Security news for developers, not just security teams.
HackTribune turns supply-chain incidents, framework advisories, and malicious package reports into searchable incident pages, watchlists, and upgrade-worthy alerts.
Latest incidents
View all →Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Google stole open source code without crediting the authors (Artemis/Minitap)
CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary fi
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configu
libvirt: Unsafe chown in qemuTPMEmulatorPrepareHost() allows arbitrary file ownership change via symlink
libvirt: Unsafe chown in qemuTPMEmulatorPrepareHost() allows arbitrary file ownership change via symlink