Friday Squid Blogging: Illegal North Korean Squid FishingSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Exploit / PoCCVE-2018-865360
Elderwood project, who is behind Op. Aurora and ongoing attacks?Security Affairs·Oct 6, 23:14 UTC · Oct 6, 2025Exploit / PoC60
DirtyMoe modules expand the bot using wormSecurity Affairs·Mar 21, 08:03 UTC · Mar 21, 2022Exploit / PoCCVE-2020-0674CVE-2019-9082CVE-2019-2725+3 CVEs60
Google, Mandiant say zero-day numbers reached allThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Exploit / PoC in the wild60
IT threat evolution Q3 2014Kaspersky Securelist·Nov 18, 10:10 UTC · Nov 18, 2014Exploit / PoCCVE-2011-0611CVE-2013-2465CVE-2013-1347+3 CVEs60
Zerodium price list for secret Hacking methodsSecurity Affairs·Nov 21, 11:06 UTC · Nov 21, 2015Exploit / PoC60
DHS memo: 'Significant' security risks presented by online votingCyberScoop·May 11, 20:19 UTC · May 11, 2020Exploit / PoC in the wild60
The New Disclosure Debate and the Evil Mr. MooreCisco Talos·Mar 16, 17:36 UTC · Mar 16, 2010Exploit / PoC57
IT threat evolution Q2 2018Kaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2018Exploit / PoCCVE-2018-817460
IT threat evolution Q3 2021Kaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021Exploit / PoCCVE-2021-4044460
Threat Spotlight: Sundown MaturesCisco Talos·Mar 31, 12:40 UTC · Mar 31, 2017Exploit / PoCCVE-2016-018960
U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 11, 07:37 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21510CVE-2026-21513CVE-2026-21514+3 CVEs160
Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026Help Net Security·Feb 11, 00:00 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21513CVE-2026-21514CVE-2026-21510+3 CVEs160
Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilitiesCyberScoop·Feb 10, 20:50 UTC · Feb 10, 2026Exploit / PoC in the wildCVE-2026-21510CVE-2026-21513CVE-2026-21514+5 CVEs160
Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploitsHelp Net Security·Dec 23, 00:00 UTC · Dec 23, 2025Exploit / PoCCVE-2025-10294CVE-2025-59295CVE-2025-59230+7 CVEs60
U.S. CISA adds Oracle, Mozilla, Microsoft Windows, Linux Kernel, and Microsoft IE flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 07:00 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2010-3765CVE-2010-3962CVE-2011-3402+4 CVEs60
U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 14, 08:03 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2025-8875CVE-2025-887660
Analyzing the Patch Timeline for Zero-Day ExploitsRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC60
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense orgThe Record·Jun 11, 14:16 UTC · Jun 11, 2025Exploit / PoCCVE-2025-3305360
U.S. CISA adds Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 14, 20:36 UTC · May 14, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+2 CVEs60
Patch Tuesday: Microsoft fixes 5 actively exploited zero-daysHelp Net Security·May 13, 00:00 UTC · May 13, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-32701CVE-2025-32706+4 CVEs60
Microsoft Fixes Four More ZeroInfosecurity Magazine·Nov 13, 09:30 UTC · Nov 13, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-49019+1 CVEs60
Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)Help Net Security·Oct 8, 00:00 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-38112+3 CVEs60
Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixesHelp Net Security·Sep 12, 14:09 UTC · Sep 12, 2024Exploit / PoC in the wildCVE-2024-38217CVE-2024-38226CVE-2024-38014+6 CVEs160
Microsoft Fixes Nine ZeroInfosecurity Magazine·Aug 14, 09:50 UTC · Aug 14, 2024Exploit / PoC in the wildCVE-2024-38213CVE-2024-38178CVE-2024-38193+7 CVEs160
Adobe patches newly exploited Flash zero-dayHelp Net Security·Dec 15, 12:35 UTC · Dec 15, 2023Exploit / PoC in the wildCVE-2018-1598260
Featured talks at the upcoming Hack In The Box Security ConferenceHelp Net Security·Nov 20, 13:37 UTC · Nov 20, 2023Exploit / PoC60
North Korea-backed hackers target security researchers with 0Ars Technica · Security·Sep 7, 22:05 UTC · Sep 7, 2023Exploit / PoC60
In 2022, more than 40% of zero-day exploits used in the wild were variations of previous issuesSecurity Affairs·Jul 30, 16:38 UTC · Jul 30, 2023Exploit / PoC in the wildCVE-2022-21882CVE-2021-1732CVE-2022-22587+29 CVEs160
Unpatched Office zero-day CVE-2023-36884 actively exploited in targeted attacksSecurity Affairs·Jul 12, 07:39 UTC · Jul 12, 2023Exploit / PoC in the wildCVE-2023-3688460
Threat Source newsletter (April 27, 2023) — New Cisco Secure offerings and extra security from DuoCisco Talos·Apr 27, 18:00 UTC · Apr 27, 2023Exploit / PoCCVE-2023-2735060
CISA adds bugs exploited by commercial surveillance spyware to Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 1, 18:06 UTC · Apr 1, 2023Exploit / PoC in the wildCVE-2021-30900CVE-2022-38181CVE-2023-0266+6 CVEs60
Google: North Korean hackers are still targeting security researchersThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Exploit / PoC60
New PetitPotam attack forces Windows servers to authenticate with an attackerThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoC45
North Korean hackers exploit Itaewon tragedy to infiltrate South Korean targetsCyberScoop·Dec 7, 21:00 UTC · Dec 7, 2022Exploit / PoC in the wildCVE-2022-4112860
Apple releases fixes for three WebKit zeroThe Record·Dec 7, 00:00 UTC · Dec 7, 2022Exploit / PoC in the wildCVE-2021-30663CVE-2021-30665CVE-2021-30666+1 CVEs60
Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 previewCisco Talos·Aug 4, 18:00 UTC · Aug 4, 2022Exploit / PoC in the wildCVE-2022-2613860
F5 Warns of a New Critical BIGThe Hacker News·May 5, 02:38 UTC · May 5, 2022Exploit / PoC in the wildCVE-2022-1388CVE-2021-1789CVE-2019-8506+3 CVEs60
Threat Source newsletter (April 14, 2022) — It's Tax Day, and you know what that meansCisco Talos·Apr 14, 18:00 UTC · Apr 14, 2022Exploit / PoC in the wildCVE-2022-2452160
CISA added 9 new flaws to the Known Exploited Vulnerabilities CatalogSecurity Affairs·Feb 16, 10:05 UTC · Feb 16, 2022Exploit / PoC in the wildCVE-2022-24086CVE-2022-0609CVE-2019-0752+9 CVEs60