Codenotary partners with Snyk to ensure the integrity and security of the entire software supply chainHelp Net Security·May 10, 00:00 UTC · May 10, 2023Vulnerability42
Prototype Pollution flaw discovered in all versions of Lodash LibrarySecurity Affairs·Jul 9, 17:50 UTC · Jul 9, 2019Exploit / PoCCVE-2019-1074460
Newly Discovered Bugs in VSCode Extensions Could Lead to Supply Chain AttacksThe Hacker News·May 31, 03:41 UTC · May 31, 2021Exploit / PoC57
Less Than Half of Organizations Have Open Source Security PolicyInfosecurity Magazine·Jun 23, 10:00 UTC · Jun 23, 2022Vulnerability42
Malicious NPM Packages Target German Companies in Supply Chain AttackThe Hacker News·May 12, 01:28 UTC · May 12, 2022Malware42
jQuery JavaScript library flaw opens exposes hundreds of millions of sitesSecurity Affairs·Apr 22, 17:56 UTC · Apr 22, 2019Exploit / PoCCVE-2019-11358160
Malware ships with bugs that defenders could use against itHelp Net Security·Jul 1, 03:09 UTC · Jul 1, 2026Malware42
Hades PyPI Attack: 19 Packages Poisoned to AutoThe Hacker News·Jun 9, 10:34 UTC · Jun 9, 2026Malware142
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV EcosystemInfosecurity Magazine·May 20, 15:00 UTC · May 20, 2026Data breach57
Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069The Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Ransomware57
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV FilesThe Hacker News·Mar 28, 06:25 UTC · Mar 28, 2026Malware42
Heisenberg: Open-source software supply chain health check toolHelp Net Security·Nov 3, 00:00 UTC · Nov 3, 2025Vulnerability42
Dependency-Track: Open-source component analysis platformHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2025Vulnerability42
Nagomi Security raises $30 million to help security teams improve their level of protectionHelp Net Security·Apr 25, 00:00 UTC · Apr 25, 2024Ransomware in the wild60
Popular Rust Crate liblzma-sys Compromised with XZ Utils Backdoor FilesThe Hacker News·Apr 12, 14:55 UTC · Apr 12, 2024Malware42
Node.js Users Beware: Manifest Confusion Attack Opens Door to MalwareThe Hacker News·Jul 5, 09:00 UTC · Jul 5, 2023Malware42
#SOOCon23: Open Source Tools can Automate SBOM RequirementsInfosecurity Magazine·Feb 9, 16:15 UTC · Feb 9, 2023Vulnerability42
Hackers Can Abuse Visual Studio Marketplace to Target Developers with Malicious ExtensionsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2023Ransomware57
How a pentester\'s attempt to be \'as realistic as possible\' alarmed cybersecurity firmsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Malware42
Hundreds of Amazon RDS Snapshots Discovered Leaking Users' DataInfosecurity Magazine·Nov 17, 16:00 UTC · Nov 17, 2022Threat actor57
RubyGems Makes Multi-Factor Authentication Mandatory for Top Package MaintainersThe Hacker News·Aug 17, 04:46 UTC · Aug 17, 2022Malware42
BluBracket enhances its code security solution to help enterprises protect software supply chainsHelp Net Security·Jun 6, 00:00 UTC · Jun 6, 2022Vulnerability42
Komodor raises $42 million to build a continuous reliability platform for KubernetesHelp Net Security·May 15, 00:00 UTC · May 15, 2022Industry142
Inside the numbers of another big year for cyber mergers, acquisitions and investmentsCyberScoop·Feb 9, 14:30 UTC · Feb 9, 2022Advisory42
Piiano raises $9M to secure and control PII with data privacy engineering for the cloudHelp Net Security·Oct 28, 00:00 UTC · Oct 28, 2021Data breach57
Unpatched Prototype Pollution Flaw Affects All Versions of Popular Lodash LibraryThe Hacker News·Jul 9, 16:08 UTC · Jul 9, 2019VulnerabilityCVE-2019-1074447