Multiple malicious packages in PyPI repository found stealing AWS secretsSecurity Affairs·Jun 25, 17:52 UTC · Jun 25, 2022Data breach45
Two malicious Python libraries were stealing SSH and GPG keysSecurity Affairs·Dec 4, 15:37 UTC · Dec 4, 2019Malware30
Microsoft releases open-source toolkit to govern autonomous AI agentsHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2026Policy & legal130
Malicious PyTorch Package Downloaded Thousands of TimesInfosecurity Magazine·Jan 4, 10:00 UTC · Jan 4, 2023Industry30
Thousands of Publicly Exposed API Tokens Could Threaten Software IntegrityInfosecurity Magazine·Oct 21, 16:00 UTC · Oct 21, 2022Research30
Whispr: Open-source multi-vault secret injection toolHelp Net Security·Apr 17, 12:36 UTC · Apr 17, 2026Industry30
OpenClaw Scanner: Open-source tool detects autonomous AI agentsHelp Net Security·Feb 17, 08:18 UTC · Feb 17, 2026Tools30
90% of exposed secrets on GitHub remain active for at least five daysHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2024Threat actor45
MyEstatePoint Property Search Android app leaks user passwordsSecurity Affairs·Jan 5, 10:14 UTC · Jan 5, 2024Data breach45
LoginID SDK empowers developers to integrate FIDO strong authentication into their websites or appsHelp Net Security·Dec 12, 14:04 UTC · Dec 12, 2023Phishing & fraud130
Package Analysis dynamic analyzes packages in open-source repositoriesSecurity Affairs·May 3, 06:08 UTC · May 3, 2022Tools30
760+ malicious packages found typosquatting on RubyGemsHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2020Malware30