Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploitedHelp Net Security·May 24, 00:00 UTC · May 24, 2026Data breach in the wildCVE-2026-42945CVE-2026-45585CVE-2026-41091+1 CVEs60
Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fixSecurity Affairs·May 21, 14:29 UTC · May 21, 2026Ransomware in the wildCVE-2024-1280260
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal DataThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC57
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startupHelp Net Security·Apr 28, 00:00 UTC · Apr 28, 2026AI tools & infra30
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code ExecutionThe Hacker News·Apr 21, 17:54 UTC · Apr 21, 2026AI safety & securityCVE-2026-2152035
Amazon MWAA: Enabling data engineers to easily execute data processing workflows in the cloudHelp Net Security·Apr 20, 09:53 UTC · Apr 20, 2026Tools30
AWS releases four storage innovations to add storage performance, resiliencyHelp Net Security·Apr 20, 09:53 UTC · Apr 20, 2026AI industry130
Infrastructure drift: A multidimensional problem with the need for new DevSecOps toolsHelp Net Security·Apr 20, 08:51 UTC · Apr 20, 2026AI tools & infra30
Amazon FSx for NetApp ONTAP brings data access and management capabilities to AWS cloudHelp Net Security·Apr 20, 08:45 UTC · Apr 20, 2026Vulnerability55
Cloud-audit: Fast, open-source AWS security scannerHelp Net Security·Apr 20, 06:36 UTC · Apr 20, 2026Tools55
Whispr: Open-source multi-vault secret injection toolHelp Net Security·Apr 17, 12:36 UTC · Apr 17, 2026Industry30
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain IncidentThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026RansomwareCVE-2026-3363460
Asqav: Open-source SDK for AI agent governanceHelp Net Security·Apr 9, 00:00 UTC · Apr 9, 2026Tools155
Everyday tools, extraordinary crimes: the ransomware exfiltration playbookCisco Talos·Mar 19, 10:00 UTC · Mar 19, 2026Ransomware57
Betterleaks: Open-source secrets scannerHelp Net Security·Mar 19, 00:00 UTC · Mar 19, 2026Model release50
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-26127160
U.S. CISA adds Cisco SD-WAN flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 26, 15:04 UTC · Feb 26, 2026Exploit / PoC in the wildCVE-2022-20775CVE-2026-2012760
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image MetadataThe Hacker News·Feb 3, 16:41 UTC · Feb 3, 2026Vulnerability155
OpenSSL issued security updates to fix 12 flaws, including Remote Code ExecutionSecurity Affairs·Jan 29, 08:35 UTC · Jan 29, 2026Vulnerability in the wild57
React2Shell Vulnerability Actively Exploited to Deploy Linux BackdoorsThe Hacker News·Dec 17, 07:26 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-29927CVE-2025-6647860
Nothing to steal? Let’s wipe. We’re analyzing the Shai Hulud 2.0 npm wormKaspersky Securelist·Dec 4, 15:46 UTC · Dec 4, 2025Data breach157
U.S. CISA adds a new Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 13:48 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
New FortiWeb zero-day CVE-2025Security Affairs·Nov 19, 06:55 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
Heisenberg: Open-source software supply chain health check toolHelp Net Security·Nov 3, 00:00 UTC · Nov 3, 2025Vulnerability42
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Product Walkthrough: How Passwork 7 Addresses Complexity of Enterprise SecurityThe Hacker News·Oct 3, 11:30 UTC · Oct 3, 2025Policy & legal30
Kali Linux 2025.3 brings improved virtual machine tooling, 10 new toolsHelp Net Security·Sep 24, 00:00 UTC · Sep 24, 2025Vulnerability30
Critical FortiSIEM flaw under active exploitation, Fortinet warnsSecurity Affairs·Aug 13, 17:40 UTC · Aug 13, 2025Exploit / PoC in the wildCVE-2025-2525660
N. Korean Hackers Used Job Lures, Cloud Account Access, and Malware to Steal Millions in CryptoThe Hacker News·Aug 10, 12:09 UTC · Aug 10, 2025Malware55
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
Week in review: Backdoor found in SOHO devices running Linux, high-risk WinRAR RCE flaw patchedHelp Net Security·Jun 29, 00:00 UTC · Jun 29, 2025VulnerabilityCVE-2025-6218CVE-2025-49144CVE-2025-577760
Shell No! (Part 2) Introducing Cknife, China Chopper’s SiblingRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
PyPI, npm, and AI Tools Exploited in Malware Surge Targeting DevOps and Cloud EnvironmentsThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Malware142
Palo Alto Networks fixed multiple privilege escalation flawsSecurity Affairs·Jun 14, 09:57 UTC · Jun 14, 2025VulnerabilityCVE-2025-4233CVE-2025-4232CVE-2025-4231+2 CVEs35
Dero miner spreads inside containerized Linux environmentsKaspersky Securelist·May 21, 10:00 UTC · May 21, 2025Malware42
NCSC Releases Post-Quantum Cryptography TimelineSchneier on Security·Mar 21, 16:02 UTC · Mar 21, 2025Industry42
U.S. CISA adds Apple products and Juniper Junos OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 14, 00:02 UTC · Mar 14, 2025Exploit / PoC in the wildCVE-2025-21590CVE-2025-2420160
Defending Your Commits From Known CVEs With GitGuardian SCA And Git HooksThe Hacker News·Mar 7, 14:51 UTC · Mar 7, 2025Vulnerability55