⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
We moved fast and broke things. It’s time for a change.CyberScoop·Feb 2, 11:00 UTC · Feb 2, 2026Exploit / PoC60
OMB rescinds ‘burdensome’ BidenCyberScoop·Jan 26, 22:12 UTC · Jan 26, 2026Exploit / PoC in the wild60
CISA Closes Ten Emergency Directives After Federal Cyber ReviewsInfosecurity Magazine·Jan 12, 16:45 UTC · Jan 12, 2026Exploit / PoC in the wild60
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024The Hacker News·Jan 10, 08:49 UTC · Jan 10, 2026Exploit / PoC in the wild60
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever ShippedThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-24990CVE-2025-59230CVE-2025-47827+5 CVEs160
Oligo Security strives to fill applicationCyberScoop·Jul 8, 15:40 UTC · Jul 8, 2025Exploit / PoC in the wild60
How DHS is working to continually improve the Continuous Diagnostics and Mitigation programCyberScoop·Mar 19, 20:52 UTC · Mar 19, 2025Exploit / PoC in the wild60
Projecting the next decade of software supply chain securityCyberScoop·Feb 10, 15:44 UTC · Feb 10, 2025Exploit / PoC in the wild60
CISOs can now obtain professional liability insuranceCyberScoop·Nov 21, 17:38 UTC · Nov 21, 2024Exploit / PoC in the wild60
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs260
Exclusive: Kevin Mandia joins SpecterOps as chair of the boardCyberScoop·Oct 1, 12:00 UTC · Oct 1, 2024Exploit / PoC in the wild60
Obfuscation: There Are Two Sides To EverythingThe Hacker News·Aug 1, 11:07 UTC · Aug 1, 2024Exploit / PoC60
Cisco Warns of Critical Flaw Affecting OnThe Hacker News·Jul 18, 13:13 UTC · Jul 18, 2024Exploit / PoC in the wildCVE-2024-20419CVE-2024-20401CVE-2024-34102+2 CVEs60
Five Core Tenets Of Highly Effective DevSecOps PracticesThe Hacker News·May 21, 11:33 UTC · May 21, 2024Exploit / PoC60
Maximum-severity GitLab flaw allowing account hijacking under active exploitationArs Technica · Security·May 2, 19:02 UTC · May 2, 2024Exploit / PoC in the wildCVE-2023-702860
Federal government affected by Russian breach of MicrosoftCyberScoop·Apr 4, 20:10 UTC · Apr 4, 2024Exploit / PoC in the wild160
New Silver SAML Attack Evades Golden SAML Defenses in Identity SystemsThe Hacker News·Mar 11, 04:52 UTC · Mar 11, 2024Exploit / PoC in the wild60
The Unknown Risks of The Software Supply Chain: A DeepThe Hacker News·Feb 17, 07:04 UTC · Feb 17, 2024Exploit / PoC60
Russian foreign intelligence hackers gain access to top Microsoft officials, company saysCyberScoop·Jan 19, 23:30 UTC · Jan 19, 2024Exploit / PoC in the wild60
Alert: PoC Exploits Released for Citrix and VMware VulnerabilitiesThe Hacker News·Nov 2, 12:20 UTC · Nov 2, 2023Exploit / PoC in the wildCVE-2023-34051CVE-2023-4966CVE-2023-35182+2 CVEs60
CISA Adds Citrix ShareFile Flaw to KEV Catalog Due to In-theThe Hacker News·Aug 21, 03:43 UTC · Aug 21, 2023Exploit / PoC in the wildCVE-2023-24489CVE-2023-351960
Microsoft Warns of Widescale Credential Stealing Attacks by Russian HackersThe Hacker News·Jun 27, 14:11 UTC · Jun 27, 2023Exploit / PoCCVE-2020-12641CVE-2020-35730CVE-2021-44026+1 CVEs60
Aqua Security strengthens software supply chain security with pipeline integrity scanningHelp Net Security·May 10, 00:00 UTC · May 10, 2023Exploit / PoC60
3CX supply chain attack was the result of a previous supply chain attack, Mandiant saysCyberScoop·Apr 20, 13:10 UTC · Apr 20, 2023Exploit / PoC in the wild60
Supply chain cyberattack with possible links to North Korea could have thousands of victims globallyCyberScoop·Mar 30, 13:31 UTC · Mar 30, 2023Exploit / PoC in the wild60
White House cybersecurity strategy to force large companies to make systems secure by designCyberScoop·Feb 23, 19:13 UTC · Feb 23, 2023Exploit / PoC in the wild60
Most attackers lose interest in Log4ShellThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC in the wildCVE-2021-4422860
Microsoft Warns of Uptick in Hackers Leveraging Publicly-Disclosed 0The Hacker News·Dec 14, 04:04 UTC · Dec 14, 2022Exploit / PoCCVE-2021-35211CVE-2021-40539CVE-2021-44077+2 CVEs60
Russian cyberspies targeted the Slovak government for monthsThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoC60
Zero-day are exploited on a massive scale in increasingly shorter timeframesSecurity Affairs·Nov 5, 17:36 UTC · Nov 5, 2022Exploit / PoCCVE-2021-35211CVE-2021-40539CVE-2021-44077+2 CVEs60
GUAC - A Google Open Source Project to secure software supply chainSecurity Affairs·Oct 21, 10:15 UTC · Oct 21, 2022Exploit / PoC57
Nakasone says Cyber Command did nine 'hunt forward' ops last year, including in UkraineCyberScoop·May 4, 21:37 UTC · May 4, 2022Exploit / PoC in the wild60
Okta breach leads to questions on disclosure, reliance on thirdCyberScoop·Mar 24, 21:26 UTC · Mar 24, 2022Exploit / PoC in the wild60
New Argo CD Bug Could Let Hackers Steal Secret Info from Kubernetes AppsThe Hacker News·Feb 7, 03:30 UTC · Feb 7, 2022Exploit / PoCCVE-2022-2434860
DHS assembles Cyber Safety Review Board to imitate fed agency that studies aviation accidentsCyberScoop·Feb 3, 15:30 UTC · Feb 3, 2022Exploit / PoC in the wild60