs newsletter Round 544 by Pierluigi Paganini – INTERNATIONAL EDITIONSecurity Affairs·Oct 5, 11:35 UTC · Oct 5, 2025Ransomware in the wildCVE-2025-4124460
ThreatsDay Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & MoreThe Hacker News·Oct 2, 12:19 UTC · Oct 2, 2025VulnerabilityCVE-2025-10184CVE-2024-36401160
When ‘minimal impact’ isn’t reassuring: lessons from the largest npm supply chain compromiseCyberScoop·Sep 15, 13:21 UTC · Sep 15, 2025Exploit / PoC in the wild60
Week in review: Microsoft fixes wormable RCE bug on Windows, check for CitrixBleed 2 exploitationHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2025Vulnerability in the wildCVE-2025-47981CVE-2025-49719CVE-2025-5777160
Malicious Open Source Packages Surge 188% AnnuallyInfosecurity Magazine·Jul 8, 11:00 UTC · Jul 8, 2025Malware55
Taking over millions of developers exploiting an Open VSX Registry flawSecurity Affairs·Jun 27, 19:37 UTC · Jun 27, 2025Vulnerability55
Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain AttacksThe Hacker News·Jun 27, 05:04 UTC · Jun 27, 2025Vulnerability55
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
Most critical vulnerabilities aren't worth your attentionHelp Net Security·Apr 28, 00:00 UTC · Apr 28, 2025Vulnerability55
Package hallucination: LLMs may deliver malicious code to careless devsHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2025Data breach160
Changing the tide: Reflections on threat data from 2024Cisco Talos·Feb 6, 19:03 UTC · Feb 6, 2025Exploit / PoC in the wild60
Taiwan Bans DeepSeek AI Over National Security Concerns, Citing Data Leakage RisksThe Hacker News·Feb 4, 11:56 UTC · Feb 4, 2025Data breach60
Security Affairs newsletter Round 508 by Pierluigi PaganiniSecurity Affairs·Jan 26, 14:30 UTC · Jan 26, 2025Ransomware in the wildCVE-2025-23006160
Cryptomining Malware Found in Popular Open Source PackagesInfosecurity Magazine·Dec 23, 16:30 UTC · Dec 23, 2024Malware55
Malware report for Q2 2024 — a quarterly reviewKaspersky Securelist·Sep 5, 07:45 UTC · Sep 5, 2024MalwareCVE-2024-309460
Here’s how carefully concealed backdoor in fake AWS files escaped mainstream noticeArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2024Malware55
Week in review: Attackers use phishing emails to steal NTLM hashes, Patch Tuesday forecastHelp Net Security·Mar 10, 00:00 UTC · Mar 10, 2024Vulnerability in the wildCVE-2024-20337CVE-2024-23225CVE-2024-23296+6 CVEs60
Securing software repositories leads to better OSS securityHelp Net Security·Mar 4, 00:00 UTC · Mar 4, 2024Vulnerability55
Phylum integrates with Sumo Logic to identify software supply chain attacksHelp Net Security·Dec 7, 00:00 UTC · Dec 7, 2023Exploit / PoC60
CI/CD Risks: Protecting Your Software Development PipelinesThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2023Vulnerability155
48 Malicious npm Packages Found Deploying Reverse Shells on Developer SystemsThe Hacker News·Nov 6, 16:38 UTC · Nov 6, 2023Malware155
Half of AI Open Source Projects Reference Buggy PackagesInfosecurity Magazine·Jul 20, 11:00 UTC · Jul 20, 2023Vulnerability155
LLMs and AI positioned to dominate the AppSec worldHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2023Policy & legal55
Google Launches New Cybersecurity Initiatives to Strengthen Vulnerability ManagementThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2023Vulnerability in the wild60
Google delivers secure open source software packagesHelp Net Security·Apr 13, 00:00 UTC · Apr 13, 2023Vulnerability55
Advanced threat predictions for 2023Kaspersky Securelist·Nov 14, 08:00 UTC · Nov 14, 2022Ransomware in the wild60
350K Open-Source Projects At Risk of Supply Chain VulnerabilityInfosecurity Magazine·Sep 21, 17:00 UTC · Sep 21, 2022Vulnerability55
Google Launches New Open Source Bug Bounty to Tackle Supply Chain AttacksThe Hacker News·Sep 1, 03:01 UTC · Sep 1, 2022Vulnerability55
Open source cyberattacks increasing by 650%, popular projects more vulnerableHelp Net Security·Sep 17, 00:00 UTC · Sep 17, 2021Vulnerability55
Software Supply Chain Attacks Surge 650% in a YearInfosecurity Magazine·Sep 15, 14:00 UTC · Sep 15, 2021Vulnerability55
Google launches Open Source Vulnerabilities (OSV) databaseSecurity Affairs·Feb 8, 21:24 UTC · Feb 8, 2021Vulnerability55
Open Source Supply Chain Attacks Surge 430%Infosecurity Magazine·Aug 13, 09:53 UTC · Aug 13, 2020Exploit / PoC in the wild60
Critical RCE flaw patched in Packagist PHP package repositorySecurity Affairs·Sep 3, 13:28 UTC · Sep 3, 2018Vulnerability55