Breaking out: Can AI agents escape their sandboxes?Help Net Security·Aug 5, 12:04 UTC · Aug 5, 2026Vulnerability230
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm packageHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2026Industry142
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News·Jul 31, 11:17 UTC · Jul 31, 2026Exploit / PoC in the wildCVE-2026-66066CVE-2025-24293160
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryThe Hacker News·Jul 29, 15:39 UTC · Jul 29, 2026VulnerabilityCVE-2026-59726160
How attackers hosted a fake Claude download page on the claude.ai domainHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026Vulnerability30
JadePuffer Returns With Ransomware Designed to Wipe AI ModelsInfosecurity Magazine·Jul 20, 14:05 UTC · Jul 20, 2026Ransomware in the wildCVE-2025-3248160
20 Open-Source Cybersecurity Tools To Keep Your Team Ready For AnythingHelp Net Security·Jul 8, 00:00 UTC · Jul 8, 2026Vulnerability30
WSL containers now build and run Linux workloads on WindowsHelp Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Tools130
Hottest cybersecurity open-source tools of the month: June 2026Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Policy & legal30
Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF RootkitThe Hacker News·Jun 12, 19:35 UTC · Jun 12, 2026Malware55
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42
PCPJack Campaign Boots TeamPCP Off Compromised MachinesInfosecurity Magazine·May 8, 09:00 UTC · May 8, 2026Threat actor57
We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually IsThe Hacker News·May 5, 10:30 UTC · May 5, 2026Vulnerability30
PentAGI: Open-source autonomous AI penetration testing systemHelp Net Security·Apr 22, 00:00 UTC · Apr 22, 2026Exploit / PoC60
ShipSec Studio brings open-source workflow orchestration to security operationsHelp Net Security·Mar 30, 00:00 UTC · Mar 30, 2026Policy & legal30
Malicious LiteLLM versions linked to TeamPCP supply chain attackSecurity Affairs·Mar 25, 08:50 UTC · Mar 25, 2026Data breach57
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI CredentialsThe Hacker News·Mar 25, 06:34 UTC · Mar 25, 2026Data breachCVE-2026-33634160
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD SecretsThe Hacker News·Mar 24, 06:31 UTC · Mar 24, 2026Data breach57
BlacksmithAI: Open-source AI-powered penetration testing frameworkHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2026Exploit / PoC145
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
New Advanced Linux VoidLink Malware Targets Cloud and container EnvironmentsThe Hacker News·Jan 19, 08:54 UTC · Jan 19, 2026Malware55
New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure IntrusionsThe Hacker News·Nov 24, 15:27 UTC · Nov 24, 2025VulnerabilityCVE-2025-12972CVE-2025-12970CVE-2025-12978+3 CVEs47
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP PacketsThe Hacker News·Oct 17, 04:34 UTC · Oct 17, 2025MalwareCVE-2024-2389747
ShinyHunters Wage Broad Corporate Extortion SpreeKrebs on Security·Oct 8, 00:36 UTC · Oct 8, 2025RansomwareCVE-2025-6188260
⚡ Weekly Recap: Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & MoreThe Hacker News·Oct 6, 11:28 UTC · Oct 6, 2025RansomwareCVE-2025-20362CVE-2025-20333CVE-2025-20363+15 CVEs60
Delinea releases free open-source MCP server to secure AI agentsHelp Net Security·Sep 26, 00:00 UTC · Sep 26, 2025AI safety & security30
TruffleHog: Open-source solution for scanning secretsHelp Net Security·Sep 16, 19:20 UTC · Sep 16, 2025AI safety & security30
Security Affairs newsletter Round 539 by Pierluigi PaganiniSecurity Affairs·Aug 31, 05:51 UTC · Aug 31, 2025Ransomware in the wildCVE-2025-9074CVE-2025-7775CVE-2025-53786160
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHubThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Vulnerability in the wildCVE-2018-15133CVE-2024-5555660
Reconmap: Open-source vulnerability assessment, pentesting management platformHelp Net Security·Jun 24, 00:00 UTC · Jun 24, 2025Vulnerability30
SafeLine WAF: Open Source Web Application Firewall with ZeroThe Hacker News·May 23, 10:30 UTC · May 23, 2025Exploit / PoC60
Duping Cloud Functions: An emerging serverless attack vectorCisco Talos·May 20, 10:00 UTC · May 20, 2025Vulnerability30
Containers are just processes: The illusion of namespace securityHelp Net Security·May 20, 00:00 UTC · May 20, 2025Vulnerability55
LoftLabs vNode simplifies Kubernetes operationsHelp Net Security·Apr 1, 00:00 UTC · Apr 1, 2025Industry30
Don't let these open-source cybersecurity tools slip under your radarHelp Net Security·Jan 27, 00:00 UTC · Jan 27, 2025Vulnerability30
HPE is investigating IntelBroker's claims of the company hackSecurity Affairs·Jan 20, 22:46 UTC · Jan 20, 2025Data breach57
HPE Launches Investigation After Hacker Claims Data BreachInfosecurity Magazine·Jan 20, 16:40 UTC · Jan 20, 2025Data breach57
Cisco states that data published on cybercrime forum was taken from publicSecurity Affairs·Oct 21, 19:22 UTC · Oct 21, 2024Data breach57