What we know about the xz Utils backdoor that almost infected the worldArs Technica · Security·Apr 1, 06:55 UTC · Apr 1, 2024Malware55
Backdoor in XZ Utils That Almost HappenedSchneier on Security·Apr 15, 00:00 UTC · Apr 15, 2024Malware155
Beware! Backdoor found in XZ utilities used by many Linux distros (CVE-2024-3094)Help Net Security·Apr 8, 13:25 UTC · Apr 8, 2024VulnerabilityCVE-2024-309460
Researchers stop ‘credible takeover attempt’ similar to XZ Utils backdoor incidentThe Record·Apr 15, 19:44 UTC · Apr 15, 2024Malware55
Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images, Fueling Supply Chain RisksThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025MalwareCVE-2024-309460
Week in review: Backdoor found in XZ utilities, weaponized iMessages, Exchange servers at riskHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2024Malware in the wildCVE-2024-3094CVE-2023-48022CVE-2023-2495560
Open Source Leaders Warn of XZ UtilsInfosecurity Magazine·Apr 16, 10:15 UTC · Apr 16, 2024Vulnerability55
Focus on what matters most: Exposure management and your attack surfaceHelp Net Security·Apr 8, 17:17 UTC · Apr 8, 2025Exploit / PoCCVE-2024-340060
Focus on What Matters Most: Exposure Management and Your Attack SurfaceThe Hacker News·Aug 23, 10:55 UTC · Aug 23, 2024Exploit / PoCCVE-2024-340060
OpenJS Foundation Targeted in Potential JavaScript Project Takeover AttemptThe Hacker News·Apr 17, 05:00 UTC · Apr 17, 2024Vulnerability55
Paid open-source maintainers spend more time on securityHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2024Vulnerability55
Polyfill, Cloudflare trade barbs after reports of supply chain attack threatening 100,000 websitesThe Record·Jun 27, 00:00 UTC · Jun 27, 2024Vulnerability55
Third-Party Cyber Attacks: The Threat No One Sees ComingThe Hacker News·Jul 30, 09:59 UTC · Jul 30, 2024Ransomware60
⚡ Weekly Recap: NFC Fraud, Curly COMrades, NThe Hacker News·Nov 20, 10:46 UTC · Nov 20, 2025Phishing & fraud in the wildCVE-2025-8875CVE-2025-8876CVE-2025-26633+36 CVEs60
Week in review: Palo Alto Networks firewalls under attack, Microsoft patches two exploited zero-daysHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2024Exploit / PoC in the wildCVE-2024-3400CVE-2024-29988CVE-2024-26234+1 CVEs60
Establishing a security baseline for open source projectsHelp Net Security·May 13, 00:00 UTC · May 13, 2024Vulnerability55
SSHamble: Open-source security testing of SSH servicesHelp Net Security·Aug 8, 00:00 UTC · Aug 8, 2024Vulnerability55
Leveraging Wazuh for Zero Trust securityThe Hacker News·Nov 5, 11:00 UTC · Nov 5, 2024Data breach in the wildCVE-2024-309460
New open-source project takeover attacks spotted, stymiedHelp Net Security·Apr 16, 00:00 UTC · Apr 16, 2024Vulnerability55
Senate Intel chair urges national cyber director to safeguard against openCyberScoop·Dec 18, 18:35 UTC · Dec 18, 2025Exploit / PoC in the wild60
Review of supply chain attacks in 2024 and potential disruption scenarios for 2025Kaspersky Securelist·Dec 9, 10:54 UTC · Dec 9, 2024Data breach in the wild60
Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain AttackThe Hacker News·Jun 28, 04:05 UTC · Jun 28, 2024VulnerabilityCVE-2024-34102CVE-2024-296160
Advanced threat predictions for 2025Kaspersky Securelist·Nov 25, 10:02 UTC · Nov 25, 2024Exploit / PoCCVE-2024-23222CVE-2024-23225CVE-2024-23296+3 CVEs60
A little-known npm package was North Korea’s warmCyberScoop·Jul 29, 21:09 UTC · Jul 29, 2026Exploit / PoC in the wild60
What public money does to open-source projectsHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026Vulnerability55
EU unveils tech sovereignty package to cut reliance on US, Chinese suppliersThe Record·Jun 5, 13:43 UTC · Jun 5, 2026Vulnerability55
Shai-Hulud worm returns stronger and more automated than ever beforeCyberScoop·Nov 24, 22:45 UTC · Nov 24, 2025Data breach in the wild60
What happens when vulnerability scores fall apart?Help Net Security·Nov 24, 00:00 UTC · Nov 24, 2025Vulnerability55
The npm incident frightened everyone, but ended up being nothing to fret aboutCyberScoop·Sep 10, 14:35 UTC · Sep 10, 2025Exploit / PoC in the wild60
Security Affairs newsletter Round 537 by Pierluigi PaganiniSecurity Affairs·Aug 17, 00:26 UTC · Aug 17, 2025Ransomware in the wildCVE-2025-2525660
Unverified code is the next national security threatCyberScoop·Jun 9, 15:56 UTC · Jun 9, 2025Exploit / PoC in the wild60
Here’s how carefully concealed backdoor in fake AWS files escaped mainstream noticeArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2024Malware55
New OpenSSH Vulnerability Could Lead to RCE as Root on Linux SystemsThe Hacker News·Jul 9, 04:22 UTC · Jul 9, 2024VulnerabilityCVE-2024-6387CVE-2006-5051CVE-2008-410960
New 'Siren' mailing list aims to share threat intelligence for open source projectsThe Record·May 20, 14:20 UTC · May 20, 2024Exploit / PoC60
Week in review: Palo Alto firewalls mitigation ineffective, PuTTY client vulnerable to key recovery attackHelp Net Security·Apr 21, 00:00 UTC · Apr 21, 2024RansomwareCVE-2024-3400CVE-2024-31497CVE-2024-29204+1 CVEs60
What’s the deal with the massive backlog of vulnerabilities at the NVD?Cisco Talos·Apr 19, 14:30 UTC · Apr 19, 2024Vulnerability in the wild60
Other Attempts to Take Over Open Source ProjectsSchneier on Security·Apr 18, 11:06 UTC · Apr 18, 2024Vulnerability55