Shai-Hulud-Like Worm Targets Developers via npm and AI ToolsInfosecurity Magazine·Feb 23, 16:00 UTC · Feb 23, 2026Malware42
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer SystemsThe Hacker News·Feb 20, 14:40 UTC · Feb 20, 2026Threat actor57
DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate CompaniesThe Hacker News·Feb 11, 14:43 UTC · Feb 11, 2026Malware42
Veracode’s platform enhancements help prevent software supply chain attacksHelp Net Security·Jan 28, 00:00 UTC · Jan 28, 2026Data breach60
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-65046CVE-2026-0628CVE-2026-20805+5 CVEs160
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
Researchers Uncover NodeCordRAT Hidden in npm BitcoinThe Hacker News·Jan 8, 10:31 UTC · Jan 8, 2026Malware30
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full ControlThe Hacker News·Jan 8, 09:26 UTC · Jan 8, 2026VulnerabilityCVE-2026-21858CVE-2025-68613CVE-2025-68668+1 CVEs60
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader MalwareThe Hacker News·Dec 20, 13:28 UTC · Dec 20, 2025Malware30
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency MitigationThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-55182CVE-2021-4422860
Goodbye, dark Telegram: Blocks are pushing the underground outKaspersky Securelist·Dec 9, 11:29 UTC · Dec 9, 2025Malware42
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Kaspersky Security Bulletin 2025. StatisticsKaspersky Securelist·Dec 2, 10:07 UTC · Dec 2, 2025Advisory42
Contagious Interview campaign expands with 197 npm Ppackages spreading new OtterCookie malwareSecurity Affairs·Nov 30, 01:02 UTC · Nov 30, 2025Malware42
North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie MalwareThe Hacker News·Nov 28, 16:18 UTC · Nov 28, 2025Malware42
ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More StoriesThe Hacker News·Nov 27, 10:03 UTC · Nov 27, 2025MalwareCVE-2009-2765CVE-2020-25506CVE-2022-37055+6 CVEs47
Shai-Hulud worm returns stronger and more automated than ever beforeCyberScoop·Nov 24, 22:45 UTC · Nov 24, 2025Data breach in the wild60
9 Black Friday cybersecurity deals you don't want to missHelp Net Security·Nov 22, 16:27 UTC · Nov 22, 2025Policy & legal30
Minimus debuts Image Creator for building secure, hardened container imagesHelp Net Security·Nov 20, 00:00 UTC · Nov 20, 2025Vulnerability42
U.S. CISA adds a Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 21:12 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-1322360
Google fixed the seventh Chrome zeroSecurity Affairs·Nov 18, 08:59 UTC · Nov 18, 2025Exploit / PoC in the wildCVE-2025-13223CVE-2025-13224CVE-2025-10585+5 CVEs60
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network OperationThe Hacker News·Oct 28, 03:53 UTC · Oct 28, 2025Malware30
OpenFGA: The open-source engine redefining access controlHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2025AI safety & security30
Keycard emerges from stealth with identity and access solution for AI agentsHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2025AI safety & security30
DataDome secures MCP infrastructure for trusted agentic AIHelp Net Security·Oct 21, 00:00 UTC · Oct 21, 2025AI safety & security30
npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord ChannelsThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Data breach157
Week in review: Cisco ASA zero-day vulnerabilities exploited, Fortra GoAnywhere instances at riskHelp Net Security·Sep 28, 00:00 UTC · Sep 28, 2025Exploit / PoCCVE-2025-10035CVE-2025-59689CVE-2025-26399+1 CVEs60
After Shai-Hulud, GitHub tightens npm publishing securityHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2025Vulnerability30
DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job ScamsThe Hacker News·Sep 22, 15:17 UTC · Sep 22, 2025Malware42
Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attackHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2025Data breach57
Arkime: Open-source network analysis and packet capture systemHelp Net Security·Sep 15, 00:00 UTC · Sep 15, 2025Policy & legal30
The npm incident frightened everyone, but ended up being nothing to fret aboutCyberScoop·Sep 10, 14:35 UTC · Sep 10, 2025Exploit / PoC in the wild60
Analyzing the TTPs of hacktivists and APTs targeting Russian organizationsKaspersky Securelist·Sep 10, 14:00 UTC · Sep 10, 2025Data breach60
Fake npm 2FA reset email led to compromise of popular code packagesHelp Net Security·Sep 9, 00:00 UTC · Sep 9, 2025Ransomware57
Noisy Bear Campaign Targeting Kazakhstan Energy Sector Outed as a Planned Phishing TestThe Hacker News·Sep 8, 14:08 UTC · Sep 8, 2025Threat actor57