Incident13,000 Projects Hit by a Single Regex
What Happened On June 2, 2020, security researcher Robert McLaughlin discovered a Regular Expression Denial-of-Service (ReDoS) vulnerability in the websocket-extensions package using an automated tool
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened On June 2, 2020, security researcher Robert McLaughlin discovered a Regular Expression Denial-of-Service (ReDoS) vulnerability in the websocket-extensions package using an automated tool
IncidentWhat Happened On March 27, 2020, Danny Thomas disclosed CVE-2020-7599 , a vulnerability in Gradle s plugin-publish plugin that exposed pre-signed AWS URLs in log output. Every version below 0.11.0 was
IncidentWhat Happened The Snyk Research Team discovered an arbitrary code execution vulnerability in Grunt, a widely-used JavaScript task runner that automates development tasks. The vulnerability, CVE-2020-7
IncidentWhat Happened In 2020, security researcher po6ix discovered a prototype pollution vulnerability in express-fileupload, a Node.js package for handling file uploads. Snyk confirmed the finding and assig
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat happened On March 11th, 2020, Snyk disclosed CVE-2020-7598 , a prototype pollution vulnerability in minimist, an npm package that parses command-line arguments. The package sees roughly 1 million
IncidentA Zip Slip vulnerability in the Golang package go-rpmutils could have allowed attackers to write arbitrary files outside intended directories during archive extraction. The vulnerability, tracked as C
IncidentOn June 7, attackers sent 4 million requests through a single unauthenticated REST API endpoint in the Gravity SMTP WordPress plugin. By that point, the vulnerability had been public for nearly three
IncidentA Major Shift in Security Priorities On September 24, 2021, OWASP released an updated Top 10 list that significantly altered the landscape of security priorities. SQL injection, which had long been a
IncidentWhat Happened In 2020, researcher Yeting Li discovered a Regular Expression Denial of Service (REDoS) vulnerability in UAParser.js, a widely-used JavaScript library for parsing user agent strings. The
IncidentA malicious web page executing arbitrary code on your development machine through your AI agent—that s exactly what Microsoft researchers discovered in AutoGen Studio s pre-release builds. The AutoJac
IncidentWhat Happened CVE-2026-4020 , a vulnerability in the Gravity SMTP WordPress plugin, allows unauthenticated attackers to extract API keys and SMTP configuration data through a broken access control fla
IncidentOn January 9, 2025, attackers compromised the npm account of a Mastra AI maintainer and published malicious updates to over 140 packages. Microsoft attributes the attack to Sapphire Sleet, a North Kor
IncidentF5 disclosed two critical remote code execution vulnerabilities in NGINX Open Source on January 14, 2025. Both CVE-2026-42530 and CVE-2026-42055 carry CVSS v4 scores of 9.2. If your team is running NG
IncidentWhat Happened Researchers at Hong Kong University of Science and Technology have discovered a denial-of-service attack that exploits AI agent safety systems. This attack, known as reasoning-extension
IncidentYour security information and event management (SIEM) platform should detect intrusions, not enable them. However, in June 2026, organizations running unpatched Splunk Enterprise found themselves in a
IncidentWhat Happened Varonis Threat Labs revealed a prompt injection attack against Microsoft M365 Copilot Enterprise that exposed internal corporate data through manipulated URL parameters. The attack, call