Your Purple Team Isn't Purple — It's Just Red and Blue in the Same RoomThe Hacker News·May 11, 11:51 UTC · May 11, 2026Exploit / PoC45
Identity discovery: The overlooked lever in strategic risk reductionHelp Net Security·Apr 29, 00:00 UTC · Apr 29, 2026Exploit / PoC60
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New StoriesThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2026Exploit / PoCCVE-2026-27175CVE-2026-27174CVE-2025-22952+1 CVEs60
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
U.S. CISA adds Ivanti EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 10, 09:52 UTC · Mar 10, 2026Exploit / PoC in the wildCVE-2021-22054CVE-2025-26399CVE-2026-160360
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
UAT-8837 targets critical infrastructure sectors in North AmericaCisco Talos·Jan 15, 11:00 UTC · Jan 15, 2026Exploit / PoCCVE-2025-5369060
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain AttacksThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wild60
SonicWall Fixes Actively Exploited CVE-2025The Hacker News·Dec 18, 03:59 UTC · Dec 18, 2025Exploit / PoC in the wildCVE-2025-40602CVE-2025-2300660
Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSSThe Record·Dec 8, 16:31 UTC · Dec 8, 2025Exploit / PoC in the wildCVE-2025-5518260
Week in review: WSUS vulnerability exploited to drop Skuld infostealer, PoC for BIND 9 DNS flaw publishedHelp Net Security·Nov 2, 00:00 UTC · Nov 2, 2025Exploit / PoCCVE-2025-2783CVE-2025-40778CVE-2025-59287+1 CVEs160
U.S. CISA adds SKYSEA Client View, Rapid7 Velociraptor, Microsoft Windows, and IGEL OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 16, 08:56 UTC · Oct 16, 2025Exploit / PoC in the wildCVE-2016-7836CVE-2025-6264CVE-2025-24990+2 CVEs60
CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active AttackThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-54253CVE-2025-54254CVE-2016-783660
U.S. CISA adds Adminer, Cisco IOS, Fortra GoAnywhere MFT, Libraesva ESG, and Sudo flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 30, 09:07 UTC · Sep 30, 2025Exploit / PoC in the wildCVE-2021-21311CVE-2025-20352CVE-2025-10035+3 CVEs60
Hackers exploit Fortra GoAnywhere flaw before public alertSecurity Affairs·Sep 26, 14:35 UTC · Sep 26, 2025Exploit / PoC in the wildCVE-2025-1003560
Fortra addressed a maximum severity flaw in GoAnywhere MFT softwareSecurity Affairs·Sep 19, 17:32 UTC · Sep 19, 2025Exploit / PoC in the wildCVE-2025-10035CVE-2024-0204160
The GoLaxy papers: Inside China’s AI persona armyThe Record·Sep 19, 13:51 UTC · Sep 19, 2025Exploit / PoC57
MeetC2 - A serverless C2 framework that leverages Google Calendar APIs as a communication channelSecurity Affairs·Sep 6, 09:39 UTC · Sep 6, 2025Exploit / PoC45
CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active ExploitationThe Hacker News·Jul 29, 04:51 UTC · Jul 29, 2025Exploit / PoC in the wildCVE-2023-253360
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 12, 09:17 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-24016CVE-2025-3305360
Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows FlawsThe Hacker News·Apr 6, 09:08 UTC · Apr 6, 2025Exploit / PoCCVE-2025-24061CVE-2025-24071CVE-2025-2663360
CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25The Hacker News·Feb 5, 05:05 UTC · Feb 5, 2025Exploit / PoC in the wildCVE-2024-45195CVE-2024-29059CVE-2018-9276+1 CVEs60
Microsoft fixes exploited zero-day (CVE-2024-49138)Help Net Security·Dec 10, 00:00 UTC · Dec 10, 2024Exploit / PoC in the wildCVE-2024-49138CVE-2024-49112CVE-2024-49114+1 CVEs160
Authlete 3.0 empowers organizations to improve how they issue and manage user credentialsHelp Net Security·Nov 6, 00:00 UTC · Nov 6, 2024Exploit / PoC45
U.S. CISA adds Veeam Backup and Replication flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 19, 15:22 UTC · Oct 19, 2024Exploit / PoC in the wildCVE-2024-4071160
Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security toolsHelp Net Security·Oct 13, 00:00 UTC · Oct 13, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-9680+5 CVEs160
Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the WildThe Hacker News·Oct 9, 12:48 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+7 CVEs60
Microsoft Fixes Five ZeroInfosecurity Magazine·Oct 9, 09:30 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-6197+2 CVEs60
U.S. CISA adds Ivanti Virtual Traffic Manager flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 08:08 UTC · Sep 25, 2024Exploit / PoC in the wildCVE-2024-759360
PoC exploit for exploited Ivanti Cloud Services Appliance flaw released (CVE-2024-8190)Help Net Security·Sep 19, 20:44 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-896360
Android camera apps could be hijacked to spy on usersHelp Net Security·Sep 18, 09:34 UTC · Sep 18, 2024Exploit / PoCCVE-2019-223450
Chinese Velvet Ant Uses Cisco ZeroInfosecurity Magazine·Aug 26, 09:00 UTC · Aug 26, 2024Exploit / PoC in the wildCVE-2024-2039960
China-linked APT Velvet Ant exploited zeroSecurity Affairs·Aug 23, 07:21 UTC · Aug 23, 2024Exploit / PoC in the wildCVE-2024-2039960
Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System ControlThe Hacker News·Aug 23, 04:10 UTC · Aug 23, 2024Exploit / PoCCVE-2024-2039960
A PoC exploit code is available for critical Ivanti vTM bugSecurity Affairs·Aug 13, 18:06 UTC · Aug 13, 2024Exploit / PoCCVE-2024-759360
Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android usersHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2024Exploit / PoC in the wildCVE-2023-45249CVE-2024-3708560
SolarWinds fixed multiple flaws in ServSecurity Affairs·Jun 7, 21:37 UTC · Jun 7, 2024Exploit / PoCCVE-2024-28996CVE-2024-28999CVE-2024-2900460
PoC exploit for Ivanti EPMM privilege escalation flaw released (CVE 2024-22026)Help Net Security·May 20, 00:00 UTC · May 20, 2024Exploit / PoCCVE-2024-22026CVE-2023-46806CVE-2023-4680760
Drozer: Open-source Android security assessment frameworkHelp Net Security·Mar 27, 00:00 UTC · Mar 27, 2024Exploit / PoC45
Kali Linux 2020.4 released: New default shell, fresh tools, and more!Help Net Security·Nov 14, 08:39 UTC · Nov 14, 2023Exploit / PoC45