Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Attackers are exploiting AI faster than defenders can keep up, new report warnsCyberScoop·Mar 16, 16:08 UTC · Mar 16, 2026Exploit / PoC in the wild60
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
Cisco email security appliances rooted and backdoored via still unpatched zero-dayHelp Net Security·Jan 16, 14:17 UTC · Jan 16, 2026Exploit / PoCCVE-2025-20393CVE-2025-5777CVE-2025-7775160
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs160
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
China-linked Silk Typhoon APT targets North AmericaSecurity Affairs·Aug 23, 08:34 UTC · Aug 23, 2025Exploit / PoCCVE-2023-351960
CrowdStrike warns of uptick in Silk Typhoon attacks this summerCyberScoop·Aug 22, 16:39 UTC · Aug 22, 2025Exploit / PoC in the wildCVE-2023-3519CVE-2025-392860
China-linked Murky Panda targets and moves laterally through cloud servicesHelp Net Security·Aug 22, 00:00 UTC · Aug 22, 2025Exploit / PoCCVE-2023-3519CVE-2025-392860
Warnings issued as hackers actively exploit critical zeroThe Record·Jul 21, 11:00 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-5377160
Is Ivanti the problem or a symptom of a systemic issue with network devices?CyberScoop·Apr 14, 13:57 UTC · Apr 14, 2025Exploit / PoC in the wild60
768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023The Hacker News·Feb 3, 13:57 UTC · Feb 3, 2025Exploit / PoC in the wildCVE-2021-4422860
What 2024 taught us about security vulnerabiltiesHelp Net Security·Jan 14, 00:00 UTC · Jan 14, 2025Exploit / PoC in the wildCVE-2023-3519CVE-2023-20198CVE-2021-4422860
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs260
Surge in exploits of zero-day vulnerabilities is ‘new normal’ warns Five Eyes allianceThe Record·Nov 12, 16:08 UTC · Nov 12, 2024Exploit / PoCCVE-2023-351960
Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the WildThe Hacker News·Oct 9, 12:48 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+7 CVEs60
New hacker group uses open-source tools to spy on entities in AsiaThe Record·Jul 18, 12:25 UTC · Jul 18, 2024Exploit / PoC60
Rising exploitation in enterprise software: Key trends for CISOsHelp Net Security·Jun 19, 00:00 UTC · Jun 19, 2024Exploit / PoC60
“Highly capable” hackers root corporate networks by exploiting firewall 0Ars Technica · Security·Apr 12, 20:48 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security FlawsThe Hacker News·Apr 6, 09:12 UTC · Apr 6, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active ExploitationThe Hacker News·Feb 10, 06:49 UTC · Feb 10, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23108CVE-2024-23109+2 CVEs60
CISA, FBI warn of China-linked hackers pre-positioning for ‘destructive cyberattacks against US critical infrastructure’The Record·Feb 7, 19:27 UTC · Feb 7, 2024Exploit / PoC60
North Korean Hackers Exploit Zero-Day Bug to Target Cybersecurity ResearchersThe Hacker News·Sep 8, 16:50 UTC · Sep 8, 2023Exploit / PoCCVE-2021-34514CVE-2022-2188160
North Korean hackers target security researchers with zero-day exploitHelp Net Security·Sep 8, 00:00 UTC · Sep 8, 2023Exploit / PoC60
North Korean hackers target security researchers with new zeroThe Record·Sep 7, 18:53 UTC · Sep 7, 2023Exploit / PoC160
Researchers warn of hackers widely exploiting bug in Zyxel hardwareThe Record·Jun 1, 12:30 UTC · Jun 1, 2023Exploit / PoC in the wildCVE-2023-28771CVE-2023-33009CVE-2023-3301060
CISA adds Veeam Backup and Replication bugs to Known Exploited Vulnerabilities CatalogSecurity Affairs·Dec 16, 09:17 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2022-26500CVE-2022-26501CVE-2022-42475+3 CVEs60
Microsoft Releases Fix for Zero-Day Flaw in July 2022 Security Patch RolloutThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2022Exploit / PoC in the wildCVE-2022-22047CVE-2022-22026CVE-2022-22049+14 CVEs60
Fed cyber officials detail Chinese state hackers using common exploits against telcosCyberScoop·Jun 8, 15:50 UTC · Jun 8, 2022Exploit / PoC in the wild60
Microsoft Releases Fix for New ZeroThe Hacker News·May 11, 16:06 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+14 CVEs60
FBI Issues Flash Alert on Actively Exploited FatPipe VPN ZeroThe Hacker News·Nov 19, 09:27 UTC · Nov 19, 2021Exploit / PoC in the wild60
Top 12 Security Flaws Russian Spy Hackers Are Exploiting in the WildThe Hacker News·May 11, 06:23 UTC · May 11, 2021Exploit / PoCCVE-2018-13379CVE-2019-9670CVE-2019-11510+9 CVEs60
U.S. government accuses Russian companies of recruiting spies, hacking for MoscowCyberScoop·Apr 16, 13:48 UTC · Apr 16, 2021Exploit / PoC in the wild60
NSA, FBI, DHS expose Russian intelligence hacking tradecraftCyberScoop·Apr 15, 13:56 UTC · Apr 15, 2021Exploit / PoC in the wild60
Advanced hackers use Fortinet flaws in likely attempt to breach government networks, feds warnCyberScoop·Apr 2, 16:59 UTC · Apr 2, 2021Exploit / PoC in the wild60
Russian-speaking hackers target Russian organizations with industrial spying toolsCyberScoop·Oct 8, 13:40 UTC · Oct 8, 2020Exploit / PoC in the wild60
Australia blames a state actor for major disruptions. China is already denying it.CyberScoop·Jun 19, 15:33 UTC · Jun 19, 2020Exploit / PoC in the wild60
NSA calls out Russian military hackers targeting mail relay softwareCyberScoop·May 28, 18:41 UTC · May 28, 2020Exploit / PoC in the wildCVE-2019-1014960