n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n ProcessThe Hacker News·Jul 27, 13:05 UTC · Jul 27, 2026Exploit / PoC in the wildCVE-2026-2757760
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theftSecurity Affairs·Jul 22, 21:20 UTC · Jul 22, 2026Exploit / PoCCVE-2026-4829460
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsThe Hacker News·Jul 11, 06:45 UTC · Jul 11, 2026Exploit / PoC in the wildCVE-2025-27915CVE-2023-37580CVE-2024-2744360
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited PagesThe Hacker News·Jul 8, 12:17 UTC · Jul 8, 2026Exploit / PoC in the wild60
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
Google fixes fifth actively exploited Chrome zeroSecurity Affairs·Jun 9, 10:38 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+2 CVEs60
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
Funnel Builder Flaw Exploited to Enable WooCommerce Checkout SkimmingThe Hacker News·Jun 1, 11:32 UTC · Jun 1, 2026Exploit / PoC in the wild60
Zapier exploit chain shows how known anti-patterns compose into critical riskHelp Net Security·May 28, 00:00 UTC · May 28, 2026Exploit / PoC60
Why the Axios attack proves AI is mandatory for supply chain securityCyberScoop·Apr 20, 13:17 UTC · Apr 20, 2026Exploit / PoC in the wild60
Critical Magento 2 flaw exploited within 16 hoursSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Exploit / PoC60
Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621)Help Net Security·Apr 13, 00:00 UTC · Apr 13, 2026Exploit / PoC in the wildCVE-2026-3462160
Acrobat Reader zero-day exploited in the wild for many months (CVE-2026-34621)Help Net Security·Apr 12, 14:38 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-3462160
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025The Hacker News·Apr 12, 04:25 UTC · Apr 12, 2026Exploit / PoCCVE-2026-3462160
ClawJacked flaw exposed OpenClaw users to data theftSecurity Affairs·Mar 2, 09:42 UTC · Mar 2, 2026Exploit / PoC60
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API EnablementThe Hacker News·Feb 28, 17:01 UTC · Feb 28, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
Microsoft Fixes Three ZeroInfosecurity Magazine·Dec 10, 09:45 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62221CVE-2025-54100CVE-2025-64671+4 CVEs60
Google fixed Chrome flaw found by Big Sleep AISecurity Affairs·Aug 20, 08:39 UTC · Aug 20, 2025Exploit / PoCCVE-2025-913260
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 11, 07:47 UTC · Jul 11, 2025Exploit / PoC in the wildCVE-2025-655460
Mozilla fixed zeroSecurity Affairs·May 19, 18:31 UTC · May 19, 2025Exploit / PoCCVE-2025-4918CVE-2025-491960
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [30 Dec]The Hacker News·Jan 8, 11:22 UTC · Jan 8, 2025Exploit / PoCCVE-2024-3393CVE-2019-3568CVE-2024-56337+7 CVEs160
ProjectSend critical flaw actively exploited in the wild, experts warnSecurity Affairs·Nov 28, 07:28 UTC · Nov 28, 2024Exploit / PoC in the wildCVE-2024-1168060
Google fixes fifth actively exploited Chrome zeroSecurity Affairs·May 16, 12:58 UTC · May 16, 2024Exploit / PoC in the wildCVE-2024-4671CVE-2024-0519CVE-2024-2887+2 CVEs60
Google fixed another Chrome zeroSecurity Affairs·Apr 3, 21:15 UTC · Apr 3, 2024Exploit / PoC in the wildCVE-2024-3159CVE-2024-3156CVE-2024-3158+3 CVEs60
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious ExtensionsThe Hacker News·Mar 29, 05:21 UTC · Mar 29, 2024Exploit / PoC in the wildCVE-2024-2138860
Google addressed 2 Chrome zeroSecurity Affairs·Mar 28, 00:39 UTC · Mar 28, 2024Exploit / PoC in the wildCVE-2024-2886CVE-2024-2887CVE-2024-2883+4 CVEs60
Mozilla fixed Firefox 0days exploited at Pwn2Own Vancouver 2024Security Affairs·Mar 23, 13:53 UTC · Mar 23, 2024Exploit / PoCCVE-2024-29944CVE-2024-29943CVE-2024-299460
Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacksSecurity Affairs·Oct 26, 05:20 UTC · Oct 26, 2023Exploit / PoCCVE-2020-35730CVE-2022-27926CVE-2023-563160
Pro-Russia hackers target inboxes with 0Ars Technica · Security·Oct 25, 22:21 UTC · Oct 25, 2023Exploit / PoCCVE-2023-563160
Roundcube webmail zero-day exploited to spy on government entities (CVE-2023-5631)Help Net Security·Oct 25, 00:00 UTC · Oct 25, 2023Exploit / PoCCVE-2023-5631CVE-2020-35730CVE-2022-2792660
Fata Morgana Watering Hole Attack Targets Shipping, Logistics FirmsInfosecurity Magazine·May 23, 17:00 UTC · May 23, 2023Exploit / PoC57
Experts devised a new exploit for the PaperCut flaw that can bypass all current detectionSecurity Affairs·May 5, 11:01 UTC · May 5, 2023Exploit / PoC in the wildCVE-2023-2735060
Researchers disclose sandbox escape bug in vm2 sandbox librarySecurity Affairs·Apr 9, 20:34 UTC · Apr 9, 2023Exploit / PoCCVE-2023-29017CVE-2022-3606760
Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players' SystemsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2023Exploit / PoCCVE-2021-38003160
Two New Security Flaws Reported in Ghost CMS Blogging SoftwareThe Hacker News·Dec 23, 11:36 UTC · Dec 23, 2022Exploit / PoC in the wildCVE-2022-41654CVE-2022-4169760
Google issued emergency fixes to fix actively exploited Chrome-zeroSecurity Affairs·Sep 3, 15:40 UTC · Sep 3, 2022Exploit / PoC in the wildCVE-2022-3075CVE-2022-2856CVE-2022-2294+3 CVEs60