Wiz and Apiiro partner to provide context-driven security from code to cloudHelp Net Security·Dec 19, 00:00 UTC · Dec 19, 2023Vulnerability55
CISA Flags Actively Exploited Gogs Vulnerability With No PatchInfosecurity Magazine·Jan 13, 16:45 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-8110CVE-2024-5594760
Wiz Discovers Flaws in GenAI Models Enabling Customer Data TheftInfosecurity Magazine·Apr 5, 13:15 UTC · Apr 5, 2024Vulnerability55
Nuclei flaw allows signature bypass and code executionSecurity Affairs·Jan 5, 19:06 UTC · Jan 5, 2025VulnerabilityCVE-2024-4340560
Vulnerability prioritization is only the beginningHelp Net Security·Aug 23, 00:00 UTC · Aug 23, 2024Vulnerability55
Google AI Threat Defense targets attackers using AI to find flaws fasterHelp Net Security·Jul 9, 05:49 UTC · Jul 9, 2026Vulnerability55
CISA Warns of Active Exploitation of Gogs Vulnerability Enabling Code ExecutionThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-8110CVE-2024-5594760
Redis patches 13-Year-Old Lua flaw enabling Remote Code ExecutionSecurity Affairs·Oct 8, 09:10 UTC · Oct 8, 2025VulnerabilityCVE-2025-4984460
Redis patches critical "RediShell" RCE vulnerability, update ASAP! (CVE-2025-49844)Help Net Security·Oct 7, 00:00 UTC · Oct 7, 2025Vulnerability in the wildCVE-2025-4984460
NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI ServersThe Hacker News·Aug 6, 09:08 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2025-23319CVE-2025-23320CVE-2025-23334+3 CVEs60
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain RisksThe Hacker News·Oct 31, 07:59 UTC · Oct 31, 2025Ransomware60
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git PushThe Hacker News·Apr 28, 18:19 UTC · Apr 28, 2026VulnerabilityCVE-2026-3854160
Google Makes CodeMender Available as Managed AI Security AgentInfosecurity Magazine·Jul 22, 10:30 UTC · Jul 22, 2026Exploit / PoC60
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs60
Critical Ingress NGINX Controller Vulnerability Allows RCE Without AuthenticationThe Hacker News·Apr 10, 06:49 UTC · Apr 10, 2025VulnerabilityCVE-2025-24513CVE-2025-24514CVE-2025-1097+2 CVEs60
CVE-2026-3854 GitHub flaw enables remote code executionSecurity Affairs·Apr 28, 20:44 UTC · Apr 28, 2026VulnerabilityCVE-2026-385460
Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026The Hacker News·Jun 4, 11:51 UTC · Jun 4, 2026Vulnerability in the wildCVE-2026-23479160
GitHub Action Compromise Puts CI/CD Secrets at Risk in Over 23,000 RepositoriesThe Hacker News·Mar 18, 04:03 UTC · Mar 18, 2025VulnerabilityCVE-2025-30066CVE-2023-49291160
Massive supply-chain attack compromises 440 packages under four hoursCyberScoop·Aug 4, 22:07 UTC · Aug 4, 2026Exploit / PoC60
Microsoft AI researchers exposed sensitive signing keys, internal messagesCyberScoop·Sep 18, 18:55 UTC · Sep 18, 2023Data breach in the wild60
A flaw in Microsoft Azure App Service exposes customer source codeSecurity Affairs·Dec 23, 05:36 UTC · Dec 23, 2021Exploit / PoC in the wild160
Developers scramble as critical React flaw threatens major appsCyberScoop·Dec 3, 19:23 UTC · Dec 3, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-6647860
13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code RemotelyThe Hacker News·Oct 7, 09:30 UTC · Oct 7, 2025Vulnerability in the wildCVE-2025-4984460
Threat Brief: OMI Vulnerabilities (CVE-2021-38645, CVE-2021-38647, CVE-2021-38648 and CVE-2021Palo Alto Unit 42·Jun 6, 01:21 UTC · Jun 6, 2024VulnerabilityCVE-2021-38645CVE-2021-38647CVE-2021-38648+1 CVEs160
Chaining NVIDIA's Triton Server flaws exposes AI systems to remote takeoverSecurity Affairs·Aug 5, 07:35 UTC · Aug 5, 2025VulnerabilityCVE-2025-23319CVE-2025-23320CVE-2025-2333460
IngressNightmare: Four Critical Bugs Found in 40% of Cloud SystemsInfosecurity Magazine·Mar 25, 09:30 UTC · Mar 25, 2025VulnerabilityCVE-2025-1097CVE-2025-1098CVE-2025-24514+1 CVEs60
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026The Hacker News·May 3, 06:26 UTC · May 3, 2026Advisory in the wildCVE-2026-3143160
Wiz partners with Contrast Security to provide real-time insights into potential security risksHelp Net Security·Jun 14, 00:00 UTC · Jun 14, 2023Vulnerability55
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential TheftThe Hacker News·Nov 25, 03:51 UTC · Nov 25, 2025Vulnerability55
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Week in review: Terrapin SSH attack, Mr. Cooper breachHelp Net Security·Dec 24, 00:00 UTC · Dec 24, 2023RansomwareCVE-2023-48795CVE-2020-1488360
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure ToolThe Hacker News·Jun 25, 03:22 UTC · Jun 25, 2024VulnerabilityCVE-2024-37032CVE-2024-2247660
String of defects in popular Kubernetes component puts 40% of cloud environments at riskCyberScoop·Mar 26, 22:39 UTC · Mar 26, 2025Exploit / PoC in the wildCVE-2025-1974CVE-2025-1097CVE-2025-1098+2 CVEs60
Experts Find Flaw in Replicate AI Service Exposing Customers' Models and DataThe Hacker News·May 27, 05:55 UTC · May 27, 2024Data breach in the wild60
Wiz Uncovers Critical Access Bypass Flaw in AIThe Hacker News·Jul 30, 07:43 UTC · Jul 30, 2025Exploit / PoC in the wild60
Shai-Hulud worm returns stronger and more automated than ever beforeCyberScoop·Nov 24, 22:45 UTC · Nov 24, 2025Data breach in the wild60
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain AttacksThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wild60
SAP-Related npm Packages Compromised in CredentialThe Hacker News·Apr 30, 16:39 UTC · Apr 30, 2026Data breach60
Google acquires Wiz for $32 billionCyberScoop·Mar 18, 14:30 UTC · Mar 18, 2025Exploit / PoC in the wild160