We moved fast and broke things. It’s time for a change.CyberScoop·Feb 2, 11:00 UTC · Feb 2, 2026Exploit / PoC60
U.S. CISA adds a flaw in Microsoft Windows to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 14, 11:45 UTC · Jan 14, 2026Exploit / PoC in the wildCVE-2026-2080560
Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploitsHelp Net Security·Dec 23, 00:00 UTC · Dec 23, 2025Exploit / PoCCVE-2025-10294CVE-2025-59295CVE-2025-59230+7 CVEs60
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research AgentThe Hacker News·Sep 20, 05:32 UTC · Sep 20, 2025Exploit / PoC45
CISA, Microsoft warn of critical Exchange hybrid flaw CVE-2025Security Affairs·Aug 7, 14:05 UTC · Aug 7, 2025Exploit / PoC in the wildCVE-2025-5378660
Palo Alto Networks to acquire CyberArk for $25 billionCyberScoop·Jul 30, 14:27 UTC · Jul 30, 2025Exploit / PoC in the wild60
China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosureSecurity Affairs·May 26, 11:31 UTC · May 26, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
Silk Typhoon shifted to specifically targeting IT management companiesCyberScoop·Mar 6, 14:54 UTC · Mar 6, 2025Exploit / PoC in the wildCVE-2025-028260
China-linked APT Silk Typhoon targets IT Supply ChainSecurity Affairs·Mar 5, 21:02 UTC · Mar 5, 2025Exploit / PoCCVE-2025-028260
Silk Typhoon Shifts Tactics to Exploit Common IT SolutionsInfosecurity Magazine·Mar 5, 16:30 UTC · Mar 5, 2025Exploit / PoC in the wildCVE-2025-028260
Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecastHelp Net Security·Jan 12, 00:00 UTC · Jan 12, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2024-41713CVE-2024-55550+1 CVEs60
Microsoft Fixes Three ZeroInfosecurity Magazine·May 15, 09:30 UTC · May 15, 2024Exploit / PoC in the wildCVE-2024-30051CVE-2024-30040CVE-2024-30046+1 CVEs160
January 2021 Patch Tuesday: Microsoft plugs Defender zero-day RCEHelp Net Security·Nov 14, 08:33 UTC · Nov 14, 2023Exploit / PoC in the wildCVE-2021-1647CVE-2021-1648CVE-2021-1658+8 CVEs60
Chinese Hacker Steals Microsoft Signing Key, Spies on US GovernmentInfosecurity Magazine·Sep 7, 13:00 UTC · Sep 7, 2023Exploit / PoC60
Ivanti Sentry zero-day vulnerability exploited, patch ASAP! (CVE-2023-38035)Help Net Security·Aug 24, 12:34 UTC · Aug 24, 2023Exploit / PoC in the wildCVE-2023-3803560
Call for Submissions to UK's New Computer Misuse ActInfosecurity Magazine·Mar 28, 10:00 UTC · Mar 28, 2023Exploit / PoC60
Pwn2Own Vancouver 2023 Day 1: Windows 11 and Tesla hackedSecurity Affairs·Mar 23, 10:10 UTC · Mar 23, 2023Exploit / PoC60
PoC exploit for recently patched Microsoft Word RCE is public (CVE-2023-21716)Help Net Security·Mar 6, 00:00 UTC · Mar 6, 2023Exploit / PoCCVE-2023-21716160
A new APT is targeting hotels across the worldThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Exploit / PoC57
Microsoft fixes exploited zero-day, revokes certificate used to sign malicious drivers (CVE-2022-44698)Help Net Security·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoCCVE-2022-44698CVE-2022-41076CVE-2022-44713+2 CVEs60
Microsoft fixes exploited zero-day in the Windows CLFS Driver (CVE-2022-37969)Help Net Security·Sep 19, 07:02 UTC · Sep 19, 2022Exploit / PoC in the wildCVE-2022-37969CVE-2022-24521CVE-2022-34724+4 CVEs60
Perception Point Free Plan allows interception of advanced threats missed by other servicesHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2021Exploit / PoC60
March 2021 Patch Tuesday: Microsoft fixes yet another actively exploited IE zero-dayHelp Net Security·Jun 8, 18:28 UTC · Jun 8, 2021Exploit / PoC in the wildCVE-2021-26411CVE-2021-27076CVE-2021-26867+1 CVEs60
Microsoft Fixes Exchange Server ZeroInfosecurity Magazine·May 12, 10:50 UTC · May 12, 2021Exploit / PoC in the wildCVE-2021-31207CVE-2021-31200CVE-2021-31204+2 CVEs60
Microsoft fixes 2 critical Exchange Server flaws reported by the NSASecurity Affairs·Apr 13, 21:05 UTC · Apr 13, 2021Exploit / PoCCVE-2021-28480CVE-2021-28481CVE-2021-28482+1 CVEs60
Microsoft Releases Windows Update (Dec 2020) to Fix 58 Security FlawsThe Hacker News·Dec 9, 04:58 UTC · Dec 9, 2020Exploit / PoC in the wildCVE-2020-17132CVE-2020-17118CVE-2020-17121+4 CVEs60
Iran-linked APT is exploiting the Zerologon flaw in attacksSecurity Affairs·Oct 6, 07:41 UTC · Oct 6, 2020Exploit / PoC in the wildCVE-2020-1472CVE-2019-0604160
Australia blames a state actor for major disruptions. China is already denying it.CyberScoop·Jun 19, 15:33 UTC · Jun 19, 2020Exploit / PoC in the wild60
Friday Squid Blogging: New Tool for Grabbing Squid and other Fragile Sea CreaturesSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Exploit / PoC160
Week in review: IE zero-day, S3 bucket security, rise of RDP as a target vectorHelp Net Security·Sep 29, 00:00 UTC · Sep 29, 2019Exploit / PoC in the wildCVE-2019-1675960
The U.S. Air Force is outsourcing all traditional IT in order to build cybersecurity mission teamsCyberScoop·Apr 3, 14:43 UTC · Apr 3, 2018Exploit / PoC in the wild60
Microsoft Fixes 3 ZeroSecurity Affairs·Oct 15, 14:09 UTC · Oct 15, 2014Exploit / PoC in the wildCVE-2014-4114CVE-2014-4148CVE-2014-4113160