Cybersecurity jobs available right now: January 13, 2026Help Net Security·May 18, 08:30 UTC · May 18, 2026Exploit / PoC60
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber DefenseRecorded Future·May 14, 00:00 UTC · May 14, 2026Exploit / PoC in the wild60
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New StoriesThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2026Exploit / PoCCVE-2026-27175CVE-2026-27174CVE-2025-22952+1 CVEs60
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active ExploitationThe Hacker News·Apr 17, 13:10 UTC · Apr 17, 2026Exploit / PoC in the wildCVE-2026-34197CVE-2024-32114CVE-2023-4660460
‘GrafanaGhost’ bypasses Grafana's AI defenses without leaving a traceCyberScoop·Apr 7, 17:01 UTC · Apr 7, 2026Exploit / PoC in the wild60
Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in Recent Mass AttacksThe Hacker News·Apr 2, 07:21 UTC · Apr 2, 2026Exploit / PoC in the wildCVE-2023-32434CVE-2023-3860660
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
2025 Talos Year in Review: Speed, scale, and staying powerCisco Talos·Mar 23, 12:01 UTC · Mar 23, 2026Exploit / PoC in the wild60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
State Dept. official says post-quantum transition plans will outlive current leadershipCyberScoop·Feb 20, 17:36 UTC · Feb 20, 2026Exploit / PoC in the wild60
Unit 42: Nearly two-thirds of breaches now start with identity abuseCyberScoop·Feb 17, 11:00 UTC · Feb 17, 2026Exploit / PoC60
Notepad++ supply chain attack: Researchers reveal details, IoCs, targetsHelp Net Security·Feb 17, 10:13 UTC · Feb 17, 2026Exploit / PoC60
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Some ChatGPT browser extensions are stealing your dataCyberScoop·Jan 26, 19:32 UTC · Jan 26, 2026Exploit / PoC in the wild60
Why cybersecurity cannot hire its way through the AI eraCyberScoop·Jan 7, 12:00 UTC · Jan 7, 2026Exploit / PoC in the wild60
What cybersecurity leaders are reading to stay aheadHelp Net Security·Dec 18, 00:00 UTC · Dec 18, 2025Exploit / PoC57
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
WinRAR zero-day was exploited by two threat actors (CVE-2025-8088)Help Net Security·Nov 19, 15:20 UTC · Nov 19, 2025Exploit / PoCCVE-2025-8088CVE-2025-5518860
Operational Cyber Threat IntelligenceRecorded Future·Nov 19, 00:00 UTC · Nov 19, 2025Exploit / PoC in the wild60
China-linked UNC6384 exploits Windows zeroSecurity Affairs·Nov 1, 14:11 UTC · Nov 1, 2025Exploit / PoC60
Trick, treat, repeatCisco Talos·Oct 30, 18:00 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-5928760
Reducing abuse of Microsoft 365 Exchange Online’s Direct SendCisco Talos·Oct 21, 10:00 UTC · Oct 21, 2025Exploit / PoC60
Researchers find a startlingly cheap way to steal your secrets from spaceCyberScoop·Oct 14, 20:06 UTC · Oct 14, 2025Exploit / PoC60
Libraesva ESG zero-day vulnerability exploited by attackers (CVE-2025-59689)Help Net Security·Sep 24, 00:00 UTC · Sep 24, 2025Exploit / PoCCVE-2025-5968960
Gurucul’s AI-IRM accelerates insider risk detectionHelp Net Security·Sep 18, 00:00 UTC · Sep 18, 2025Exploit / PoC in the wildCVE-2026-8749160
How a fake ICS network can reveal real cyberattacksHelp Net Security·Sep 17, 00:00 UTC · Sep 17, 2025Exploit / PoC60
MeetC2 - A serverless C2 framework that leverages Google Calendar APIs as a communication channelSecurity Affairs·Sep 6, 09:39 UTC · Sep 6, 2025Exploit / PoC45
From summer camp to grind seasonCisco Talos·Sep 4, 18:02 UTC · Sep 4, 2025Exploit / PoCCVE-2025-5517760
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-dayHelp Net Security·Aug 24, 00:00 UTC · Aug 24, 2025Exploit / PoC in the wildCVE-2025-43300CVE-2018-0171CVE-2025-31324+1 CVEs60
WinRAR Zero-Day Under Active ExploitationThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Exploit / PoC in the wildCVE-2025-8088CVE-2023-38831CVE-2025-6218+2 CVEs60
High-severity WinRAR 0Ars Technica · Security·Aug 12, 00:13 UTC · Aug 12, 2025Exploit / PoC in the wildCVE-2025-8088CVE-2025-621860
WinRAR zero-day exploited by RomCom hackers in targeted attacksHelp Net Security·Aug 11, 00:00 UTC · Aug 11, 2025Exploit / PoC in the wildCVE-2025-808860
Third of Exploited Flaws Weaponized Within a Day of DisclosureInfosecurity Magazine·Jul 30, 12:45 UTC · Jul 30, 2025Exploit / PoC in the wild60
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter EnvironmentsThe Hacker News·Jul 29, 04:24 UTC · Jul 29, 2025Exploit / PoCCVE-2023-34048CVE-2023-20867CVE-2022-138860
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053)Help Net Security·Jun 16, 13:26 UTC · Jun 16, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-33073CVE-2025-33070+6 CVEs60
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active ExploitationThe Hacker News·Apr 8, 15:56 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
Attackers are targeting CrushFTP vulnerability with public PoC (CVE-2025-2825)Help Net Security·Apr 7, 09:29 UTC · Apr 7, 2025Exploit / PoC in the wildCVE-2025-2825CVE-2025-3116160
Tomorrow, and tomorrow, and tomorrow: Information security and the Baseball Hall of FameCisco Talos·Mar 20, 18:00 UTC · Mar 20, 2025Exploit / PoC60