Incident1.2M Sites Hit by CDN Compromise
On a Friday evening in late 2024, websites using OptinMonster began serving malicious JavaScript to visitors. The attack originated from a compromised content delivery network (CDN), not OptinMonster
Expert perspectives on application security, compliance, and emerging threats
IncidentOn a Friday evening in late 2024, websites using OptinMonster began serving malicious JavaScript to visitors. The attack originated from a compromised content delivery network (CDN), not OptinMonster
IncidentWhat Happened The Federal Trade Commission (FTC) issued a public warning to companies: if you fail to protect consumer data from exposure due to Log4j vulnerabilities, they will pursue legal action. T
IncidentOn January 9, 2022, developers worldwide faced a sudden disruption: their builds were broken. This wasn t due to a zero-day exploit or a sophisticated supply chain attack, but rather a maintainer inte
IncidentWhat Happened In December 2021, a critical vulnerability in Apache Log4j—a widely used Java logging library—allowed attackers to execute arbitrary code on vulnerable systems. This exploit, known as CV
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened Between late 2025 and June 11, 2026, attackers executed a supply chain attack against the Arch User Repository (AUR). They adopted orphaned packages—projects whose original maintainers h
IncidentOn March 15, 2022, thousands of developers running npm install unknowingly pulled malicious code into their projects. The maintainer of node-ipc—a widely-used inter-process communication library—intro
IncidentSummary of Events For over 15 years, npm allowed packages to execute arbitrary code during installation through preinstall, install, and postinstall scripts. These scripts ran automatically whenever a
IncidentOn March 30, 2022, researchers disclosed CVE-2022-22965, a critical remote code execution vulnerability in the Spring Framework. Within hours, proof-of-concept exploits circulated publicly. If your te
IncidentThe Discovery GitGuardian s analysis revealed an average of 150 secrets per developer machine. These secrets weren t found in repositories or CI/CD logs but on local workstations — hidden in shell his
IncidentSummary of the Incident A single unpatched VPN vulnerability in Marquis Software s platform compromised over seventy financial institutions. This vulnerability was present in the production infrastruc
IncidentWhat Happened Hola Browser s Windows distribution was compromised through its software supply chain, resulting in a cryptocurrency miner being bundled with legitimate installations. The malicious exec
IncidentWhat Happened On January 8, 2025, CISA added CVE-2024-21182 to its Known Exploited Vulnerabilities catalog. This vulnerability affects Oracle WebLogic Server and allows remote code execution. Oracle r
IncidentIncident Overview The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch Oracle WebLogic S
IncidentWhat Happened The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-9082, a critical SQL injection vulnerability in Drupal, to its Known Exploited Vulnerabilities (KEV) catalo
IncidentOn February 19, 2025, Ghost CMS released version 6.19.1, addressing CVE-2026-26980, a critical SQL injection vulnerability affecting versions 3.24.0 through 6.19.0. This flaw allowed attackers to read
IncidentOn a quiet Tuesday, the Laravel-Lang organization s PHP localization packages became a delivery mechanism for credential theft across Windows, Linux, and macOS systems. More than 700 compromised packa