Week in review: Public MS Word RCE PoC, API exploitation, Patch Tuesday forecastHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2023Exploit / PoCCVE-2023-27532CVE-2023-25610CVE-2023-21716160
Google: North Korean gov’t hackers used Internet Explorer zeroThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Exploit / PoCCVE-2022-4112860
New German government coalition promises not to buy exploitsThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Exploit / PoC60
Chinese Hackers Begin Exploiting Latest Microsoft Office ZeroThe Hacker News·Jun 1, 10:00 UTC · Jun 1, 2022Exploit / PoC in the wildCVE-2022-30190160
Microsoft shared workarounds for the Microsoft Office Follina 0daySecurity Affairs·May 31, 11:19 UTC · May 31, 2022Exploit / PoCCVE-2022-30190160
Microsoft Office versions impacted by an actively exploited zeroSecurity Affairs·May 30, 12:06 UTC · May 30, 2022Exploit / PoC in the wild60
IRS Will Soon Require Selfies for Online AccessKrebs on Security·Jan 30, 15:19 UTC · Jan 30, 2022Exploit / PoC60
Talos release protection against zero-day vulnerability (CVE-2021Cisco Talos·Sep 9, 15:38 UTC · Sep 9, 2021Exploit / PoC in the wildCVE-2021-4044460
Attackers are exploiting zero-day RCE flaw to target Windows users (CVE-2021-40444)Help Net Security·Sep 8, 00:00 UTC · Sep 8, 2021Exploit / PoCCVE-2021-4044460
Biden budget seeks $750 million to respond to SolarWinds compromises, plus billions more for cyberCyberScoop·May 28, 18:11 UTC · May 28, 2021Exploit / PoC in the wild60
Fake job listings help suspected Iranian hackers aim at targets in LebanonCyberScoop·Apr 8, 14:44 UTC · Apr 8, 2021Exploit / PoC in the wild60
UK 'almost certain' that 2019 election was target of Russian disinformation operationCyberScoop·Jul 16, 15:47 UTC · Jul 16, 2020Exploit / PoC in the wild60
Is Emotet gang targeting companies with external SOC?Security Affairs·Oct 14, 17:49 UTC · Oct 14, 2019Exploit / PoC60
Chinese-linked hacking group gets crafty to avoid detectionCyberScoop·Oct 2, 12:00 UTC · Oct 2, 2019Exploit / PoC in the wild60
Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”Cisco Talos·Sep 17, 15:09 UTC · Sep 17, 2019Exploit / PoCCVE-2017-10271CVE-2017-563860
A researcher made an elite hacking tool out of the info in the Vault 7 leakCyberScoop·Feb 27, 21:15 UTC · Feb 27, 2019Exploit / PoC in the wild60
3 New Code Execution Flaws Discovered in Atlantis Word ProcessorThe Hacker News·Nov 20, 16:30 UTC · Nov 20, 2018Exploit / PoCCVE-2018-4038CVE-2018-4039CVE-2018-404060
Operation Shaheen - Pakistan Air Force targeted by nationSecurity Affairs·Nov 13, 14:27 UTC · Nov 13, 2018Exploit / PoC60
Threats posed by using RATs in ICSKaspersky Securelist·Sep 20, 10:00 UTC · Sep 20, 2018Exploit / PoC60
GZipDe Downloader spotted serving Metasploit backdoorSecurity Affairs·Jun 22, 08:27 UTC · Jun 22, 2018Exploit / PoC57
Former DIA official allegedly sold secrets to China, including possible Cyber Command informationCyberScoop·Jun 5, 17:50 UTC · Jun 5, 2018Exploit / PoC in the wild60
Booby-trapped Office docs build with ThreadKit trigger CVE-2018Security Affairs·Apr 10, 08:15 UTC · Apr 10, 2018Exploit / PoCCVE-2018-4878CVE-2018-0802CVE-2017-857060
NSA has been tracking bitcoin users since 2013CyberScoop·Mar 20, 22:35 UTC · Mar 20, 2018Exploit / PoC in the wild60
Chinese hackers tried to spy on U.S. think tanks to steal military strategy documents, CrowdStrike saysCyberScoop·Dec 21, 18:45 UTC · Dec 21, 2017Exploit / PoC in the wild60
North Korean hackers turn focus to cryptocurrency, point-ofCyberScoop·Dec 21, 14:32 UTC · Dec 21, 2017Exploit / PoC in the wild60
Carbanak gang makes the headlines again, hackers refined intrusion tacticsSecurity Affairs·Oct 9, 21:08 UTC · Oct 9, 2017Exploit / PoC45
Deep Dive in MarkLogic Exploitation Process via Argus PDF ConverterCisco Talos·Sep 14, 19:38 UTC · Sep 14, 2017Exploit / PoCCVE-2016-833560
WikiLeaks Exposed CIA's Hacking Tools And Capabilities DetailsThe Hacker News·Mar 7, 18:30 UTC · Mar 7, 2017Exploit / PoC60
Online Trust Alliance joins warnings on IoT cyber dangersCyberScoop·Oct 18, 11:09 UTC · Oct 18, 2016Exploit / PoC in the wild60
NIST: Agencies must prepare to get hackedCyberScoop·Jun 20, 12:31 UTC · Jun 20, 2016Exploit / PoC in the wild60
The Acrobat JavaScript Blocklist FrameworkCisco Talos·Jan 20, 17:56 UTC · Jan 20, 2010Exploit / PoC in the wildCVE-2008-2992CVE-2009-0927CVE-2009-1493+5 CVEs60
Guardian Agents: The Next Layer of Identity GovernanceThe Hacker News·Jun 26, 11:30 UTC · Jun 26, 2026Exploit / PoC145
New cybersecurity guidance paves the way for AI in critical infrastructureCyberScoop·Dec 11, 12:00 UTC · Dec 11, 2025Exploit / PoC in the wild60
Five-page draft Trump administration cyber strategy targeted for January releaseCyberScoop·Dec 4, 14:44 UTC · Dec 4, 2025Exploit / PoC in the wild60
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
Diplomatic entities in Belgium and Hungary hacked in ChinaThe Record·Oct 30, 18:17 UTC · Oct 30, 2025Exploit / PoC60
We Are Still Unable to Secure LLMs from Malicious InputsSchneier on Security·Aug 27, 13:17 UTC · Aug 27, 2025Exploit / PoC45
UAT-5918 targets critical infrastructure entities in TaiwanCisco Talos·Mar 20, 10:00 UTC · Mar 20, 2025Exploit / PoC60
Cellebrite blocked Serbia from using its solution because misuse of the equipment for political reasonsSecurity Affairs·Feb 27, 09:41 UTC · Feb 27, 2025Exploit / PoCCVE-2024-4304760
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW ProtectionsThe Hacker News·Feb 6, 03:48 UTC · Feb 6, 2025Exploit / PoC in the wildCVE-2025-041160