Friday Squid Blogging: Illegal North Korean Squid FishingSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Exploit / PoCCVE-2018-865360
Week in review: Windows kernel flaw patched, suspected Fortinet FortiWeb zero-day exploitedHelp Net Security·Nov 16, 00:00 UTC · Nov 16, 2025Exploit / PoC in the wildCVE-2025-12480CVE-2025-21042CVE-2025-62215+2 CVEs60
Kaspersky Security Bulletin 2006: Internet AttacksKaspersky Securelist·Feb 27, 20:48 UTC · Feb 27, 2007Advisory in the wildCVE-2005-1921CVE-2005-0116CVE-2005-195060
Parasite HTTP RAT implements a broad range of protections and evasion mechanismsSecurity Affairs·Jul 28, 09:27 UTC · Jul 28, 2018Malware55
MysterySnail attacks with Windows zeroKaspersky Securelist·Oct 13, 14:49 UTC · Oct 13, 2021Exploit / PoCCVE-2016-3309CVE-2021-4044960
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
Researcher Explains Release of Undisclosed ZeroInfosecurity Magazine·Jul 2, 12:51 UTC · Jul 2, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2026-58049CVE-2026-58050+10 CVEs160
Frebniis Malware Exploits Microsoft IIS FeatureInfosecurity Magazine·Feb 20, 16:00 UTC · Feb 20, 2023Malware55
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
MixShell Malware Delivered via Contact Forms Targets U.S. Supply Chain ManufacturersThe Hacker News·Aug 28, 08:41 UTC · Aug 28, 2025Malware55
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
Google warns of Brickstorm backdoor targeting U.S. legal and tech sectorsSecurity Affairs·Sep 26, 07:04 UTC · Sep 26, 2025Malware55
New VPNFilter malware targets at least 500K networking devices worldwideCisco Talos·May 23, 13:00 UTC · May 23, 2018Malware55
CactusPete APT group’s updated Bisonal backdoorKaspersky Securelist·Aug 13, 10:00 UTC · Aug 13, 2020MalwareCVE-2018-817460
Docker fixes critical Desktop flaw allowing container escapesSecurity Affairs·Aug 25, 22:30 UTC · Aug 25, 2025Exploit / PoCCVE-2025-9074160
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 CrossThe Hacker News·Aug 5, 14:27 UTC · Aug 5, 2026Vulnerability in the wildCVE-2026-58073CVE-2026-58072CVE-2026-58067+10 CVEs160
Critical RCE Flaw Found in OpenVPN that Escaped Two Recent Security AuditsThe Hacker News·Jun 22, 08:19 UTC · Jun 22, 2017VulnerabilityCVE-2017-7521CVE-2017-7520CVE-2017-7508+1 CVEs60
Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3The Hacker News·Aug 25, 17:53 UTC · Aug 25, 2025VulnerabilityCVE-2025-9074160
Chinese APT Weaver Ant infiltrated a telco for over four yearsSecurity Affairs·Mar 24, 20:36 UTC · Mar 24, 2025Vulnerability55
Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and MalwareThe Hacker News·Jul 29, 09:05 UTC · Jul 29, 2025MalwareCVE-2023-38950CVE-2023-38951CVE-2023-3895260
Malicious package with AdaptixC2 framework agent found in npm registryKaspersky Securelist·Oct 17, 10:00 UTC · Oct 17, 2025Malware55
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory LeakThe Hacker News·May 11, 18:23 UTC · May 11, 2026VulnerabilityCVE-2026-7482CVE-2026-42248CVE-2026-4224960
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News·Jun 29, 14:42 UTC · Jun 29, 2026Malware in the wildCVE-2026-43503CVE-2026-12569CVE-2026-47729+19 CVEs60
CL-STA-1087 targets military capabilities since 2020Security Affairs·Mar 17, 12:03 UTC · Mar 17, 2026Data breach60
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
Chinese Hackers Breach Asian Telecom, Remain Undetected for Over 4 YearsThe Hacker News·Mar 26, 04:30 UTC · Mar 26, 2025Data breach60
How Kaspersky Lab Disabled the Hlux/Kelihos BotnetKaspersky Securelist·Sep 28, 23:53 UTC · Sep 28, 2011Malware55
Week in review: Fake ChatGPT desktop client steals data, Patch Tuesday forecastHelp Net Security·May 7, 00:00 UTC · May 7, 2023VulnerabilityCVE-2023-20126CVE-2018-9995CVE-2016-20016+1 CVEs60
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology SectorsThe Hacker News·Sep 25, 15:04 UTC · Sep 25, 2025MalwareCVE-2023-46805CVE-2024-2188760
NGINX Rift: an 18-year-old flaw in the world's most deployed web server just came to lightSecurity Affairs·May 14, 13:30 UTC · May 14, 2026Exploit / PoC in the wildCVE-2026-42945CVE-2026-42946CVE-2026-40701+1 CVEs60
Cisco Prime Home flaw allows hackers to reach into people's homesHelp Net Security·Dec 14, 13:29 UTC · Dec 14, 2023Exploit / PoCCVE-2017-379160
Equation Group: from Houston with loveKaspersky Securelist·Feb 19, 09:00 UTC · Feb 19, 2015Vulnerability55
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persistCisco Talos·Apr 22, 10:00 UTC · Apr 22, 2026Phishing & fraud55
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-ofThe Hacker News·Jul 2, 15:49 UTC · Jul 2, 2026Vulnerability in the wildCVE-2026-8451CVE-2026-8452CVE-2026-8655+4 CVEs60
Threat Assessment: Black Basta RansomwarePalo Alto Unit 42·Jun 5, 17:55 UTC · Jun 5, 2024Ransomware60
QakBot Banking malware causes massive Active Directory lockoutsSecurity Affairs·Jun 4, 09:14 UTC · Jun 4, 2017Malware55
A cascade of compromise: unveiling Lazarus' new campaignKaspersky Securelist·Oct 27, 05:41 UTC · Oct 27, 2023Threat actor160
VPNFilter III: More Tools for the Swiss Army Knife of MalwareCisco Talos·Sep 26, 14:59 UTC · Sep 26, 2018Malware55