CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live AttacksThe Hacker News·Jul 23, 13:04 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
Microsoft SharePoint servers under attack via zero-day vulnerability (CVE-2025-53770)Help Net Security·Jul 22, 15:29 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs60
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News·Jul 22, 03:59 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs60
Oligo Security strives to fill applicationCyberScoop·Jul 8, 15:40 UTC · Jul 8, 2025Exploit / PoC in the wild60
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, TelecomsThe Hacker News·Jul 3, 09:25 UTC · Jul 3, 2025Exploit / PoC in the wildCVE-2024-8963CVE-2024-9380CVE-2024-819060
Log4Shell: How It’s Exploited and Mitigating DamageRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2021-4422860
Review: Learning Kali Linux, 2nd EditionHelp Net Security·Jun 16, 00:00 UTC · Jun 16, 2025Exploit / PoC45
Using an agent for the Mythic framework: pros and cons in pentestingKaspersky Securelist·May 13, 10:00 UTC · May 13, 2025Exploit / PoC60
New Critical SAP NetWeaver Flaw Exploited to Drop Web Shell, Brute Ratel FrameworkThe Hacker News·May 6, 13:53 UTC · May 6, 2025Exploit / PoC in the wildCVE-2017-9844CVE-2025-31324CVE-2017-1263760
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active ExploitationThe Hacker News·Apr 8, 15:56 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
Cybercrime gang exploited VeraCore zero-day vulnerabilities for years (CVE-2025-25181, CVE-2024-57968)Help Net Security·Feb 11, 13:53 UTC · Feb 11, 2025Exploit / PoCCVE-2025-25181CVE-2024-57968160
XE Group shifts from credit card skimming to exploiting zeroSecurity Affairs·Feb 10, 12:53 UTC · Feb 10, 2025Exploit / PoCCVE-2024-57968CVE-2025-25181CVE-2017-9248+1 CVEs60
U.S. CISA adds Cleo Harmony, VLTrader, and LexiCom flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 16, 15:09 UTC · Jan 16, 2025Exploit / PoC in the wildCVE-2024-50623160
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [30 Dec]The Hacker News·Jan 8, 11:22 UTC · Jan 8, 2025Exploit / PoCCVE-2024-3393CVE-2019-3568CVE-2024-56337+7 CVEs160
Mandiant devised a technique to bypass browser isolation using QR codesSecurity Affairs·Dec 9, 12:12 UTC · Dec 9, 2024Exploit / PoC45
Advanced threat predictions for 2025Kaspersky Securelist·Nov 25, 10:02 UTC · Nov 25, 2024Exploit / PoCCVE-2024-23222CVE-2024-23225CVE-2024-23296+3 CVEs60
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber IntrusionsThe Hacker News·Nov 11, 05:16 UTC · Nov 11, 2024Exploit / PoCCVE-2020-12271CVE-2020-15069CVE-2020-29574+2 CVEs60
Cybercriminals capitalize on poorly configured cloud environmentsHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2024Exploit / PoC60
U.S. Offers $10 Million for Info on Russian Cadet Blizzard Hackers Behind Major AttacksThe Hacker News·Sep 9, 04:33 UTC · Sep 9, 2024Exploit / PoC in the wild60
The best and worst ways to get users to improve their account securityCisco Talos·Sep 5, 18:00 UTC · Sep 5, 2024Exploit / PoCCVE-2024-797160
Sonos smart speakers flaw allowed to eavesdrop on usersSecurity Affairs·Aug 10, 00:00 UTC · Aug 10, 2024Exploit / PoCCVE-2023-50809CVE-2024-2001860
CISA adds Microsoft COM for Windows bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 8, 20:41 UTC · Aug 8, 2024Exploit / PoC in the wildCVE-2018-0824160
CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 13:33 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2022-3802860
Hackers Exploit OpenMetadata Flaws to Mine Crypto on KubernetesThe Hacker News·Apr 23, 05:41 UTC · Apr 23, 2024Exploit / PoCCVE-2024-28847CVE-2024-28848CVE-2024-28253+3 CVEs60
Palo Alto Networks Discloses More Details on Critical PANThe Hacker News·Apr 20, 13:04 UTC · Apr 20, 2024Exploit / PoC in the wildCVE-2024-340060
Hackers Exploit Fortinet Flaw, Deploy ScreenConnect, Metasploit in New CampaignThe Hacker News·Apr 18, 14:09 UTC · Apr 18, 2024Exploit / PoCCVE-2023-4878860
Palo Alto Networks ZeroInfosecurity Magazine·Apr 15, 15:30 UTC · Apr 15, 2024Exploit / PoC in the wildCVE-2024-340060
“Highly capable” hackers root corporate networks by exploiting firewall 0Ars Technica · Security·Apr 12, 20:48 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security FlawsThe Hacker News·Apr 6, 09:12 UTC · Apr 6, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-2189360
U.S. Charges 7 Chinese Nationals in Major 14The Hacker News·Mar 26, 16:21 UTC · Mar 26, 2024Exploit / PoC60
Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warnsArs Technica · Security·Feb 27, 20:57 UTC · Feb 27, 2024Exploit / PoCCVE-2023-2339760
Ivanti Pulse Secure Found Using 11-YearThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21893+1 CVEs60
CISA orders federal agencies to disconnect Ivanti VPN instances by February 2Security Affairs·Feb 1, 19:46 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Ivanti Releases ZeroInfosecurity Magazine·Feb 1, 09:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Rust Payloads Exploiting Ivanti 0Infosecurity Magazine·Jan 30, 15:00 UTC · Jan 30, 2024Exploit / PoCCVE-2024-21887CVE-2023-4680560
Securonix Autonomous Threat Sweeper automates search for Log4j related activityHelp Net Security·Dec 12, 13:02 UTC · Dec 12, 2023Exploit / PoC45
Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60