Week in review: Windows Event Log zero-day, exploited critical Jenkins RCE flawHelp Net Security·Feb 4, 00:00 UTC · Feb 4, 2024Exploit / PoC in the wildCVE-2024-0402CVE-2024-2389760
Apple rushes fixes for exploited zero-days in iPhones and Macs (CVE-2023-28205, CVE-2023-28206)Help Net Security·Jan 9, 11:58 UTC · Jan 9, 2024Exploit / PoC in the wildCVE-2023-28205CVE-2023-2820660
Trustwave delivers managed support for key Palo Alto Networks offeringsHelp Net Security·Dec 14, 13:48 UTC · Dec 14, 2023Exploit / PoC60
Attackers exploited WinRAR zero-day for months to steal money from brokers (CVE-2023-38831)Help Net Security·Oct 18, 08:32 UTC · Oct 18, 2023Exploit / PoCCVE-2023-38831CVE-2023-4047760
A new Chrome 0-day is sending the Internet into a new chapter of Groundhog DayArs Technica · Security·Sep 28, 21:23 UTC · Sep 28, 2023Exploit / PoCCVE-2023-5217CVE-2023-486360
New threat intel effort to study 'undermonitered' regionsCyberScoop·Sep 21, 17:00 UTC · Sep 21, 2023Exploit / PoC in the wild60
With 0-days hitting Chrome, iOS, and dozens more this month, is no software safe?Ars Technica · Security·Sep 15, 00:00 UTC · Sep 15, 2023Exploit / PoC in the wildCVE-2023-486360
New Juniper Junos OS Flaws Expose Devices to Remote AttacksThe Hacker News·Aug 29, 05:59 UTC · Aug 29, 2023Exploit / PoCCVE-2023-36844CVE-2023-36845CVE-2023-36846+1 CVEs60
WinRAR Security Flaw Exploited in ZeroThe Hacker News·Aug 24, 11:12 UTC · Aug 24, 2023Exploit / PoCCVE-2023-38831CVE-2023-4047760
WinRAR 0-day that uses poisoned JPG and TXT files under exploit since AprilArs Technica · Security·Aug 23, 19:34 UTC · Aug 23, 2023Exploit / PoC in the wildCVE-2023-38831CVE-2018-2025060
Microsoft patches four exploited zero-days, but lags with fixes for a fifth (CVE-2023-36884)Help Net Security·Aug 4, 09:09 UTC · Aug 4, 2023Exploit / PoC in the wildCVE-2023-36884CVE-2023-32049CVE-2023-35311+2 CVEs160
New ChatGPT Attack Technique Spreads Malicious PackagesInfosecurity Magazine·Jun 6, 16:00 UTC · Jun 6, 2023Exploit / PoC45
PoC exploit for recently patched Microsoft Word RCE is public (CVE-2023-21716)Help Net Security·Mar 6, 00:00 UTC · Mar 6, 2023Exploit / PoCCVE-2023-21716160
IT threat evolution Q2 2022Kaspersky Securelist·Aug 15, 09:54 UTC · Aug 15, 2022Exploit / PoC in the wildCVE-2022-22965CVE-2022-26925CVE-2022-30190160
Attackers are leveraging Follina. What can you do?Help Net Security·Jun 3, 00:00 UTC · Jun 3, 2022Exploit / PoC in the wildCVE-2022-30190CVE-2021-4044460
Okta breach leads to questions on disclosure, reliance on thirdCyberScoop·Mar 24, 21:26 UTC · Mar 24, 2022Exploit / PoC in the wild60
Addressing CVE-2014Palo Alto Unit 42·Jan 28, 21:24 UTC · Jan 28, 2022Exploit / PoC in the wildCVE-2014-6332CVE-2014-0322CVE-2014-1776+1 CVEs60
Microsoft: Attackers Exploiting Windows Zero-Day FlawKrebs on Security·Sep 8, 15:16 UTC · Sep 8, 2021Exploit / PoC in the wildCVE-2021-40444160
Fake job listings help suspected Iranian hackers aim at targets in LebanonCyberScoop·Apr 8, 14:44 UTC · Apr 8, 2021Exploit / PoC in the wild60
Hackers Set Up a Fake Cybersecurity Firm to Target Security ExpertsThe Hacker News·Apr 3, 06:05 UTC · Apr 3, 2021Exploit / PoC60
Cisco plugs critical hole in WebEx, users urged to upgrade ASAPHelp Net Security·Jun 18, 12:51 UTC · Jun 18, 2020Exploit / PoC in the wildCVE-2018-011260
It's time to update your Cisco WebEx software again!Help Net Security·Jun 18, 12:50 UTC · Jun 18, 2020Exploit / PoC in the wildCVE-2018-0264CVE-2018-0253CVE-2018-025860
Friday Squid Blogging: New Tool for Grabbing Squid and other Fragile Sea CreaturesSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Exploit / PoC160
BlueKeep is back. For now, attackers are just using it for cryptominingCyberScoop·Nov 4, 16:23 UTC · Nov 4, 2019Exploit / PoC60
Microsoft drops emergency Internet Explorer fix for actively exploited zero-dayHelp Net Security·Sep 24, 00:00 UTC · Sep 24, 2019Exploit / PoC in the wildCVE-2019-1367CVE-2019-125560
NSA-approved cybersecurity law and policy course now available onlineCyberScoop·Aug 27, 20:59 UTC · Aug 27, 2019Exploit / PoC in the wild60
Microsoft Issues Emergency Fix for IE Zero DayKrebs on Security·Dec 19, 21:15 UTC · Dec 19, 2018Exploit / PoC in the wildCVE-2018-865360
3 New Code Execution Flaws Discovered in Atlantis Word ProcessorThe Hacker News·Nov 20, 16:30 UTC · Nov 20, 2018Exploit / PoCCVE-2018-4038CVE-2018-4039CVE-2018-404060
Reaper Group’s Updated Mobile ArsenalPalo Alto Unit 42·Aug 16, 06:27 UTC · Aug 16, 2018Exploit / PoC45
MS Office zero-day is used to infect millions of users with DridexHelp Net Security·Jun 26, 21:23 UTC · Jun 26, 2018Exploit / PoC60
Russian-linked group tied to Winter Olympics attack is now targeting biochemical researchersCyberScoop·Jun 19, 20:50 UTC · Jun 19, 2018Exploit / PoC in the wild60
Adobe Patches Zero-Day Flash FlawKrebs on Security·Jun 7, 16:45 UTC · Jun 7, 2018Exploit / PoC in the wildCVE-2018-500260
Misinterpretation of Intel docs is the root cause for the CVE-2018Security Affairs·May 10, 06:15 UTC · May 10, 2018Exploit / PoCCVE-2018-889750
Researchers found a semi-legit way to turn an Amazon Echo into a wiretapCyberScoop·Apr 26, 14:59 UTC · Apr 26, 2018Exploit / PoC in the wild60
Who Wasn’t Responsible for Olympic Destroyer?Cisco Talos·Feb 26, 18:03 UTC · Feb 26, 2018Exploit / PoC45
Hackers linked to Lebanese government caught in global cyberCyberScoop·Jan 18, 21:13 UTC · Jan 18, 2018Exploit / PoC in the wild60
'Highly active' Hamas-linked hackers found spying on Palestinian political groupCyberScoop·Oct 9, 20:52 UTC · Oct 9, 2017Exploit / PoC in the wild60
In-progress email threads were hacked to spearphish private companies, report saysCyberScoop·Oct 6, 13:14 UTC · Oct 6, 2017Exploit / PoC in the wild60