Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms networkThe Record·May 19, 19:21 UTC · May 19, 2026Exploit / PoCCVE-2021-22359CVE-2022-2979860
A dozen allied agencies say China is building covert hacker networks out of everyday routersCyberScoop·Apr 23, 16:13 UTC · Apr 23, 2026Exploit / PoC in the wild60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customersCyberScoop·Jan 29, 04:52 UTC · Jan 29, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs·Aug 28, 10:48 UTC · Aug 28, 2025Exploit / PoCCVE-2024-21887CVE-2023-46805CVE-2024-3400+3 CVEs160
Multi-national warning issued over Russia’s targeting of logistics, tech firmsCyberScoop·May 21, 18:41 UTC · May 21, 2025Exploit / PoC in the wildCVE-2023-23397CVE-2023-3883160
CISA Shifts Alert Distribution Strategy to Email, Social MediaInfosecurity Magazine·May 13, 15:15 UTC · May 13, 2025Exploit / PoC in the wild60
U.S. CISA adds Cisco Smart Licensing Utility flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 31, 19:56 UTC · Mar 31, 2025Exploit / PoC in the wildCVE-2024-20439CVE-2024-20440CVE-2024-030560
Cisco Smart Licensing Utility flaws actively exploited in the wildSecurity Affairs·Mar 21, 09:26 UTC · Mar 21, 2025Exploit / PoC in the wildCVE-2024-20439CVE-2024-20440CVE-2024-030560
U.S. CISA adds Microsoft Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 12, 08:01 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2024-40891CVE-2024-40890CVE-2025-21418+1 CVEs60
Removal of Cyber Safety Review Board members sparks alarm from cyber pros, key lawmakerCyberScoop·Jan 22, 21:26 UTC · Jan 22, 2025Exploit / PoC in the wild60
Cisco ASA flaw CVE-2014Security Affairs·Dec 3, 22:49 UTC · Dec 3, 2024Exploit / PoC in the wildCVE-2014-212060
Recently disclosed VMware vCenter Server bugs are actively exploited in attacksSecurity Affairs·Nov 18, 20:45 UTC · Nov 18, 2024Exploit / PoC in the wildCVE-2024-38812CVE-2024-38813CVE-2024-37079+1 CVEs160
Palo Alto Networks confirmed active exploitation of recently disclosed zeroSecurity Affairs·Nov 16, 17:39 UTC · Nov 16, 2024Exploit / PoC in the wildCVE-2024-9463CVE-2024-946560
Surge in exploits of zero-day vulnerabilities is ‘new normal’ warns Five Eyes allianceThe Record·Nov 12, 16:08 UTC · Nov 12, 2024Exploit / PoCCVE-2023-351960
Fortinet Confirms Exploitation of Critical FortiManager ZeroInfosecurity Magazine·Oct 24, 11:45 UTC · Oct 24, 2024Exploit / PoC in the wildCVE-2024-47575CVE-2024-2311360
Fortinet FortiManager flaw exploited in zero-day attacks (CVE-2024-47575)Help Net Security·Oct 24, 00:00 UTC · Oct 24, 2024Exploit / PoC in the wildCVE-2024-4757560
SonicWall warns that SonicOS bug exploited in attacksSecurity Affairs·Sep 6, 18:59 UTC · Sep 6, 2024Exploit / PoC in the wildCVE-2024-40766CVE-2022-22274CVE-2023-065660
US and Allies Accuse Russian Military of Destructive CyberInfosecurity Magazine·Sep 6, 11:20 UTC · Sep 6, 2024Exploit / PoC in the wild60
Google warns of an actively exploited Android kernel flawSecurity Affairs·Sep 4, 20:39 UTC · Sep 4, 2024Exploit / PoC in the wildCVE-2024-36971CVE-2024-3289660
Panel advises CISA on how to improve industryCyberScoop·Jun 5, 22:14 UTC · Jun 5, 2024Exploit / PoC in the wild60
Experts released PoC exploit code for RCE in Fortinet SIEMSecurity Affairs·May 28, 19:11 UTC · May 28, 2024Exploit / PoC in the wildCVE-2024-23108CVE-2024-23109160
Palo Alto Networks warns of zeroThe Record·Apr 12, 14:52 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
Ivanti fixed for 4 new issues in Connect Secure and Policy SecureSecurity Affairs·Apr 4, 08:10 UTC · Apr 4, 2024Exploit / PoCCVE-2024-21894CVE-2024-22052CVE-2024-22053+5 CVEs60
Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
Researchers want more detail on industrial control system alertsCyberScoop·Nov 22, 16:04 UTC · Nov 22, 2023Exploit / PoC in the wild60
Tens of thousands Cisco IOS XE devices were hacked by exploiting CVE-2023Security Affairs·Oct 20, 10:13 UTC · Oct 20, 2023Exploit / PoC in the wildCVE-2023-2019860
Cisco fixes 3 high-severity DoS flaws in NXSecurity Affairs·Aug 27, 15:00 UTC · Aug 27, 2023Exploit / PoC in the wildCVE-2023-20200CVE-2023-20169CVE-2023-20168+2 CVEs60
Zimbra urges customers to manually fix actively exploited zeroSecurity Affairs·Jul 13, 20:12 UTC · Jul 13, 2023Exploit / PoC in the wildCVE-2022-41352CVE-2022-27925160
CISA adds VMware's Cloud Foundation bug to Known Exploited Vulnerabilities CatalogSecurity Affairs·Mar 11, 08:20 UTC · Mar 11, 2023Exploit / PoC in the wildCVE-2021-3914460
VMware NSX Manager bugs actively exploited in the wildSecurity Affairs·Mar 8, 07:37 UTC · Mar 8, 2023Exploit / PoC in the wildCVE-2021-39144CVE-2022-3167860
Hackers Deploy Open-Source Tool Sliver C2, Replacing Cobalt Strike, MetasploitInfosecurity Magazine·Jan 23, 18:00 UTC · Jan 23, 2023Exploit / PoC45
Citrix and NSA urge admins to fix actively exploited zeroSecurity Affairs·Dec 13, 20:46 UTC · Dec 13, 2022Exploit / PoC in the wildCVE-2022-2751860
Over 17000 Fortinet devices exposed online are very likely vulnerable to CVE-2022Security Affairs·Oct 18, 07:56 UTC · Oct 18, 2022Exploit / PoC in the wildCVE-2022-4068460
VMware warns of public PoC code for critical auth bypass bug CVE-2022Security Affairs·Aug 10, 07:46 UTC · Aug 10, 2022Exploit / PoCCVE-2022-31656CVE-2022-3165960
MyBook Users Urged to Unplug Devices from InternetKrebs on Security·Jun 25, 20:37 UTC · Jun 25, 2021Exploit / PoC in the wildCVE-2018-1847260
Pulse Secure fixes zero-day in Pulse Connect Secure (PCS) SSL VPNSecurity Affairs·May 3, 17:39 UTC · May 3, 2021Exploit / PoC in the wildCVE-2021-2289360
Google reported that Microsoft failed to fix a Windows zeroSecurity Affairs·Dec 24, 13:08 UTC · Dec 24, 2020Exploit / PoC in the wildCVE-2020-0986CVE-2019-0880CVE-2020-1700860
DHS warns US businesses of China’s dataCyberScoop·Dec 23, 17:42 UTC · Dec 23, 2020Exploit / PoC in the wild60
Apache Software Foundation fixes code execution flaw in Apache Struts 2Security Affairs·Dec 9, 07:36 UTC · Dec 9, 2020Exploit / PoCCVE-2020-17530CVE-2019-0230160