CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without CredentialsThe Hacker News·Aug 10, 08:02 UTC · Aug 10, 2025RansomwareCVE-2025-49827CVE-2025-49831CVE-2025-49828+3 CVEs60
Backblaze B2 Cloud Storage platform delivers enhanced security and performance upgradesHelp Net Security·May 27, 00:00 UTC · May 27, 2021Ransomware57
Cryptojacking Campaign Targets DevOps Servers Including NomadInfosecurity Magazine·Jun 2, 15:00 UTC · Jun 2, 2025Threat actorCVE-2020-14144160
Cryptojacking campaign relies on DevOps toolsSecurity Affairs·Jun 3, 07:17 UTC · Jun 3, 2025Threat actorCVE-2020-14144260
Cryptojacking Campaign Exploits DevOps APIs Using Off-theThe Hacker News·Jun 3, 07:04 UTC · Jun 3, 2025Threat actorCVE-2020-14144160
Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New AttacksThe Hacker News·Nov 26, 04:36 UTC · Nov 26, 2024Research42
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4855860
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Attackers already know the secrets are on your developers' machines. Do you?Help Net Security·Jun 4, 00:00 UTC · Jun 4, 2026Threat actor57
Red Hat npm packages compromised in new Mini Shai-Hulud malware waveHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Malware42
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud SecretsThe Hacker News·May 31, 12:15 UTC · May 31, 2026Data breach157
Laravel-Lang PHP Packages Compromised to Deliver CrossThe Hacker News·May 24, 08:14 UTC · May 24, 2026Malware42
GitLab 19.0 adds AI workflows, secrets management, and self-hosted model supportHelp Net Security·May 22, 00:00 UTC · May 22, 2026Advisory42
Grafana Labs Says Code Breach Stemmed from TanStack AttackInfosecurity Magazine·May 21, 08:00 UTC · May 21, 2026Ransomware57
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromiseHelp Net Security·May 21, 00:00 UTC · May 21, 2026Vulnerability142
Brutus: Open-source credential testing tool for offensive securityHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2026Malware42
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware ChainsThe Hacker News·Oct 30, 09:40 UTC · Oct 30, 2025Malware142
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT DevicesThe Hacker News·Oct 29, 15:38 UTC · Oct 29, 2025Malware in the wildCVE-2017-9841CVE-2021-3129CVE-2022-47945+2 CVEs160
whoAMI attack could allow remote code execution within AWS accountSecurity Affairs·Feb 17, 10:50 UTC · Feb 17, 2025Vulnerability42
New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code ExecutionThe Hacker News·Feb 17, 03:43 UTC · Feb 17, 2025Vulnerability42
Securing GitHub Actions for a safer DevOps pipelineHelp Net Security·Oct 2, 00:00 UTC · Oct 2, 2023Vulnerability42
AWS fixes vulnerability affecting container image repositoryThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Vulnerability42
Rapid7 Source Code Breached in Codecov SupplyThe Hacker News·May 15, 00:00 UTC · May 15, 2021Data breach57
Baffle integrates with Tableau Software to protect data analytics pipelineHelp Net Security·Aug 5, 00:00 UTC · Aug 5, 2020Data breach57