Strix: Open-source AI agents for penetration testingHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2025Exploit / PoC45
Top 10 Takeaways from Predict 2025: Turning Intelligence Into ActionRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025Exploit / PoC in the wild60
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 21:39 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2025-2791560
Zimbra users targeted in zeroSecurity Affairs·Oct 7, 21:32 UTC · Oct 7, 2025Exploit / PoCCVE-2025-2791560
Default Cursor setting can be exploited to run malicious code on developers' machinesHelp Net Security·Sep 11, 00:00 UTC · Sep 11, 2025Exploit / PoC145
Apache Tomcat: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-2481360
Combating Human Trafficking With Threat Intelligence — ProsecutionRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC45
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025The Hacker News·Aug 12, 08:36 UTC · Aug 12, 2025Exploit / PoC in the wildCVE-2025-6543CVE-2025-577760
You Are What You Eat: Why Your AI Security Tools Are Only as Strong as the Data You Feed ThemThe Hacker News·Aug 1, 11:00 UTC · Aug 1, 2025Exploit / PoC60
CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active ExploitationThe Hacker News·Jul 29, 04:51 UTC · Jul 29, 2025Exploit / PoC in the wildCVE-2023-253360
Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the WildThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Exploit / PoC in the wildCVE-2025-4781260
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe Hacker News·Jul 8, 05:08 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+3 CVEs60
Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry CloudThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoCCVE-2025-43697CVE-2025-43698CVE-2025-43699+3 CVEs60
Researcher Finds Five Zero-Days and 20 Misconfigurations in SalesforceInfosecurity Magazine·Jun 11, 11:30 UTC · Jun 11, 2025Exploit / PoCCVE-2025-4399CVE-2025-43700CVE-2025-43701+2 CVEs60
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance ModelsThe Hacker News·May 5, 15:51 UTC · May 5, 2025Exploit / PoC in the wildCVE-2023-44221CVE-2024-38475CVE-2021-2003560
U.S. CISA adds Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 3, 10:11 UTC · May 3, 2025Exploit / PoC in the wildCVE-2025-34028CVE-2024-58136CVE-2025-32432260
U.S. CISA adds SonicWall SMA100 and Apache HTTP Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 2, 07:50 UTC · May 2, 2025Exploit / PoC in the wildCVE-2024-38475CVE-2023-4422160
Two SonicWall SMA100 flaws actively exploited in the wildSecurity Affairs·May 1, 08:31 UTC · May 1, 2025Exploit / PoC in the wildCVE-2023-44221CVE-2024-3847560
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active ExploitationThe Hacker News·Apr 8, 15:56 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
Splunk fixed tens of flaws in Splunk Enterprise and Cloud PlatformSecurity Affairs·Jul 4, 09:06 UTC · Jul 4, 2024Exploit / PoC in the wildCVE-2024-36985CVE-2024-36984CVE-2024-36997+12 CVEs60
Palo Alto Networks Discloses More Details on Critical PANThe Hacker News·Apr 20, 13:04 UTC · Apr 20, 2024Exploit / PoC in the wildCVE-2024-340060
Palo Alto Networks Releases Urgent Fixes for Exploited PANThe Hacker News·Apr 17, 12:08 UTC · Apr 17, 2024Exploit / PoC in the wildCVE-2024-340060
Don't miss these keynotes at RSAC 2019Help Net Security·Feb 8, 09:54 UTC · Feb 8, 2024Exploit / PoC in the wildCVE-2026-8749160
CISA adds Qlik Sense flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 11, 09:52 UTC · Dec 11, 2023Exploit / PoC in the wildCVE-2023-41265CVE-2023-4126660
Featured talks at the upcoming Hack In The Box Security ConferenceHelp Net Security·Nov 20, 13:37 UTC · Nov 20, 2023Exploit / PoC60
Enhancing TLS Security: Google Adds QuantumThe Hacker News·Aug 12, 05:46 UTC · Aug 12, 2023Exploit / PoC60
Menlo Leverages Advanced Technology to Combat Surging Browser ThreatsInfosecurity Magazine·Aug 3, 13:15 UTC · Aug 3, 2023Exploit / PoC60
A Data Exfiltration Attack Scenario: The Porsche ExperienceThe Hacker News·Jul 28, 11:48 UTC · Jul 28, 2023Exploit / PoC60
Microsoft Warns of Widescale Credential Stealing Attacks by Russian HackersThe Hacker News·Jun 27, 14:11 UTC · Jun 27, 2023Exploit / PoCCVE-2020-12641CVE-2020-35730CVE-2021-44026+1 CVEs60
KeePass fixed bug that allows extraction of cleartext master pwdSecurity Affairs·Jun 5, 18:24 UTC · Jun 5, 2023Exploit / PoCCVE-2023-3278450
KeePass 2.X Master Password Dumper allows retrieving the KeePass master passwordSecurity Affairs·May 18, 20:17 UTC · May 18, 2023Exploit / PoCCVE-2023-3278450
CISA adds Zimbra bug exploited in attacks against NATO countries to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 8, 22:11 UTC · Apr 8, 2023Exploit / PoC in the wildCVE-2022-2792660
RSA Conference announces initial 2019 keynote speakersHelp Net Security·Mar 9, 19:18 UTC · Mar 9, 2023Exploit / PoC in the wildCVE-2026-8749160
A couple of bugs can be chained to hack Netcomm routersSecurity Affairs·Jan 18, 15:18 UTC · Jan 18, 2023Exploit / PoCCVE-2022-4873CVE-2022-487460
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
A flaw in Amazon Ring could expose user's camera recordingsSecurity Affairs·Aug 19, 11:56 UTC · Aug 19, 2022Exploit / PoC57
Chinese Hackers Exploited Sophos Firewall ZeroThe Hacker News·Jun 18, 03:43 UTC · Jun 18, 2022Exploit / PoCCVE-2022-1040CVE-2022-2613460
Chinese APT exploited Sophos Firewall ZeroSecurity Affairs·Jun 17, 23:00 UTC · Jun 17, 2022Exploit / PoC in the wildCVE-2022-1040CVE-2022-2613460