Citizen Lab links Cellebrite to the hacking of a Kenyan presidential candidate’s phoneCyberScoop·Feb 17, 11:00 UTC · Feb 17, 2026Exploit / PoC in the wild60
Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858)Help Net Security·Jan 28, 00:00 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
Industry, government, nonprofits weigh voluntary rules for commercial hacking toolsCyberScoop·Jan 26, 14:11 UTC · Jan 26, 2026Exploit / PoC in the wild60
Attackers exploited critical Fortra GoAnywhere flaw in zero-day attacks (CVE-2025-10035)Help Net Security·Oct 7, 14:53 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2025-1003560
New $50 Battering RAM Attack Breaks Intel and AMD Cloud Security ProtectionsThe Hacker News·Oct 1, 10:52 UTC · Oct 1, 2025Exploit / PoCCVE-2025-4030060
Meta confused over WhatsApp ban issued to House staffersCyberScoop·Jun 24, 21:12 UTC · Jun 24, 2025Exploit / PoC in the wild60
Cybersecurity experts issue response to Trump order targeting Chris Krebs, SentinelOneCyberScoop·Apr 28, 20:57 UTC · Apr 28, 2025Exploit / PoC in the wild60
PoC rootkit Curing evades traditional Linux detection systemsSecurity Affairs·Apr 28, 09:38 UTC · Apr 28, 2025Exploit / PoC60
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
Microsoft IDs developers behind alleged generative AI hacking-forCyberScoop·Feb 27, 18:30 UTC · Feb 27, 2025Exploit / PoC in the wild160
Attackers exploit a new zeroSecurity Affairs·Feb 11, 23:06 UTC · Feb 11, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2024-55591160
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024Security Affairs·Jan 3, 09:42 UTC · Jan 3, 2025Exploit / PoCCVE-2024-49113CVE-2024-49112160
New Bootkit “Bootkitty” Targets Linux Systems via UEFIInfosecurity Magazine·Nov 27, 16:30 UTC · Nov 27, 2024Exploit / PoC60
Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixesHelp Net Security·Sep 12, 14:09 UTC · Sep 12, 2024Exploit / PoC in the wildCVE-2024-38217CVE-2024-38226CVE-2024-38014+6 CVEs160
Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROIHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2024Exploit / PoCCVE-2024-6327CVE-2024-4111060
Low-level cybercriminals are pouncing on CrowdStrikeCyberScoop·Jul 23, 22:05 UTC · Jul 23, 2024Exploit / PoC in the wild60
Celebrity TikTok Accounts Compromised Using ZeroThe Hacker News·Jun 8, 05:52 UTC · Jun 8, 2024Exploit / PoC60
Dangling Domains: Security Threats, Detection and PrevalencePalo Alto Unit 42·Jun 6, 01:30 UTC · Jun 6, 2024Exploit / PoC45
May 2024 Patch Tuesday: Microsoft fixes exploited zero-days (CVE-2024-30051, CVE-2024-30040)Help Net Security·May 31, 08:23 UTC · May 31, 2024Exploit / PoC in the wildCVE-2024-30051CVE-2024-30040CVE-2023-36033+2 CVEs160
New TunnelVision technique can bypass the VPN encapsulationSecurity Affairs·May 8, 18:21 UTC · May 8, 2024Exploit / PoCCVE-2024-366150
Hackers exploited Windows 0-day for 6 months after Microsoft knew of itArs Technica · Security·Mar 4, 22:47 UTC · Mar 4, 2024Exploit / PoC in the wildCVE-2024-2133860
CISA adds Microsoft Windows bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 15, 10:04 UTC · Feb 15, 2024Exploit / PoC in the wildCVE-2024-21412CVE-2024-21351CVE-2023-3602560
CISA orders federal agencies to disconnect Ivanti VPN instances by February 2Security Affairs·Feb 1, 19:46 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Attacks against Denmark 's energy sector were not carried out by RussiaSecurity Affairs·Jan 14, 16:40 UTC · Jan 14, 2024Exploit / PoC in the wildCVE-2023-28771CVE-2020-9054CVE-2022-3052560
New iPhone Exploit Uses Four Zero-DaysSchneier on Security·Jan 4, 12:11 UTC · Jan 4, 2024Exploit / PoCCVE-2023-41990CVE-2023-32434CVE-2023-38606+1 CVEs60
Microsoft Fixes 34 CVEs and One ZeroInfosecurity Magazine·Dec 13, 10:30 UTC · Dec 13, 2023Exploit / PoCCVE-2023-20588CVE-2023-35628CVE-2023-35641+2 CVEs60
Apple news: iLeakage attack, MAC address leakage bugHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2023Exploit / PoCCVE-2023-32434CVE-2023-4284660
Hamas-linked app offers window into cyber infrastructure, possible links to IranCyberScoop·Oct 19, 17:40 UTC · Oct 19, 2023Exploit / PoC in the wild60
Incomplete disclosures by Apple and Google create “huge blindspot” for 0Ars Technica · Security·Sep 21, 22:19 UTC · Sep 21, 2023Exploit / PoC in the wildCVE-2023-41064CVE-2023-486360
Spoofing an Apple device and tricking users into sharing dataSecurity Affairs·Aug 21, 08:02 UTC · Aug 21, 2023Exploit / PoC45
Tenable CEO accuses Microsoft of negligence in addressing security flawCyberScoop·Aug 2, 18:12 UTC · Aug 2, 2023Exploit / PoC160
Microsoft downplays damaging report on Chinese hacking its own engineers vettedCyberScoop·Jul 31, 18:35 UTC · Jul 31, 2023Exploit / PoC in the wild60
Zenbleed: New Flaw in AMD Zen 2 Processors Puts Encryption Keys and Passwords at RiskThe Hacker News·Jul 27, 06:35 UTC · Jul 27, 2023Exploit / PoC in the wildCVE-2023-2059360
Tracers on the stage: Talking with the sleuths who cracked the big crypto cases of the 2010sThe Record·Apr 18, 12:49 UTC · Apr 18, 2023Exploit / PoC45
Apple fixes actively exploited WebKit zero-day in iOS, macOS (CVE-2023-23529)Help Net Security·Feb 14, 00:00 UTC · Feb 14, 2023Exploit / PoC in the wildCVE-2023-23529CVE-2023-2351460
Microsoft fixes exploited zero-day in the Windows CLFS Driver (CVE-2022-37969)Help Net Security·Sep 19, 07:02 UTC · Sep 19, 2022Exploit / PoC in the wildCVE-2022-37969CVE-2022-24521CVE-2022-34724+4 CVEs60
Hacktivists claiming attack on Iranian steel facilities dump tranche of 'top secret documents'CyberScoop·Jul 7, 17:30 UTC · Jul 7, 2022Exploit / PoC in the wild60
Suspicious withdrawals were indeed a 'security incident,' $30M stolen, Crypto.com saysCyberScoop·Jan 20, 16:20 UTC · Jan 20, 2022Exploit / PoC in the wild60
Israeli newspaper Jerusalem Post is hacked, website defaced to include threatsCyberScoop·Jan 3, 15:06 UTC · Jan 3, 2022Exploit / PoC in the wild60
A flaw in Microsoft Azure App Service exposes customer source codeSecurity Affairs·Dec 23, 05:36 UTC · Dec 23, 2021Exploit / PoC in the wild160