U.S. CISA adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 6, 09:22 UTC · Feb 6, 2026Exploit / PoC in the wildCVE-2025-11953CVE-2026-2442360
SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch ReleaseThe Hacker News·Jan 30, 04:24 UTC · Jan 30, 2026Exploit / PoC in the wildCVE-2025-52691CVE-2026-2376060
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
Atlassian fixed maximum severity flaw CVE-2025Security Affairs·Dec 15, 15:03 UTC · Dec 15, 2025Exploit / PoCCVE-2025-66516CVE-2025-54988CVE-2021-39227+1 CVEs60
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
Cisco ASA zero-day vulnerabilities exploited in sophisticated attacksHelp Net Security·Nov 13, 13:30 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Samsung Mobile Flaw Exploited as ZeroThe Hacker News·Nov 11, 11:21 UTC · Nov 11, 2025Exploit / PoC in the wildCVE-2025-21042CVE-2025-21043CVE-2025-55177+1 CVEs60
LANDFALL spyware exploited Samsung zero-day CVE-2025Security Affairs·Nov 7, 21:54 UTC · Nov 7, 2025Exploit / PoC in the wildCVE-2025-21042CVE-2025-2104360
Chrome Zero-Day Exploited to Deliver Italian Memento Labs' LeetAgent SpywareThe Hacker News·Nov 3, 17:57 UTC · Nov 3, 2025Exploit / PoC in the wildCVE-2025-2783160
Lanscope Endpoint Manager vulnerability exploited in zero-day attacks (CVE-2025-61932)Help Net Security·Oct 30, 23:11 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-6193260
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER MalwareThe Hacker News·Sep 27, 12:13 UTC · Sep 27, 2025Exploit / PoC in the wildCVE-2025-20362CVE-2025-20333CVE-2025-2036360
ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram BotsThe Hacker News·Aug 28, 03:59 UTC · Aug 28, 2025Exploit / PoCCVE-2018-7600CVE-2018-76020CVE-2024-2795650
H1 2024 Malware & Vulnerability Trends Report: Zero-Day Exploits, Infostealers, and Emerging Malware ThreatsRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Exploit / PoC60
NightEagle APT Exploits Microsoft Exchange Flaw to Target China's Military and Tech SectorsThe Hacker News·Jul 10, 04:17 UTC · Jul 10, 2025Exploit / PoC60
Researcher Finds Five Zero-Days and 20 Misconfigurations in SalesforceInfosecurity Magazine·Jun 11, 11:30 UTC · Jun 11, 2025Exploit / PoCCVE-2025-4399CVE-2025-43700CVE-2025-43701+2 CVEs60
Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network AttacksThe Hacker News·May 22, 12:07 UTC · May 22, 2025Exploit / PoCCVE-2025-4427CVE-2025-4428CVE-2025-3132460
CISA: Recently fixed Chrome vulnerability exploited in the wild (CVE-2025-4664)Help Net Security·May 16, 00:00 UTC · May 16, 2025Exploit / PoC in the wildCVE-2025-466460
UAT-5918 targets critical infrastructure entities in TaiwanCisco Talos·Mar 20, 10:00 UTC · Mar 20, 2025Exploit / PoC60
U.S. CISA adds Trimble Cityworks flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 7, 21:54 UTC · Feb 7, 2025Exploit / PoC in the wildCVE-2025-099460
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW ProtectionsThe Hacker News·Feb 6, 03:48 UTC · Feb 6, 2025Exploit / PoC in the wildCVE-2025-041160
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [3 February]The Hacker News·Feb 4, 11:56 UTC · Feb 4, 2025Exploit / PoC in the wildCVE-2025-24085CVE-2024-41710CVE-2025-0626+30 CVEs60
The Mask APT is back after 10 years of silenceSecurity Affairs·Dec 18, 08:20 UTC · Dec 18, 2024Exploit / PoC60
Careto APT’s recent attacks discoveredKaspersky Securelist·Dec 12, 10:00 UTC · Dec 12, 2024Exploit / PoC160
BootKitty Linux UEFI bootkit spotted exploiting LogoFAIL flawsSecurity Affairs·Dec 3, 08:11 UTC · Dec 3, 2024Exploit / PoCCVE-2023-4023850
Russian group RomCom exploited Firefox and Tor Browser zero-days to target attacks Europe and North AmericaSecurity Affairs·Nov 27, 08:37 UTC · Nov 27, 2024Exploit / PoC in the wildCVE-2024-9680CVE-2024-4903960
RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated CyberattacksThe Hacker News·Nov 27, 04:06 UTC · Nov 27, 2024Exploit / PoCCVE-2024-9680CVE-2024-49039CVE-2023-3688460
ESET researchers analyze first UEFI bootkit for Linux systemsHelp Net Security·Nov 27, 00:00 UTC · Nov 27, 2024Exploit / PoC57
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
U.S. CISA adds SonicWall SonicOS, ImageMagick and Linux Kernel bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 10, 07:18 UTC · Sep 10, 2024Exploit / PoC in the wildCVE-2016-3714CVE-2017-1000253CVE-2024-4076660
US and Allies Accuse Russian Military of Destructive CyberInfosecurity Magazine·Sep 6, 11:20 UTC · Sep 6, 2024Exploit / PoC in the wild60
South Korea-linked group APT-C-60 exploited a WPS Office zeroSecurity Affairs·Aug 30, 11:09 UTC · Aug 30, 2024Exploit / PoCCVE-2924-726360
CISA adds Microsoft COM for Windows bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 8, 20:41 UTC · Aug 8, 2024Exploit / PoC in the wildCVE-2018-0824160
Void Banshee APT exploited "lingering Windows relic" in zero-day attacksHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2024Exploit / PoCCVE-2024-3811260
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
TheMoon bot infected 40,000 devices in January and FebruarySecurity Affairs·Mar 26, 21:19 UTC · Mar 26, 2024Exploit / PoC60
Alert: Ivanti Discloses 2 New ZeroThe Hacker News·Feb 1, 03:20 UTC · Feb 1, 2024Exploit / PoCCVE-2024-21888CVE-2024-21893CVE-2023-46805+1 CVEs160
Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
Experts Uncover DarkCasino: New Emerging APT Threat Exploiting WinRAR FlawThe Hacker News·Nov 17, 05:08 UTC · Nov 17, 2023Exploit / PoCCVE-2023-3883160