⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News·Jun 23, 03:40 UTC · Jun 23, 2026Malware in the wildCVE-2026-24858CVE-2025-59718CVE-2025-59719+1 CVEs60
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security·Jun 21, 00:00 UTC · Jun 21, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-48558CVE-2026-39813+3 CVEs160
Fedora Hummingbird brings the container security model to a Linux host OSHelp Net Security·Jun 19, 11:21 UTC · Jun 19, 2026Vulnerability30
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update LuresThe Hacker News·Jun 17, 08:52 UTC · Jun 17, 2026Malware42
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain AttacksThe Hacker News·Jun 11, 06:23 UTC · Jun 11, 2026Industry42
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Hades PyPI Attack: 19 Packages Poisoned to AutoThe Hacker News·Jun 9, 10:34 UTC · Jun 9, 2026Malware42
GitHub Copilot app launches as desktop home for AI coding agentsHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2026AI research130
AgentGG: Open-source agentic SAST scannerHelp Net Security·Jun 5, 00:00 UTC · Jun 5, 2026Vulnerability30
Mythos Outperforms GPT5.5 on Google Chrome Vulnerability ExploitsInfosecurity Magazine·Jun 4, 13:00 UTC · Jun 4, 2026Vulnerability55
OpenAI Codex Authentication Tokens Stolen in codexuiThe Hacker News·Jun 1, 09:31 UTC · Jun 1, 2026Threat actor157
GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack InfrastructureThe Hacker News·May 27, 15:23 UTC · May 27, 2026Malware42
How cybersecurity firms took down Glassworm botnet in one shotSecurity Affairs·May 27, 11:35 UTC · May 27, 2026Malware42
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 CountriesThe Hacker News·May 27, 09:52 UTC · May 27, 2026Threat actor60
Mini Shai-Hulud returns, compromising hundreds of npm packagesCyberScoop·May 19, 21:21 UTC · May 19, 2026Data breach in the wild60
Lyrie: Open-source autonomous pentesting agentHelp Net Security·May 18, 00:00 UTC · May 18, 2026Exploit / PoC45
Sandyaa: Open-source autonomous security bug hunterHelp Net Security·May 13, 00:00 UTC · May 13, 2026Exploit / PoC45
HEIDI: Free IDE security plugin for open-source vulnerability checksHelp Net Security·May 12, 00:00 UTC · May 12, 2026Vulnerability42
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K DownloadsThe Hacker News·May 11, 18:22 UTC · May 11, 2026Data breach57
Granulate adds Kubernetes filtering feature to open-source gProfilerHelp Net Security·Apr 17, 12:41 UTC · Apr 17, 2026Industry130
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-27681CVE-2026-34621CVE-2026-34619+7 CVEs60
Microsoft Issues Patches for SharePoint ZeroThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2023-20585CVE-2026-21637CVE-2026-25250+4 CVEs160
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEsThe Hacker News·Apr 10, 13:23 UTC · Apr 10, 2026Threat actor145
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-YearThe Hacker News·Apr 9, 16:23 UTC · Apr 9, 2026MalwareCVE-2024-32114CVE-2026-34197CVE-2022-41678160
Social engineering attacks on open source developers are escalatingHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2026Phishing & fraud30
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances ExposedThe Hacker News·Apr 7, 05:56 UTC · Apr 7, 2026Vulnerability in the wildCVE-2025-59528CVE-2025-8943CVE-2025-2631960
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsThe Hacker News·Apr 6, 06:40 UTC · Apr 6, 2026Vulnerability142
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applicationsCisco Talos·Apr 2, 10:00 UTC · Apr 2, 2026Data breachCVE-2025-55182160
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and MoreThe Hacker News·Mar 31, 18:05 UTC · Mar 31, 2026AI safety & security in the wildCVE-2026-3055CVE-2025-62843CVE-2025-62844+32 CVEs50
EtherRAT Techniques Bypass Security Via Ethereum Smart ContractsInfosecurity Magazine·Mar 26, 15:00 UTC · Mar 26, 2026Malware42
Kaspersky Global Report by Kaspersky Security Services 2026Kaspersky Securelist·Mar 25, 10:35 UTC · Mar 25, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & VibeThe Hacker News·Mar 9, 18:22 UTC · Mar 9, 2026Data breach in the wildCVE-2026-21385CVE-2026-2796CVE-2026-2256+13 CVEs60
Open-source tool Sage puts a security layer between AI agents and the OSHelp Net Security·Mar 9, 00:00 UTC · Mar 9, 2026Malware42
Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government TargetsThe Hacker News·Mar 3, 09:20 UTC · Mar 3, 2026Malware30
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for CrossThe Hacker News·Mar 3, 06:20 UTC · Mar 3, 2026Malware42
BlacksmithAI: Open-source AI-powered penetration testing frameworkHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2026Exploit / PoC145
Shai-Hulud-Like Worm Targets Developers via npm and AI ToolsInfosecurity Magazine·Feb 23, 16:00 UTC · Feb 23, 2026Malware42