OverDoS: Taking Down Over 70,000 n8n Instances 2026-05-12 True Ori Ron True Same Origin, Same Tricks: Bypassing n8n’s CSP Sandbox (CVE-2026-27578) 2026-04-06 True Ori Ron True Rapid Exploitation and Clever Malware in the Supply Chain, Last Week In AppSec (2026-04-02) 2026-04-02 True Darren Meyer True GlassWorm Targets Developer IDEs Again, Hiding Staged Malware Behind Runtime-Rebuilt Loaders 2026-03-23 True Daniel Miranda True Unearned Confidence: AI Security Reviewers Don’t Really Get It 2026-03-05 True Alon Lerner True AI fights and more attacks on dev infrastructure: Last Week in AppSec for 4. March 2026 2026-03-05 True Darren Meyer True Last Week in AppSec for 26. February 2026 2026-02-26 True Darren Meyer True Learning About LLM-Based Zero-Day Hunting with Claude Code’s Opus 4.6 2026-02-25 True Ori Ron True Protecting yourself against malicious open-source packages 2026-02-19 True Darren Meyer True Last Week in AppSec for 12. Feb 2026 2026-02-12 True Darren Meyer True Last Week in AppSec for 12. Feb 2026 2026-02-12 True Darren Meyer True Solidity devs targeted again: Malicious VS Code extension drops ScreenConnect-based remote access trojan (RAT) 2026-01-29 True Daniel Miranda True Last Week in AppSec for 29. January 2026 2026-01-29 True Darren Meyer True Last Week in AppSec for 15. January 2026 2026-01-15 True Darren Meyer True Last Week in AppSec for 08. January 2026 2026-01-07 True Darren Meyer True AI Model Confusion: An LLM/AI Model Supply Chain Attack 2026-01-06 True Ori Ron True Turning AI Safeguards Into Weapons with HITL Dialog Forging 2025-12-16 True Ori Ron True Cybersecurity AI agent is Vulnerable to Command Injection (CVE-2025-67511) 2025-12-11 True Darren Meyer True Inside Shai-Hulud’s Maw: How The NPM Worm Exploits And Propagates 2025-12-09 True Bruno Dias True Taking Down More Malicious VSCode Extensions in the ‘Prettier’ Campaign 2025-12-05 True Darren Meyer True React2Shell (CVE-2025-55182) Deserialization to Remote Code Execution in React and Next.js 2025-12-04 True Alex Shleymovich True Exploiting Markdown Injection in AI agents: Microsoft Copilot Chat and Google Gemini 2025-12-04 True Ori Ron True Last Week in AppSec for 02. December 2025 2025-12-01 True Darren Meyer True 11 Emerging AI Security Risks with MCP (Model Context Protocol) 2025-11-25 True Tal Folkman True How we take down malicious Visual Studio Code extensions 2025-11-13 True Daniel Miranda True Last Week in AppSec for 11. November 2025 2025-11-11 True Darren Meyer True Last Week in AppSec for 04. November 2025 2025-11-04 True Darren Meyer True Last Week in AppSec for 28. October 2025 2025-10-28 True Darren Meyer True Last Week in AppSec for 21. October 2025 2025-10-21 True Darren Meyer True Last Week In AppSec for 14. October 2025 2025-10-14 True Darren Meyer True Last Week in AppSec for 07. October 2025 2025-10-07 True Darren Meyer True NPM Malware Alert: `@lanyer640/mcp-runcommand-server` with Reverse Shell 2025-10-02 True Darren Meyer True Last Week in AppSec for 30. September 2025 2025-09-30 True Darren Meyer True When Vigilance Causes an Outage: The NPM Stylus Package Outage 2025-07-29 True Rom Gotshal True Last Week in AppSec for 29. July 2025 2025-07-29 True Darren Meyer True Last Week in AppSec for 22. July 2025 2025-07-22 True Darren Meyer True Supply Chain Phishing Campaign Drops More Malware Into NPM: got-fetch 5.1 2025-07-21 True Tal Folkman True Last Week in AppSec for 15. July 2025 2025-07-15 True Darren Meyer True Last Week In AppSec for 08. July 2025 2025-07-08 True Darren Meyer True EchoLeak (CVE-2025-32711) Show us That AI Security is Challenging 2025-07-02 True Joao Cunha da Silva True PyPI Supply Chain Attack Uncovered: Colorama and Colorizr Name Confusion 2025-05-28 True Darren Meyer True CVE-2025-27520 Critical RCE In BentoML Has Fewer Affected Versions Than Reported 2025-04-10 True Bruno Dias True The Glass Sandbox – The Complexity of Python Sandboxing 2025-03-26 True Alex Shleymovich True Behind the Middleware Curtain — Explaining CVE-2025-29927, A Critical Authorization Bypass in Next.js 2025-03-25 True Raphael Silva True Find and Fix CVE-2025-30066, Compromised GitHub Actions Leading to Credential Leaks 2025-03-18 True Darren Meyer True Understanding Vulnerability Hunting and its Challenges 2025-02-04 True Davide Ferreira True Skibidi Java – The Infinite Loop in Java Collections; Edge Case to Java Universal DoS 2025-01-23 True Eilon Cohen True NPM command confusion 2025-01-14 True Eugene Rojavski True November 2024 in Software Supply Chain Security 2024-12-10 True Yehuda Gelb True