⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
Hackers turn open-source AI framework into global cryptojacking operationCyberScoop·Nov 19, 15:29 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2023-48022160
North Korean Hackers Turn JSON Services into Covert Malware Delivery ChannelsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Malware42
Red Hat Investigating Breach Impacting as Many as 28,000 Customers, Including the Navy and Congress404 Media·Oct 2, 14:24 UTC · Oct 2, 2025Policy & legal30
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security ChangesThe Hacker News·Aug 9, 06:49 UTC · Aug 9, 2025Vulnerability42
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
SparkCat campaign target crypto wallets using OCR to steal recovery phrasesSecurity Affairs·Feb 5, 12:54 UTC · Feb 5, 2025Threat actor45
Lazarus Group Targets Web3 Developers with Fake LinkedIn Profiles in Operation 99The Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Threat actor157
Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecastHelp Net Security·Jan 12, 00:00 UTC · Jan 12, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2024-41713CVE-2024-55550+1 CVEs60
The shocking speed of AWS key exploitationHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2024Vulnerability130
Cisco states that data published on cybercrime forum was taken from publicSecurity Affairs·Oct 21, 19:22 UTC · Oct 21, 2024Data breach57
Foxit PDF Reader Flaw Exploited by Hackers to Deliver Diverse Malware ArsenalThe Hacker News·May 22, 03:19 UTC · May 22, 2024Malware42
nodeQ launches PQtunnel to simplify the migration to PQC for both SMEs and large enterprisesHelp Net Security·May 8, 00:00 UTC · May 8, 2024Industry130
New JSOutProx Malware Targets Financial Firms in APAC, MENAInfosecurity Magazine·Apr 4, 16:30 UTC · Apr 4, 2024Malware30
Legit Security launches enterprise secrets scanning solutionHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2024Data breach60
New Python-Based Snake Info Stealer Spreading Through Facebook MessagesThe Hacker News·Mar 8, 05:56 UTC · Mar 8, 2024Malware30
Kubestriker: A security auditing tool for Kubernetes clustersHelp Net Security·Feb 5, 13:53 UTC · Feb 5, 2024Vulnerability30
Threat actor used Vimeo, Ars Technica to serve second-stage malwareHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2024Malware42
Very Good Security appoints Paul Machle as Chief Financial OfficerHelp Net Security·Jan 26, 08:53 UTC · Jan 26, 2024Policy & legal30
Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto MinersThe Hacker News·Jan 6, 06:24 UTC · Jan 6, 2024Malware30
StripedFly Malware Operated Unnoticed for 5 Years, Infecting 1 Million DevicesThe Hacker News·Nov 6, 13:51 UTC · Nov 6, 2023Malware42
Week in review: 18 free Microsoft Azure cybersecurity resources, K8 vulnerability allows RCEHelp Net Security·Sep 24, 00:00 UTC · Sep 24, 2023Vulnerability in the wildCVE-2023-41179CVE-2023-41992CVE-2023-41991+6 CVEs60
Veza for SaaS Apps secures sensitive data against breaches, ransomware, and insider threatsHelp Net Security·May 3, 00:00 UTC · May 3, 2023Ransomware57
Bitwarden Secrets Manager secures, controls, and manages infrastructure secretsHelp Net Security·Mar 30, 00:00 UTC · Mar 30, 2023AI tools & infra130
Application and cloud security is a shared responsibilityHelp Net Security·Feb 16, 00:00 UTC · Feb 16, 2023Vulnerability55
Veza Open Authorization API boosts security across enterprise data systemsHelp Net Security·Dec 3, 00:00 UTC · Dec 3, 2022Ransomware160
Rafay launches Technical Alliance Program and Kubernetes Addon Catalog for Kubernetes managementHelp Net Security·Oct 24, 00:00 UTC · Oct 24, 2022Industry55
Tens of Jenkins plugins are affected by zeroSecurity Affairs·Jul 3, 21:15 UTC · Jul 3, 2022Vulnerability30
GitGuardian announces new features to help developers reduce risks of exposureHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2022Vulnerability130
Researchers Uncover Rust Supply Chain Attack Targeting Cloud CI PipelinesThe Hacker News·May 21, 03:11 UTC · May 21, 2022Malware42
GrammaTech CodeSonar 7.0 helps developers find and fix issues while codingHelp Net Security·Apr 28, 00:00 UTC · Apr 28, 2022Policy & legal155
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
Putting the “sec” in DevSecOps: An overall reduction of riskHelp Net Security·Nov 29, 00:00 UTC · Nov 29, 2021Policy & legal55
Cloudflare mitigated 2 Tbps DDoS, the largest attack it has seen to dateSecurity Affairs·Nov 15, 20:36 UTC · Nov 15, 2021Vulnerability30
GitHub Revoked Insecure SSH Keys Generated by a Popular git ClientThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2021Exploit / PoC in the wildCVE-2021-4111760
Beyond Identity's solution secures the software supply chain against insider threats and malicious attacksHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2021Vulnerability55
GrammaTech CodeSonar extends DevSecOps to embedded software developmentHelp Net Security·Aug 19, 00:00 UTC · Aug 19, 2021Tools55
Wallarm advances API security with native gRPC and GraphQL supportHelp Net Security·Feb 24, 00:00 UTC · Feb 24, 2020Vulnerability130