Security news for developers, not just security teams.
HackTribune turns supply-chain incidents, framework advisories, and malicious package reports into searchable incident pages, watchlists, and upgrade-worthy alerts.
Latest incidents
View all →A Blackstone real estate company exposed SSN digits, DOBs, addresses and more
jss: jss: JSSTrustManager does not verify NSS trust flags on CA certificates
jss: jss: JSSTrustManager does not verify NSS trust flags on CA certificates
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
https://www.oracle.com/security-alerts/cpujan2026.html ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-21962
Moon (2024)
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
Sakai Conversations has a Stored XSS Issue
Sakai Conversations has a Stored XSS Issue
org.sakaiproject.conversations:sakai-conversations-impl: ≥ 23.0