AI Can Find Bugs, But Human Knowledge Still Proves ThemThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC57
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2025-32711150
Anthropic and OpenAI Security Tools Could Fuel CyberInfosecurity Magazine·Jul 10, 13:45 UTC · Jul 10, 2026Exploit / PoC60
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItThe Hacker News·Jul 9, 05:17 UTC · Jul 9, 2026Exploit / PoCCVE-2026-3986150
The Threat Isn’t the Frontier ModelRecorded Future·Jul 8, 00:00 UTC · Jul 8, 2026Exploit / PoC in the wild60
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsThe Hacker News·Jul 7, 04:58 UTC · Jul 7, 2026Exploit / PoCCVE-2026-53359CVE-2026-43284CVE-2026-43500+2 CVEs60
Seven Bugs in FatFs Put IoT and Embedded Devices at RiskSecurity Affairs·Jul 6, 10:20 UTC · Jul 6, 2026Exploit / PoCCVE-2026-6682CVE-2026-6683CVE-2026-6687+4 CVEs150
Bad Epoll Flaw Gives Attackers Root Access on Linux and AndroidSecurity Affairs·Jul 6, 08:24 UTC · Jul 6, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-4307460
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidThe Hacker News·Jul 3, 19:41 UTC · Jul 3, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-43074CVE-2026-31431+2 CVEs160
Public PoC Released for Critical libssh2 CVE-2026-55200 ClientThe Hacker News·Jun 29, 07:06 UTC · Jun 29, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2019-3855CVE-2026-55199+1 CVEs160
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsThe Hacker News·Jun 10, 17:30 UTC · Jun 10, 2026Exploit / PoC in the wildCVE-2026-33825CVE-2026-45498CVE-2026-41091160
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
MOVEit Transfer zero-day attacks: The latest infoHelp Net Security·Jun 8, 10:36 UTC · Jun 8, 2026Exploit / PoC60
Zero trust physical security needs trust decisions at the edgeHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Exploit / PoC60
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midtermsCyberScoop·May 27, 21:16 UTC · May 27, 2026Exploit / PoC in the wild60
Zero-Day Exploit Against Windows BitLockerSchneier on Security·May 18, 11:08 UTC · May 18, 2026Exploit / PoC60
Linux Kernel bug Fragnesia allows local root access attacksSecurity Affairs·May 17, 12:40 UTC · May 17, 2026Exploit / PoCCVE-2026-4630050
Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900KSecurity Affairs·May 15, 21:53 UTC · May 15, 2026Exploit / PoC60
Zero-day exploit completely defeats default Windows 11 BitLocker protectionsArs Technica · Security·May 15, 00:00 UTC · May 15, 2026Exploit / PoC60
NGINX Rift: an 18-year-old flaw in the world's most deployed web server just came to lightSecurity Affairs·May 14, 13:30 UTC · May 14, 2026Exploit / PoC in the wildCVE-2026-42945CVE-2026-42946CVE-2026-40701+1 CVEs60
Researchers say AI just broke every benchmark for autonomous cyber capabilityCyberScoop·May 13, 22:29 UTC · May 13, 2026Exploit / PoC in the wild60
One Missed Threat Per Week: What 25M Alerts Reveal About LowThe Hacker News·May 8, 10:30 UTC · May 8, 2026Exploit / PoC60
Ivanti EPMM vulnerability exploited in zero-day attacks (CVE-2026-6973)Help Net Security·May 8, 00:00 UTC · May 8, 2026Exploit / PoC in the wildCVE-2026-6973CVE-2026-1281CVE-2026-1340+4 CVEs60
12-year-old Pack2TheRoot bug lets Linux users gain root privilegesSecurity Affairs·Apr 24, 19:46 UTC · Apr 24, 2026Exploit / PoCCVE-2026-4165160
CISA cancels summer internships for cyber scholarship students amid DHS funding lapseCyberScoop·Apr 14, 23:17 UTC · Apr 14, 2026Exploit / PoC in the wild60
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197160
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates ReleasedThe Hacker News·Apr 9, 04:57 UTC · Apr 9, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in Recent Mass AttacksThe Hacker News·Apr 2, 07:21 UTC · Apr 2, 2026Exploit / PoC in the wildCVE-2023-32434CVE-2023-3860660
2025 Talos Year in Review: Speed, scale, and staying powerCisco Talos·Mar 23, 12:01 UTC · Mar 23, 2026Exploit / PoC in the wild60
Unprivileged users could exploit AppArmor bugs to gain root accessSecurity Affairs·Mar 16, 08:05 UTC · Mar 16, 2026Exploit / PoC60
Microsoft Fixes Two Publicly Disclosed ZeroInfosecurity Magazine·Mar 11, 09:20 UTC · Mar 11, 2026Exploit / PoCCVE-2026-21262CVE-2026-26127CVE-2026-23668+2 CVEs60
Microsoft warns North Korean threat groups are scaling up fake worker schemes with generative AICyberScoop·Mar 6, 19:16 UTC · Mar 6, 2026Exploit / PoC60
Coruna: Spy-grade iOS exploit kit powering financial crimeHelp Net Security·Mar 6, 10:01 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2024-23222CVE-2022-48503CVE-2023-43000+5 CVEs60
U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 4, 08:56 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2026-22719CVE-2026-2138560
VMware Aria Operations flaws could enable remote attacksSecurity Affairs·Feb 24, 15:03 UTC · Feb 24, 2026Exploit / PoCCVE-2026-22719CVE-2026-22720CVE-2026-2272160
CISA Adds Two Actively Exploited Roundcube Flaws to KEV CatalogThe Hacker News·Feb 21, 07:21 UTC · Feb 21, 2026Exploit / PoC in the wildCVE-2025-49113CVE-2025-6846160
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060