New PetitPotam attack forces Windows servers to authenticate with an attackerThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoC45
Zoom credits Keybase acquisition with quick turnaround on end-toCyberScoop·Oct 27, 16:08 UTC · Oct 27, 2020Exploit / PoC in the wild60
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms networkThe Record·May 19, 19:21 UTC · May 19, 2026Exploit / PoCCVE-2021-22359CVE-2022-2979860
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure EntitiesThe Hacker News·Feb 7, 11:03 UTC · Feb 7, 2026Exploit / PoC60
IT threat evolution Q2 2022Kaspersky Securelist·Aug 15, 09:54 UTC · Aug 15, 2022Exploit / PoC in the wildCVE-2022-22965CVE-2022-26925CVE-2022-30190160
SonicWall SMA zero-days were exploited weeks before disclosureHelp Net Security·Jul 21, 00:00 UTC · Jul 21, 2026Exploit / PoCCVE-2026-15409CVE-2026-1541060
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theftSecurity Affairs·Jul 22, 21:20 UTC · Jul 22, 2026Exploit / PoCCVE-2026-4829460
Friday Squid Blogging: Zaqistan FlagSchneier on Security·Jul 28, 21:01 UTC · Jul 28, 2023Exploit / PoC60
Threat Advisory: Microsoft Outlook privilege escalation vulnerability being exploited in the wildCisco Talos·Mar 15, 23:46 UTC · Mar 15, 2023Exploit / PoC in the wildCVE-2023-2339760
Microsoft publishes mitigations for the PetitPotam attackSecurity Affairs·Jul 26, 07:22 UTC · Jul 26, 2021Exploit / PoC45
Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploitedHelp Net Security·Aug 25, 00:00 UTC · Aug 25, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-6800CVE-2024-28987+2 CVEs60
Threat Source newsletter (April 14, 2022) — It's Tax Day, and you know what that meansCisco Talos·Apr 14, 18:00 UTC · Apr 14, 2022Exploit / PoC in the wildCVE-2022-2452160
Hackers continue to exploit the Drupalgeddon2 flaw in attacks in the wildSecurity Affairs·Oct 8, 05:32 UTC · Oct 8, 2019Exploit / PoCCVE-2018-760060
Cybersecurity jobs available right now: May 13, 2025Help Net Security·Jan 30, 10:25 UTC · Jan 30, 2026Exploit / PoC60
17,000+ Microsoft Exchange servers in Germany are vulnerable to attack, BSI warnsHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-2619860
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking FlawThe Hacker News·Aug 3, 08:23 UTC · Aug 3, 2026Exploit / PoCCVE-2026-8233CVE-2026-36884CVE-2025-6677650
Experts: No cybersecurity without collaborationCyberScoop·May 20, 21:03 UTC · May 20, 2016Exploit / PoC in the wild60
New attacks on 4G LTE networks can allow to spy on users and spoof emergency alertsSecurity Affairs·Mar 5, 09:03 UTC · Mar 5, 2018Exploit / PoC60
Obtaining password hash of Windows systems with PetitPotam attackSecurity Affairs·Jul 24, 05:08 UTC · Jul 24, 2021Exploit / PoC45
CISA added Zoho ManageEngine RCE (CVE-2022-47966) to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Jan 24, 11:03 UTC · Jan 24, 2023Exploit / PoC in the wildCVE-2022-4796660
Threats posed by using RATs in ICSKaspersky Securelist·Sep 20, 10:00 UTC · Sep 20, 2018Exploit / PoC60
How to use weaponized PDF documents to steal Windows credentialsSecurity Affairs·Apr 28, 12:40 UTC · Apr 28, 2018Exploit / PoC45
TeamViewer flaw could be exploited to crack users' passwordHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2020Exploit / PoC in the wildCVE-2020-1369960
Just 10 lines of code can steal AI secrets from Apple, AMD, and Qualcomm GPUsArs Technica · Security·Jan 17, 18:15 UTC · Jan 17, 2024Exploit / PoC57
Zoom to begin end-to-end encryption rollout with monthlong previewCyberScoop·Oct 14, 18:31 UTC · Oct 14, 2020Exploit / PoC in the wild60
Treasury report calls out cyber risks to financial sector fueled by AICyberScoop·Mar 29, 18:20 UTC · Mar 29, 2024Exploit / PoC in the wild60
New Metasploit RFTransceiver extension allows testing IoT sevicesSecurity Affairs·Mar 22, 10:36 UTC · Mar 22, 2017Exploit / PoCCVE-2016-508450
Expert discloses details of 3 Tor zeroSecurity Affairs·Jul 30, 21:53 UTC · Jul 30, 2020Exploit / PoC60
Dormakaba flaws allow to access major organizations’ doorsSecurity Affairs·Jan 27, 06:15 UTC · Jan 27, 2026Exploit / PoC60
Boffins show PIN bypass attack Mastercard and Maestro contactless paymentsSecurity Affairs·Aug 28, 16:08 UTC · Aug 28, 2021Exploit / PoC45
Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)Help Net Security·May 12, 08:27 UTC · May 12, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs160
Misconceptions hinder threat-sharing with government, DHS official saysCyberScoop·Nov 14, 21:29 UTC · Nov 14, 2019Exploit / PoC in the wild60
Researchers uncover 4G LTE exploits that can be used to spy, spoof and cause panicCyberScoop·Mar 5, 17:28 UTC · Mar 5, 2018Exploit / PoC in the wild60
Mem3nt0 moriKaspersky Securelist·Oct 27, 03:00 UTC · Oct 27, 2025Exploit / PoC in the wildCVE-2025-278360
Microsoft fixes exploited WordPad, Skype for Business zero-days (CVE-2023-36563, CVE-2023-41763)Help Net Security·Oct 10, 00:00 UTC · Oct 10, 2023Exploit / PoC in the wildCVE-2023-36563CVE-2023-41763CVE-2023-44487+2 CVEs60
CISA, FBI warn of China-linked hackers pre-positioning for ‘destructive cyberattacks against US critical infrastructure’The Record·Feb 7, 19:27 UTC · Feb 7, 2024Exploit / PoC60
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerThe Hacker News·Jul 28, 04:01 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-54121160
Electric equipment vendor Schweitzer joins US testing program to defend grid from hacking threatsCyberScoop·Mar 19, 20:17 UTC · Mar 19, 2021Exploit / PoC in the wild60
Rudy Giuliani has had virtually no input on U.S. cybersecurity policyCyberScoop·Sep 21, 12:20 UTC · Sep 21, 2017Exploit / PoC in the wild60