Scientists Think They’ve Uncovered the 15-Million-Year404 Media·Jun 27, 17:02 UTC · Jun 27, 2026Exploit / PoC45
FortiBleed Exposes Admin Passwords for 75,000 Fortinet FirewallsSecurity Affairs·Jun 18, 07:31 UTC · Jun 18, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt StrikeThe Hacker News·May 26, 05:19 UTC · May 26, 2026Exploit / PoCCVE-2026-542660
Exaforce raises $125 million to respond to AI-powered attacksHelp Net Security·May 12, 00:00 UTC · May 12, 2026Exploit / PoC60
A dozen allied agencies say China is building covert hacker networks out of everyday routersCyberScoop·Apr 23, 16:13 UTC · Apr 23, 2026Exploit / PoC in the wild60
CISA Confirms Active Exploitation of FileZen CVE-2026The Hacker News·Feb 25, 05:23 UTC · Feb 25, 2026Exploit / PoC in the wildCVE-2026-2510860
CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV UpdateThe Hacker News·Feb 24, 15:30 UTC · Feb 24, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2024-7694CVE-2020-7796+1 CVEs60
U.S. CISA adds Dell RecoverPoint and GitLab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 19, 15:16 UTC · Feb 19, 2026Exploit / PoC in the wildCVE-2021-22175CVE-2026-22769CVE-2020-779660
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root AccessThe Hacker News·Jan 27, 08:53 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2026-2406160
Monitoring Tool Nezha Abused For Stealthy PostInfosecurity Magazine·Dec 22, 14:30 UTC · Dec 22, 2025Exploit / PoC145
Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 releasedHelp Net Security·Dec 21, 00:00 UTC · Dec 21, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-40602CVE-2025-14174+1 CVEs160
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency MitigationThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-55182CVE-2021-4422860
JPCERT Confirms Active Command Injection Attacks on Array AG GatewaysThe Hacker News·Dec 9, 07:35 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2023-28461CVE-2025-6664460
Too many Cisco ASA firewalls still unsecure despite zero-day attack alertsHelp Net Security·Nov 13, 12:09 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20333CVE-2025-20362CVE-2025-2035260
CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active AttackThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-54253CVE-2025-54254CVE-2016-783660
North Korea IT worker scheme swells beyond US companiesCyberScoop·Oct 2, 14:26 UTC · Oct 2, 2025Exploit / PoC in the wild60
Future of CVE Program in limbo as CISA, board members debate path forwardThe Record·Sep 19, 00:00 UTC · Sep 19, 2025Exploit / PoC in the wild60
Mitsubishi Electric to acquire Nozomi Networks in $1 billion dealCyberScoop·Sep 9, 14:22 UTC · Sep 9, 2025Exploit / PoC in the wild60
CISA guide seeks a unified approach to software ‘ingredients lists’CyberScoop·Sep 3, 19:20 UTC · Sep 3, 2025Exploit / PoC in the wild60
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860
Apache Tomcat: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-2481360
Singapore warns China-linked group UNC3886 targets its critical infrastructureSecurity Affairs·Jul 20, 17:17 UTC · Jul 20, 2025Exploit / PoCCVE-2022-4132860
Nippon Steel IT Subsidiary Hit by “ZeroInfosecurity Magazine·Jul 10, 12:35 UTC · Jul 10, 2025Exploit / PoC60
Melting Down Grids and Warping Minds: Cyberwarfare in PracticeRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC60
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting ProviderThe Hacker News·Jun 24, 13:30 UTC · Jun 24, 2025Exploit / PoC60
Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely CompromisedThe Hacker News·Apr 29, 10:40 UTC · Apr 29, 2025Exploit / PoC in the wildCVE-2024-58136CVE-2024-4990CVE-2025-32432+1 CVEs60
DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025The Hacker News·Apr 25, 08:43 UTC · Apr 25, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-2245760
35 countries use Chinese networks for transporting mobile user traffic, posing cyber risksCyberScoop·Apr 17, 12:30 UTC · Apr 17, 2025Exploit / PoC in the wild60
CISA Adds Five Actively Exploited Vulnerabilities in Advantive VeraCore and Ivanti EPM to KEV ListThe Hacker News·Mar 11, 04:06 UTC · Mar 11, 2025Exploit / PoC in the wildCVE-2024-57968CVE-2025-25181CVE-2024-13159+3 CVEs60
China Accuses NSA's TAO Unit of Hacking its Military Research UniversityThe Hacker News·Mar 3, 09:33 UTC · Mar 3, 2025Exploit / PoC60
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [3 February]The Hacker News·Feb 4, 11:56 UTC · Feb 4, 2025Exploit / PoC in the wildCVE-2025-24085CVE-2024-41710CVE-2025-0626+30 CVEs60
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [30 Dec]The Hacker News·Jan 8, 11:22 UTC · Jan 8, 2025Exploit / PoCCVE-2024-3393CVE-2019-3568CVE-2024-56337+7 CVEs160
International crackdown disrupts DDoS-forCyberScoop·Dec 12, 15:08 UTC · Dec 12, 2024Exploit / PoC in the wild60
Here’s how simple it is for script kiddies to stand up DDoS servicesCyberScoop·Nov 26, 11:00 UTC · Nov 26, 2024Exploit / PoC60
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
CERT-UA Identifies Malicious RDP Files in Latest Attack on Ukrainian EntitiesThe Hacker News·Nov 1, 03:36 UTC · Nov 1, 2024Exploit / PoC60