ZDResearch Advanced Web Hacking Training 2018The Hacker News·Sep 25, 13:16 UTC · Sep 25, 2018Exploit / PoC60
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
FBI removes web shells from hacked Microsoft Exchange serversHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2021Exploit / PoC160
International dark web FBI sting launched 'to send a message'CyberScoop·Nov 3, 17:46 UTC · Nov 3, 2016Exploit / PoC in the wild60
UAT-5918 targets critical infrastructure entities in TaiwanCisco Talos·Mar 20, 10:00 UTC · Mar 20, 2025Exploit / PoC60
Radware Cloud Web DDoS Protection blocks Tsunami DDoS attacksHelp Net Security·May 23, 00:00 UTC · May 23, 2023Exploit / PoC60
File upload security best practices rarely implemented to protect web applicationsHelp Net Security·Aug 30, 00:00 UTC · Aug 30, 2021Exploit / PoC60
Cyemptive Web Fortress protects web servers against zero-day cyberattacks in real timeHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2021Exploit / PoC60
The dark web isn't quite the criminal haven you may think it isCyberScoop·Nov 2, 11:43 UTC · Nov 2, 2016Exploit / PoC in the wild60
New Apache Web Server Bug Threatens Security of Shared Web HostsThe Hacker News·Apr 3, 09:07 UTC · Apr 3, 2019Exploit / PoCCVE-2019-0211CVE-2019-0217CVE-2019-021560
Discover Why Proactive Web Security Outsmarts Traditional Antivirus SolutionsThe Hacker News·Nov 29, 09:21 UTC · Nov 29, 2023Exploit / PoC60
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
FBI silently removed web shells planted on Microsoft Exchange serversSecurity Affairs·Apr 14, 10:20 UTC · Apr 14, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
New Critical SAP NetWeaver Flaw Exploited to Drop Web Shell, Brute Ratel FrameworkThe Hacker News·May 6, 13:53 UTC · May 6, 2025Exploit / PoC in the wildCVE-2017-9844CVE-2025-31324CVE-2017-1263760
Gcore WAAP protects websites, web applications, and APIsHelp Net Security·Sep 17, 00:00 UTC · Sep 17, 2024Exploit / PoC60
Absolute Software expands its SSE solution with Absolute Secure Web Gateway ServiceHelp Net Security·Nov 21, 14:32 UTC · Nov 21, 2023Exploit / PoC60
Respond Software adds web filtering investigation and discovery capabilities to its Respond Analyst solutionHelp Net Security·Oct 30, 00:00 UTC · Oct 30, 2019Exploit / PoC60
Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7Palo Alto Unit 42·Nov 6, 12:34 UTC · Nov 6, 2018Exploit / PoCCVE-2018-8174CVE-2009-0075CVE-2008-4844+3 CVEs60
Asia's hackers are finding a home on the dark webCyberScoop·Aug 8, 16:45 UTC · Aug 8, 2018Exploit / PoC in the wild60
Schneider Electric Development Tools InduSoft Web Studio and InTouch Machine Edition are affected by a critical buffer flawSecurity Affairs·May 3, 12:46 UTC · May 3, 2018Exploit / PoC60
SafeLine WAF: Open Source Web Application Firewall with ZeroThe Hacker News·May 23, 10:30 UTC · May 23, 2025Exploit / PoC60
CISA adds SolarWinds Web Help Desk bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 16, 20:13 UTC · Aug 16, 2024Exploit / PoC in the wildCVE-2024-2898660
Sophos Web Appliance vulnerability exploited in the wild (CVE-2023-1671)Help Net Security·Nov 22, 09:12 UTC · Nov 22, 2023Exploit / PoC in the wildCVE-2023-1671CVE-2020-255160
US CISA adds Centos Web Panel RCE CVE-2022-44877 to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Jan 19, 09:48 UTC · Jan 19, 2023Exploit / PoC in the wildCVE-2022-4487760
Hafnium Update: Continued Microsoft Exchange Server ExploitationCisco Talos·Mar 10, 00:52 UTC · Mar 10, 2021Exploit / PoC60
Flaw in Evernote Web Clipper for Chrome extension allows stealing dataSecurity Affairs·Jun 13, 07:29 UTC · Jun 13, 2019Exploit / PoCCVE-2019-1259260
5 Popular Web Hosting Services Found Vulnerable to Multiple FlawsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2019Exploit / PoC60
Dark web intelligence firm Terbium Labs raises $6 millionCyberScoop·Nov 30, 18:25 UTC · Nov 30, 2017Exploit / PoC in the wild60
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web ManagerSecurity Affairs·Dec 19, 08:53 UTC · Dec 19, 2025Exploit / PoC in the wildCVE-2025-2039360
Hacking forums survive cybercrime dragnet as feds prioritize drugCyberScoop·May 16, 11:01 UTC · May 16, 2019Exploit / PoC in the wild60
Attackers abuse SolarWinds Web Help Desk to install Zoho agents and VelociraptorSecurity Affairs·Feb 9, 12:28 UTC · Feb 9, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-26399CVE-2025-4053660
U.S. CISA adds SolarWinds Web Help Desk, Sangoma FreePBX, and GitLab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 3, 21:06 UTC · Feb 3, 2026Exploit / PoC in the wildCVE-2019-19006CVE-2021-39935CVE-2025-40551+1 CVEs60
⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AIThe Hacker News·Jan 20, 09:20 UTC · Jan 20, 2026Exploit / PoCCVE-2025-29824CVE-2025-2775CVE-2025-2776+19 CVEs60
SolarWinds fixed hardcoded credential issue in Web Help DeskSecurity Affairs·Aug 22, 17:29 UTC · Aug 22, 2024Exploit / PoC in the wildCVE-2024-28987CVE-2024-2898660
Global 'Operation Dark HunTor' dark web sting leads to 150 arrestsCyberScoop·Oct 26, 15:40 UTC · Oct 26, 2021Exploit / PoC in the wild60