Shai-Hulud worm returns stronger and more automated than ever beforeCyberScoop·Nov 24, 22:45 UTC · Nov 24, 2025Data breach in the wild60
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supplyCyberScoop·May 12, 21:38 UTC · May 12, 2026Malware155
Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of SecretsThe Hacker News·Nov 27, 03:43 UTC · Nov 27, 2025Threat actor160
Massive supply-chain attack compromises 440 packages under four hoursCyberScoop·Aug 4, 22:07 UTC · Aug 4, 2026Exploit / PoC60
Mini Shai-Hulud returns, compromising hundreds of npm packagesCyberScoop·May 19, 21:21 UTC · May 19, 2026Data breach in the wild60
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential TheftThe Hacker News·Nov 25, 03:51 UTC · Nov 25, 2025Vulnerability55
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
Developer Workstations Are Now Part of the Software Supply ChainThe Hacker News·May 18, 11:23 UTC · May 18, 2026Threat actor160
SAP-Related npm Packages Compromised in CredentialThe Hacker News·Apr 30, 16:39 UTC · Apr 30, 2026Data breach60
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
Malware is targeting AI tools in software development environmentsCyberScoop·Jul 22, 17:24 UTC · Jul 22, 2026Malware in the wild160
A Record-Breaking Patch Tuesday for June 2026Krebs on Security·Jun 10, 01:28 UTC · Jun 10, 2026VulnerabilityCVE-2026-49160CVE-2026-45586CVE-2026-5050760
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs160
ThreatsDay Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & MoreThe Hacker News·Oct 2, 12:19 UTC · Oct 2, 2025VulnerabilityCVE-2025-10184CVE-2024-36401160
Why metaphor may dictate your security strategyCisco Talos·Aug 6, 18:00 UTC · Aug 6, 2026Vulnerability155
Security Affairs newsletter Round 583 by Pierluigi Paganini – INTERNATIONAL EDITIONSecurity Affairs·Jul 4, 23:02 UTC · Jul 4, 2026RansomwareCVE-2026-47729CVE-2026-20971CVE-2026-20245+1 CVEs60
Agentic attack chains advance as infostealers flood criminal marketsHelp Net Security·Jun 19, 12:05 UTC · Jun 19, 2026Malware in the wild60
GitHub Breach Traced to Malicious ‘Nx Console’ VS Code ExtensionInfosecurity Magazine·May 21, 14:45 UTC · May 21, 2026Data breachCVE-2026-48027160
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal ReposThe Hacker News·May 20, 16:10 UTC · May 20, 2026Data breach60
TeamPCP breached GitHub's internal codebase via poisoned VS Code extensionHelp Net Security·May 20, 00:00 UTC · May 20, 2026Data breach60
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News·May 19, 04:33 UTC · May 19, 2026Ransomware in the wildCVE-2026-42897CVE-2026-20182CVE-2026-2012760
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-0300160
How LiteLLM Turned Developer Machines Into Credential Vaults for AttackersThe Hacker News·Apr 8, 10:59 UTC · Apr 8, 2026Vulnerability155
ENISA Technical Advisory on Secure Package Managers: Essential DevSecOps GuidanceSecurity Affairs·Mar 12, 08:49 UTC · Mar 12, 2026AdvisoryCVE-2025-5518260
Exploitable Vulnerabilities Present in 87% of OrganizationsInfosecurity Magazine·Feb 26, 14:00 UTC · Feb 26, 2026Vulnerability in the wild60
Low-Skilled Cybercriminals Use AI to Perform “Vibe Extortion” AttacksInfosecurity Magazine·Feb 17, 13:45 UTC · Feb 17, 2026Ransomware in the wild160
Researchers Uncover 454,000+ Malicious Open Source PackagesInfosecurity Magazine·Jan 28, 11:00 UTC · Jan 28, 2026Vulnerability55
PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and BunSecurity Affairs·Jan 28, 08:43 UTC · Jan 28, 2026Exploit / PoC160
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More StoriesThe Hacker News·Dec 4, 16:05 UTC · Dec 4, 2025Phishing & fraud55
5 Threats That Reshaped Web Security This Year [2025]The Hacker News·Dec 4, 11:30 UTC · Dec 4, 2025VulnerabilityCVE-2025-54135CVE-2025-53109CVE-2025-5528460
Security Affairs newsletter Round 552 by Pierluigi PaganiniSecurity Affairs·Nov 30, 15:30 UTC · Nov 30, 2025RansomwareCVE-2025-5928760
Malicious package with AdaptixC2 framework agent found in npm registryKaspersky Securelist·Oct 17, 10:00 UTC · Oct 17, 2025Malware55
Week in review: Cisco ASA zero-day vulnerabilities exploited, Fortra GoAnywhere instances at riskHelp Net Security·Sep 28, 00:00 UTC · Sep 28, 2025Exploit / PoCCVE-2025-10035CVE-2025-59689CVE-2025-26399+1 CVEs60