Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devicesHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2022Exploit / PoC in the wildCVE-2022-41033CVE-2022-40684CVE-2022-36067+1 CVEs160
Max-severity Exchange server flaw under active exploitation by Kremlin hackersArs Technica · Security·Jul 30, 20:57 UTC · Jul 30, 2026Exploit / PoC in the wildCVE-2026-4289760
Russian Hackers Exploit New ‘ZeroInfosecurity Magazine·Jul 23, 15:50 UTC · Jul 23, 2026Exploit / PoCCVE-2025-6637660
CISA Adds 8 Exploited Flaws to KEV, Sets AprilThe Hacker News·Apr 21, 13:51 UTC · Apr 21, 2026Exploit / PoC in the wildCVE-2023-27351CVE-2024-27199CVE-2025-2749+7 CVEs60
U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 4, 08:56 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2026-22719CVE-2026-2138560
CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV UpdateThe Hacker News·Feb 24, 15:30 UTC · Feb 24, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2024-7694CVE-2020-7796+1 CVEs60
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe Hacker News·Jul 8, 05:08 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+3 CVEs60
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities CatalogThe Hacker News·Jun 12, 05:02 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-32433CVE-2024-42009CVE-2025-3102260
Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious CodeThe Hacker News·Jun 9, 12:15 UTC · Jun 9, 2025Exploit / PoC in the wildCVE-2025-49113CVE-2024-3738360
U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 22, 22:17 UTC · May 22, 2025Exploit / PoC in the wildCVE-2025-463260
Multi-national warning issued over Russia’s targeting of logistics, tech firmsCyberScoop·May 21, 18:41 UTC · May 21, 2025Exploit / PoC in the wildCVE-2023-23397CVE-2023-3883160
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
Kremlin-linked hackers target webmail servers of Eastern European government agenciesThe Record·May 15, 14:13 UTC · May 15, 2025Exploit / PoC60
Russian state threat group shifts focus to US, UK targetsCyberScoop·Feb 12, 17:58 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs60
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
China's elite hackers expand target list to European UnionCyberScoop·Nov 7, 10:00 UTC · Nov 7, 2024Exploit / PoC in the wild60
Email Security Flaw Found in the WildSchneier on Security·Nov 21, 12:05 UTC · Nov 21, 2023Exploit / PoC60
Nation State Hackers Exploiting ZeroThe Hacker News·Oct 26, 03:42 UTC · Oct 26, 2023Exploit / PoCCVE-2020-35730CVE-2023-563160
Pro-Russia hackers target inboxes with 0Ars Technica · Security·Oct 25, 22:21 UTC · Oct 25, 2023Exploit / PoCCVE-2023-563160
Winter Vivern: Zero-Day XSS Exploit Targets Roundcube ServersInfosecurity Magazine·Oct 25, 17:00 UTC · Oct 25, 2023Exploit / PoCCVE-2020-35730CVE-2023-563160
Roundcube webmail zero-day exploited to spy on government entities (CVE-2023-5631)Help Net Security·Oct 25, 00:00 UTC · Oct 25, 2023Exploit / PoCCVE-2023-5631CVE-2020-35730CVE-2022-2792660
CISA CVE-2021-3493 to Known Exploited Vulnerabilities CatalogSecurity Affairs·Oct 21, 13:49 UTC · Oct 21, 2022Exploit / PoC in the wildCVE-2021-3493CVE-2021-4034CVE-2022-41352160
Microsoft: Two New 0-Day Flaws in Exchange ServerKrebs on Security·Sep 30, 17:03 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
Experts Detail Malicious Code Dropped Using ManageEngine ADSelfService ExploitThe Hacker News·Nov 9, 03:15 UTC · Nov 9, 2021Exploit / PoC in the wildCVE-2021-4053960
Top 12 Security Flaws Russian Spy Hackers Are Exploiting in the WildThe Hacker News·May 11, 06:23 UTC · May 11, 2021Exploit / PoCCVE-2018-13379CVE-2019-9670CVE-2019-11510+9 CVEs60
NSA, FBI, DHS expose Russian intelligence hacking tradecraftCyberScoop·Apr 15, 13:56 UTC · Apr 15, 2021Exploit / PoC in the wild60
Pentagon’s next cyber policy guru predicts more collective responses in cyberspaceCyberScoop·Nov 22, 14:08 UTC · Nov 22, 2019Exploit / PoC in the wild60