China-linked APT UAT-8837 targets North American critical infrastructureSecurity Affairs·Jan 17, 15:50 UTC · Jan 17, 2026Exploit / PoCCVE-2025-5369060
Cisco email security appliances rooted and backdoored via still unpatched zero-dayHelp Net Security·Jan 16, 14:17 UTC · Jan 16, 2026Exploit / PoCCVE-2025-20393CVE-2025-5777CVE-2025-7775160
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)Help Net Security·Jan 16, 00:00 UTC · Jan 16, 2026Exploit / PoC in the wildCVE-2025-2039360
Cisco Patches Zero-Day RCE Exploited by ChinaThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoCCVE-2025-2039360
Hackers turn open-source AI framework into global cryptojacking operationCyberScoop·Nov 19, 15:29 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2023-48022160
Strix: Open-source AI agents for penetration testingHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2025Exploit / PoC45
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Red Hat AI 3 helps enterprises scale AI workloads across hybrid environmentsHelp Net Security·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC145
NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs·Aug 28, 10:48 UTC · Aug 28, 2025Exploit / PoCCVE-2024-21887CVE-2023-46805CVE-2024-3400+3 CVEs160
ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram BotsThe Hacker News·Aug 28, 03:59 UTC · Aug 28, 2025Exploit / PoCCVE-2018-7600CVE-2018-76020CVE-2024-2795650
Hundreds of Salesforce customers impacted by attack spree linked to thirdCyberScoop·Aug 27, 01:22 UTC · Aug 27, 2025Exploit / PoC in the wild60
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter EnvironmentsThe Hacker News·Jul 29, 04:24 UTC · Jul 29, 2025Exploit / PoCCVE-2023-34048CVE-2023-20867CVE-2022-138860
Researchers flag flaw in Google’s AI coding assistant that allowed for ‘silent’ code exfiltrationCyberScoop·Jul 28, 20:26 UTC · Jul 28, 2025Exploit / PoC in the wild60
Oligo Security strives to fill applicationCyberScoop·Jul 8, 15:40 UTC · Jul 8, 2025Exploit / PoC in the wild60
China-linked group Houken hit French organizations using zeroSecurity Affairs·Jul 3, 18:16 UTC · Jul 3, 2025Exploit / PoCCVE-2024-8963CVE-2024-938060
Chinese Hackers Target France in Ivanti ZeroInfosecurity Magazine·Jul 2, 12:00 UTC · Jul 2, 2025Exploit / PoCCVE-2024-8190CVE-2024-8963CVE-2024-9380160
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 12, 09:17 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-24016CVE-2025-3305360
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation EvidenceThe Hacker News·May 8, 13:52 UTC · May 8, 2025Exploit / PoC in the wildCVE-2025-324860
Security Affairs newsletter Round 520 by Pierluigi PaganiniSecurity Affairs·Apr 20, 16:14 UTC · Apr 20, 2025Exploit / PoC in the wildCVE-2025-30406CVE-2025-24054CVE-2021-2003560
Commix: Open-source OS command injection exploitation toolHelp Net Security·Apr 2, 08:47 UTC · Apr 2, 2025Exploit / PoC145
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade DetectionThe Hacker News·Feb 10, 04:09 UTC · Feb 10, 2025Exploit / PoC57
U.S. CISA adds Cleo Harmony, VLTrader, and LexiCom flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 16, 15:09 UTC · Jan 16, 2025Exploit / PoC in the wildCVE-2024-5062360
Fake PoC Exploit Targets Security Researchers with InfostealerInfosecurity Magazine·Jan 10, 09:15 UTC · Jan 10, 2025Exploit / PoCCVE-2024-49113160
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC ExploitsThe Hacker News·Dec 17, 04:40 UTC · Dec 17, 2024Exploit / PoC57
Here’s how simple it is for script kiddies to stand up DDoS servicesCyberScoop·Nov 26, 11:00 UTC · Nov 26, 2024Exploit / PoC60
Advanced threat predictions for 2025Kaspersky Securelist·Nov 25, 10:02 UTC · Nov 25, 2024Exploit / PoCCVE-2024-23222CVE-2024-23225CVE-2024-23296+3 CVEs60
Attackers are hijacking Jupyter notebooks to host illegal Champions League streamsCyberScoop·Nov 19, 14:00 UTC · Nov 19, 2024Exploit / PoC in the wild160
Google’s AI Tool Big Sleep Finds Zero-Day Vulnerability in SQLite Database EngineThe Hacker News·Nov 4, 10:04 UTC · Nov 4, 2024Exploit / PoC60
Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android usersHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2024Exploit / PoC in the wildCVE-2023-45249CVE-2024-3708560
Low-level cybercriminals are pouncing on CrowdStrikeCyberScoop·Jul 23, 22:05 UTC · Jul 23, 2024Exploit / PoC in the wild60
Are Your Nagios XI Servers Turning Into Cryptocurrency Miners for Attackers?Palo Alto Unit 42·Jun 6, 12:45 UTC · Jun 6, 2024Exploit / PoCCVE-2021-2529650
PDF Exploitation Targets Foxit Reader UsersInfosecurity Magazine·May 15, 16:30 UTC · May 15, 2024Exploit / PoC45
Palo Alto Networks Outlines Remediation for Critical PANThe Hacker News·May 1, 06:14 UTC · May 1, 2024Exploit / PoC in the wildCVE-2024-340060
Critical Update: CrushFTP ZeroThe Hacker News·Apr 27, 05:01 UTC · Apr 27, 2024Exploit / PoC in the wildCVE-2024-404060
Palo Alto Networks Releases Urgent Fixes for Exploited PANThe Hacker News·Apr 17, 12:08 UTC · Apr 17, 2024Exploit / PoC in the wildCVE-2024-340060
Palo Alto Networks ZeroInfosecurity Magazine·Apr 15, 15:30 UTC · Apr 15, 2024Exploit / PoC in the wildCVE-2024-340060
Palo Alto Networks warns of zeroThe Record·Apr 12, 14:52 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
North Korean hackers exploit Windows zeroThe Record·Feb 29, 18:36 UTC · Feb 29, 2024Exploit / PoCCVE-2024-2133860
Hackers backed by Russia and China are infecting SOHO routers like yours, FBI warnsArs Technica · Security·Feb 27, 20:57 UTC · Feb 27, 2024Exploit / PoCCVE-2023-2339760