Apple fixes two actively exploited iOS zero-days (CVE-2024-23225, CVE-2024-23296)Help Net Security·May 14, 12:44 UTC · May 14, 2024Exploit / PoC in the wildCVE-2024-23225CVE-2024-2329660
Treasury official: Small financial institutions have ‘growth to do’ in using AI against threatsCyberScoop·Apr 19, 15:45 UTC · Apr 19, 2024Exploit / PoC in the wild60
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious ExtensionsThe Hacker News·Mar 29, 05:21 UTC · Mar 29, 2024Exploit / PoC in the wildCVE-2024-2138860
Zero-day exploitation surged in 2023, Google findsHelp Net Security·Mar 28, 00:00 UTC · Mar 28, 2024Exploit / PoC in the wild60
ONCD releases report on the adoption of memoryCyberScoop·Feb 26, 19:43 UTC · Feb 26, 2024Exploit / PoC in the wild60
Week in review: AnyDesk phishing campaign targets employees, Microsoft fixes exploited zero-daysHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23313CVE-2023-43770+5 CVEs160
Apple Issues Patch for Critical Zero-Day in iPhones, MacsThe Hacker News·Jan 23, 10:40 UTC · Jan 23, 2024Exploit / PoC in the wildCVE-2024-23222CVE-2023-42916CVE-2023-42917160
Zero-Day Alert: Apple Rolls Out iOS, macOS, and Safari Patches for 2 Actively Exploited FlawsThe Hacker News·Dec 5, 05:36 UTC · Dec 5, 2023Exploit / PoC in the wildCVE-2023-42916CVE-2023-42917CVE-2023-634560
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246)Help Net Security·Nov 9, 00:00 UTC · Nov 9, 2023Exploit / PoCCVE-2023-47246CVE-2023-3436260
Week in review: Chrome zero-day is actually in libwebp, Sony hacking rumoursHelp Net Security·Oct 1, 00:00 UTC · Oct 1, 2023Exploit / PoC in the wildCVE-2023-42793CVE-2023-5129CVE-2023-4863+1 CVEs60
CISA Adds Microsoft .NET Vulnerability to KEV Catalog Due to Active ExploitationThe Hacker News·Aug 11, 03:38 UTC · Aug 11, 2023Exploit / PoC in the wildCVE-2023-3818060
Microsoft Addresses Critical Power Platform Flaw After Delays and CriticismThe Hacker News·Aug 5, 07:38 UTC · Aug 5, 2023Exploit / PoC in the wild60
Apple Issues Urgent Patch for Zero-Day Flaw Targeting iOS, iPadOS, macOS, and SafariThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Exploit / PoC in the wildCVE-2023-3745060
Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in iOS, macOS, and SafariThe Hacker News·Jul 11, 03:31 UTC · Jul 11, 2023Exploit / PoC in the wildCVE-2023-32434CVE-2023-32435CVE-2023-32439+6 CVEs60
Microsoft Warns of Widescale Credential Stealing Attacks by Russian HackersThe Hacker News·Jun 27, 14:11 UTC · Jun 27, 2023Exploit / PoCCVE-2020-12641CVE-2020-35730CVE-2021-44026+1 CVEs60
NSO Group Used 3 Zero-Click iPhone Exploits Against Human Rights DefendersThe Hacker News·Apr 20, 11:48 UTC · Apr 20, 2023Exploit / PoC60
The Discord servers at the center of a massive US intelligence leakCyberScoop·Apr 10, 19:59 UTC · Apr 10, 2023Exploit / PoC in the wild60
Hackers Steal Over $1.6 Million in Crypto from General Bytes Bitcoin ATMs Using ZeroThe Hacker News·Mar 23, 11:58 UTC · Mar 23, 2023Exploit / PoC60
Hackers used Fortra zero-day to steal sales data from cloud management giant RubrikThe Record·Mar 14, 21:37 UTC · Mar 14, 2023Exploit / PoC in the wildCVE-2023-066960
CISA director urges tech sector to stop shipping unsafe productsCyberScoop·Feb 27, 17:43 UTC · Feb 27, 2023Exploit / PoC in the wild60
Zero day affecting Fortra’s GoAnywhere file transfer tool is actively being exploitedThe Record·Feb 7, 14:52 UTC · Feb 7, 2023Exploit / PoC60
Microsoft: Chinese APT Targeted Exchange Servers With Four ZeroThe Record·Jan 30, 00:00 UTC · Jan 30, 2023Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Google: North Korean gov’t hackers used Internet Explorer zeroThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Exploit / PoCCVE-2022-4112860
CISA adds Apple zero-day, Cisco and Gigabyte bugs to exploited vulnerabilities listThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Exploit / PoC in the wildCVE-2020-3433CVE-2020-315360
Hackers Can Use Ultrasonic Waves to Secretly Control Voice Assistant DevicesThe Hacker News·Dec 30, 09:06 UTC · Dec 30, 2022Exploit / PoC in the wild60
Senators want agencies to encrypt data before sharing with new NSF databaseCyberScoop·Dec 20, 18:00 UTC · Dec 20, 2022Exploit / PoC in the wild60
New SmashEx attack breaks Intel SGX enclavesThe Record·Dec 18, 00:00 UTC · Dec 18, 2022Exploit / PoCCVE-2021-0186CVE-2021-3376750
Senate intel committee to revive ‘roadshow’ on Chinese threatsThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC60
Meta takes down surveillance-for-hire firms, calls for government action against the industryCyberScoop·Dec 15, 18:00 UTC · Dec 15, 2022Exploit / PoC in the wild60
Researcher dumps three iOS zero-days after Apple failed to fix issues for monthsThe Record·Dec 14, 00:00 UTC · Dec 14, 2022Exploit / PoC60
Apple releases fix for iOS and macOS zeroThe Record·Dec 10, 00:00 UTC · Dec 10, 2022Exploit / PoC in the wildCVE-2021-30807CVE-2021-1782CVE-2021-1870+10 CVEs60
Google Warns of Internet Explorer Zero-Day Vulnerability Exploited by ScarCruft HackersThe Hacker News·Dec 9, 17:03 UTC · Dec 9, 2022Exploit / PoC in the wildCVE-2020-1380CVE-2021-26411CVE-2022-4112860
GitHub to review its exploit-hosting policy in light of recent scandalThe Record·Dec 7, 00:00 UTC · Dec 7, 2022Exploit / PoC45
‘Every Attack Was Like a Slightly Deadlier Version Than the Last:’ NYT’s Perlroth Talks About Her New BookThe Record·Nov 17, 16:28 UTC · Nov 17, 2022Exploit / PoC60
Mitigation for Exchange Zero-Days Bypassed! Microsoft Issues New WorkaroundsThe Hacker News·Oct 6, 04:57 UTC · Oct 6, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160