China-Linked APT Exploited Sitecore ZeroThe Hacker News·Jan 22, 08:08 UTC · Jan 22, 2026Exploit / PoCCVE-2025-5369060
Security Affairs newsletter Round 559 by Pierluigi PaganiniSecurity Affairs·Jan 18, 13:46 UTC · Jan 18, 2026Exploit / PoC in the wild60
CISA Flags Microsoft Office and HPE OneView Bugs as Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wildCVE-2009-0556CVE-2025-37164160
Spanish police disrupt Black Axe, arrest alleged leaders in action spanning four citiesCyberScoop·Jan 12, 23:13 UTC · Jan 12, 2026Exploit / PoC in the wild60
Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on SelfThe Hacker News·Jan 10, 14:26 UTC · Jan 10, 2026Exploit / PoC in the wildCVE-2025-66209CVE-2025-66210CVE-2025-66211+8 CVEs60
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 30, 08:33 UTC · Dec 30, 2025Exploit / PoC in the wildCVE-2025-1484760
MongoBleed flaw actively exploited in attacks in the wildSecurity Affairs·Dec 29, 23:21 UTC · Dec 29, 2025Exploit / PoC in the wildCVE-2025-1484760
MongoBleed defect swirls, stamping out hope of yearCyberScoop·Dec 29, 21:46 UTC · Dec 29, 2025Exploit / PoC in the wildCVE-2025-1484760
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency MitigationThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-55182CVE-2021-4422860
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSSThe Record·Dec 8, 16:31 UTC · Dec 8, 2025Exploit / PoC in the wildCVE-2025-5518260
NSO Group argues WhatsApp injunction threatens existence, future U.S. government workCyberScoop·Nov 20, 23:11 UTC · Nov 20, 2025Exploit / PoC in the wild60
Dozens of groups call for governments to protect encryptionCyberScoop·Nov 17, 20:56 UTC · Nov 17, 2025Exploit / PoC in the wild60
CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to NoThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Exploit / PoC in the wildCVE-2025-9242CVE-2025-62215CVE-2025-1248060
Too many Cisco ASA firewalls still unsecure despite zero-day attack alertsHelp Net Security·Nov 13, 12:09 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20333CVE-2025-20362CVE-2025-2035260
Judge forbids NSO Group from targeting WhatsApp usersCyberScoop·Oct 20, 15:27 UTC · Oct 20, 2025Exploit / PoC in the wild60
North Korea IT worker scheme swells beyond US companiesCyberScoop·Oct 2, 14:26 UTC · Oct 2, 2025Exploit / PoC in the wild60
Dutch Authorities Arrest Teens in Foreign Interference CaseInfosecurity Magazine·Sep 29, 17:00 UTC · Sep 29, 2025Exploit / PoC60
Future of CVE Program in limbo as CISA, board members debate path forwardThe Record·Sep 19, 00:00 UTC · Sep 19, 2025Exploit / PoC in the wild60
From summer camp to grind seasonCisco Talos·Sep 4, 18:02 UTC · Sep 4, 2025Exploit / PoCCVE-2025-5517760
CISA guide seeks a unified approach to software ‘ingredients lists’CyberScoop·Sep 3, 19:20 UTC · Sep 3, 2025Exploit / PoC in the wild60
Experts warn of actively exploited FreePBX zeroSecurity Affairs·Aug 29, 13:20 UTC · Aug 29, 2025Exploit / PoC in the wildCVE-2025-5781960
Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543)Help Net Security·Aug 29, 09:22 UTC · Aug 29, 2025Exploit / PoC in the wildCVE-2025-6543CVE-2025-577760
IoT under siege: The return of the MiraiSecurity Affairs·Aug 24, 08:36 UTC · Aug 24, 2025Exploit / PoCCVE-2024-1285660
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
New CrushFTP Critical Vulnerability Exploited in the WildInfosecurity Magazine·Jul 21, 14:00 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-54309CVE-2025-3116160
Mass attack spree hits Microsoft SharePoint zeroCyberScoop·Jul 21, 13:44 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706160
U.S. CISA adds Citrix NetScaler ADC and Gateway flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 15, 23:33 UTC · Jul 15, 2025Exploit / PoC in the wildCVE-2025-5777CVE-2023-4966CVE-2025-534960
Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the WildThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Exploit / PoC in the wildCVE-2025-4781260
Meta confused over WhatsApp ban issued to House staffersCyberScoop·Jun 24, 21:12 UTC · Jun 24, 2025Exploit / PoC in the wild60
ZScaler acquires Red Canary for boost in AICyberScoop·May 27, 22:21 UTC · May 27, 2025Exploit / PoC in the wild60
Chinese cyber spies are using Ivanti EPMM flaws to breach EU, US organizationsHelp Net Security·May 23, 00:00 UTC · May 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
Multi-national warning issued over Russia’s targeting of logistics, tech firmsCyberScoop·May 21, 18:41 UTC · May 21, 2025Exploit / PoC in the wildCVE-2023-23397CVE-2023-3883160
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation EvidenceThe Hacker News·May 8, 13:52 UTC · May 8, 2025Exploit / PoC in the wildCVE-2025-324860
U.S. CISA adds GoVision device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 8, 08:04 UTC · May 8, 2025Exploit / PoC in the wildCVE-2024-6047CVE-2024-1112060
New Critical SAP NetWeaver Flaw Exploited to Drop Web Shell, Brute Ratel FrameworkThe Hacker News·May 6, 13:53 UTC · May 6, 2025Exploit / PoC in the wildCVE-2017-9844CVE-2025-31324CVE-2017-1263760
France blames Russian military intelligence for years of cyberattacks on local entitiesThe Record·Apr 29, 16:53 UTC · Apr 29, 2025Exploit / PoC60