Researchers disclosed a remote code execution flaw in Fastjson LibrarySecurity Affairs·Jun 16, 10:14 UTC · Jun 16, 2022VulnerabilityCVE-2022-2584547
Zero trust: How the ‘Jia Tan’ hack complicated openCyberScoop·Aug 15, 13:00 UTC · Aug 15, 2024Vulnerability42
MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned LibrariesThe Hacker News·Jan 22, 16:48 UTC · Jan 22, 2024Threat actor157
Software Supply Chain Attacks Soar 742% in Three YearsInfosecurity Magazine·Oct 19, 09:30 UTC · Oct 19, 2022Vulnerability42
Dependency-Track: Open-source component analysis platformHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2025Vulnerability42
Vet: Open-source software supply chain security toolHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2025Vulnerability42
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4855860
New Google tool reveals dependencies for open source projectsHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2021Vulnerability42
ENISA advisory examines package manager security risksHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2026Advisory42
The Log4j saga: New vulnerabilities and attack vectors discoveredHelp Net Security·Dec 20, 00:00 UTC · Dec 20, 2021VulnerabilityCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs47
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm RegistryThe Hacker News·Jan 1, 10:11 UTC · Jan 1, 2026Malware42
VSCode Marketplace Removes Two Extensions Deploying EarlyThe Hacker News·Mar 24, 11:10 UTC · Mar 24, 2025Ransomware57
GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious CodeThe Hacker News·Sep 9, 12:05 UTC · Sep 9, 2024Malware142