Microsoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsThe Hacker News·Jul 30, 11:54 UTC · Jul 30, 2026Exploit / PoC145
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)Help Net Security·Jul 27, 00:00 UTC · Jul 27, 2026Exploit / PoCCVE-2026-54121160
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News·Jul 22, 15:41 UTC · Jul 22, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine·Jul 20, 14:00 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
AI Can Find Bugs, But Human Knowledge Still Proves ThemThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC57
Researcher Explains Release of Undisclosed ZeroInfosecurity Magazine·Jul 2, 12:51 UTC · Jul 2, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2026-58049CVE-2026-58050+10 CVEs160
New attack provides one more reason why AI browsers are a bad ideaArs Technica · Security·Jun 30, 20:03 UTC · Jun 30, 2026Exploit / PoC45
Malicious hackers exploit Cisco zero-day for highest access level at communications service providerCyberScoop·Jun 24, 19:00 UTC · Jun 24, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2026-20182CVE-2026-2024560
Researchers Trick AI Browsers Into Leaking CredentialsInfosecurity Magazine·Jun 24, 16:05 UTC · Jun 24, 2026Exploit / PoC45
Unpatchable BootROM Flaw Impacts Apple A12, A13 ChipsInfosecurity Magazine·Jun 22, 14:00 UTC · Jun 22, 2026Exploit / PoC60
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
China’s Zero-Day Pipeline: From Discovery to DeploymentRecorded Future·Jun 4, 00:00 UTC · Jun 4, 2026Exploit / PoC60
Autonomous AI-driven worm can reason its way through corporate networksHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2026Exploit / PoC in the wild60
Why you need BAS and autonomous pentesting togetherHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Exploit / PoC60
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AIThe Hacker News·May 26, 12:07 UTC · May 26, 2026Exploit / PoC in the wild60
Linux Kernel bug Fragnesia allows local root access attacksSecurity Affairs·May 17, 12:40 UTC · May 17, 2026Exploit / PoCCVE-2026-4630050
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-31431CVE-2022-27666CVE-2026-43284+1 CVEs60
Zero-day exploit completely defeats default Windows 11 BitLocker protectionsArs Technica · Security·May 15, 00:00 UTC · May 15, 2026Exploit / PoC60
U.S. CISA adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 14, 18:36 UTC · May 14, 2026Exploit / PoC in the wildCVE-2026-20182CVE-2026-2012760
New Fragnesia Flaw Hands Linux Local Users Root AccessInfosecurity Magazine·May 14, 13:00 UTC · May 14, 2026Exploit / PoCCVE-2026-46300CVE-2026-31431CVE-2026-43284+1 CVEs50
U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 11, 09:14 UTC · May 11, 2026Exploit / PoC in the wildCVE-2026-4220860
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AICyberScoop·May 8, 13:14 UTC · May 8, 2026Exploit / PoC in the wild60
One Missed Threat Per Week: What 25M Alerts Reveal About LowThe Hacker News·May 8, 10:30 UTC · May 8, 2026Exploit / PoC60
Rowhammer Attack Against NVIDIA ChipsSchneier on Security·May 6, 10:37 UTC · May 6, 2026Exploit / PoC45
cPanel zero-day exploited for months before patch release (CVE-2026-41940)Help Net Security·May 5, 12:05 UTC · May 5, 2026Exploit / PoC in the wildCVE-2026-4194060
U.S. CISA adds a flaw in WebPros cPanel to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 3, 14:41 UTC · May 3, 2026Exploit / PoC in the wildCVE-2026-4194060
U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 29, 07:40 UTC · Apr 29, 2026Exploit / PoC in the wildCVE-2024-1708CVE-2026-3220260
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New StoriesThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2026Exploit / PoCCVE-2026-27175CVE-2026-27174CVE-2025-22952+1 CVEs60
Researchers unveil novel attack methods targeting Intel's conditional branch predictorHelp Net Security·Apr 23, 13:44 UTC · Apr 23, 2026Exploit / PoC45
Capsule Security debuts with $7 million funding to secure AI agent behaviorHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2026Exploit / PoCCVE-2026-2152060
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Ubiquiti defect poses account takeover risk for UniFi Networking Application usersCyberScoop·Mar 20, 16:22 UTC · Mar 20, 2026Exploit / PoC in the wildCVE-2026-22557CVE-2026-2255860
U.S. robotics companies want federal help to keep Chinese robots out of America’s networksCyberScoop·Mar 18, 19:42 UTC · Mar 18, 2026Exploit / PoC in the wild60
U.S. CISA adds Ivanti EPM, SolarWinds, and Omnissa Workspace One flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 10, 09:52 UTC · Mar 10, 2026Exploit / PoC in the wildCVE-2021-22054CVE-2025-26399CVE-2026-160360
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since MidThe Hacker News·Mar 6, 10:06 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2026-2276960
AI-Driven Insider Risk Now a “Critical Business Threat,” Report WarnsInfosecurity Magazine·Mar 5, 16:00 UTC · Mar 5, 2026Exploit / PoC60
Russia-linked APT28 exploited MSHTML zero-day CVE-2026Security Affairs·Mar 2, 14:46 UTC · Mar 2, 2026Exploit / PoCCVE-2026-2151360
Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127)Help Net Security·Feb 27, 07:46 UTC · Feb 27, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2022-2077560