900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell AttacksThe Hacker News·Mar 4, 16:55 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2025-6432860
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 14, 16:27 UTC · Feb 14, 2026Exploit / PoC in the wildCVE-2026-1731CVE-2026-2485860
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
China-linked APT UNC3886 targets Singapore telcosSecurity Affairs·Feb 10, 08:40 UTC · Feb 10, 2026Exploit / PoCCVE-2022-4132860
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 30, 10:40 UTC · Jan 30, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-2485860
⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AIThe Hacker News·Jan 20, 09:20 UTC · Jan 20, 2026Exploit / PoCCVE-2025-29824CVE-2025-2775CVE-2025-2776+19 CVEs60
Week in review: PoC for FortiSIEM flaw released, Rakuten Viber CISO/CTO on messaging risksHelp Net Security·Jan 18, 00:00 UTC · Jan 18, 2026Exploit / PoCCVE-2025-64155CVE-2025-20393160
Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 releasedHelp Net Security·Dec 21, 00:00 UTC · Dec 21, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-40602CVE-2025-14174+1 CVEs160
U.S. CISA adds a flaw in WatchGuard Fireware OS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 20, 10:26 UTC · Dec 20, 2025Exploit / PoC in the wildCVE-2025-14733CVE-2025-59718CVE-2025-59719+1 CVEs60
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell AccessThe Hacker News·Nov 7, 06:24 UTC · Nov 7, 2025Exploit / PoC in the wildCVE-2025-261160
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever ShippedThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-24990CVE-2025-59230CVE-2025-47827+5 CVEs160
NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs·Aug 28, 10:48 UTC · Aug 28, 2025Exploit / PoCCVE-2024-21887CVE-2023-46805CVE-2024-3400+3 CVEs160
Vulnerabilities in MSP-friendly RMM solution exploited in the wild (CVE-2025-8875, CVE-2025-8876)Help Net Security·Aug 14, 00:00 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2025-8875CVE-2025-887660
Third of Exploited Flaws Weaponized Within a Day of DisclosureInfosecurity Magazine·Jul 30, 12:45 UTC · Jul 30, 2025Exploit / PoC in the wild60
Singapore warns China-linked group UNC3886 targets its critical infrastructureSecurity Affairs·Jul 20, 17:17 UTC · Jul 20, 2025Exploit / PoCCVE-2022-4132860
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, TelecomsThe Hacker News·Jul 3, 09:25 UTC · Jul 3, 2025Exploit / PoC in the wildCVE-2024-8963CVE-2024-9380CVE-2024-819060
CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, DThe Hacker News·Jun 27, 05:06 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2024-54085CVE-2024-0769CVE-2019-669360
Week in review: Google fixes exploited Chrome zero-day, Patch Tuesday forecastHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2025Exploit / PoC in the wildCVE-2025-541960
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
Dutch Warn of “Whole of Society” Russian CyberInfosecurity Magazine·Apr 23, 09:45 UTC · Apr 23, 2025Exploit / PoC60
Security Affairs newsletter Round 520 by Pierluigi PaganiniSecurity Affairs·Apr 20, 16:14 UTC · Apr 20, 2025Exploit / PoC in the wildCVE-2025-30406CVE-2025-24054CVE-2021-2003560
China-linked APT UNC3886 targets EoL Juniper routersSecurity Affairs·Mar 13, 23:47 UTC · Mar 13, 2025Exploit / PoCCVE-2022-41328CVE-2025-2159060
China continues cyberattacks on routers, this time targeting Juniper Networks devicesThe Record·Mar 12, 22:37 UTC · Mar 12, 2025Exploit / PoC60
Week in review: Botnet hits M365 accounts, PoC for Ivanti Endpoint Manager vulnerabilities releasedHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2025Exploit / PoCCVE-2024-13159CVE-2025-2336360
768 CVEs Exploited in 2024, Reflecting a 20% Increase from 639 in 2023The Hacker News·Feb 3, 13:57 UTC · Feb 3, 2025Exploit / PoC in the wildCVE-2021-4422860
3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security UpdateThe Hacker News·Jan 21, 15:30 UTC · Jan 21, 2025Exploit / PoC in the wildCVE-2024-7344CVE-2025-21333CVE-2025-21334+13 CVEs60
What 2024 taught us about security vulnerabiltiesHelp Net Security·Jan 14, 00:00 UTC · Jan 14, 2025Exploit / PoC in the wildCVE-2023-3519CVE-2023-20198CVE-2021-4422860
Cybersecurity jobs available right now: October 16, 2024Help Net Security·Nov 25, 09:23 UTC · Nov 25, 2024Exploit / PoC45
Palo Alto Networks Confirms New ZeroInfosecurity Magazine·Nov 15, 15:30 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-591060
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs260
Surge in exploits of zero-day vulnerabilities is ‘new normal’ warns Five Eyes allianceThe Record·Nov 12, 16:08 UTC · Nov 12, 2024Exploit / PoCCVE-2023-351960
Defenders must adapt to shrinking exploitation timelinesHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2024Exploit / PoC in the wildCVE-2023-28121CVE-2023-2799760
Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the WildThe Hacker News·Oct 9, 12:48 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+7 CVEs60
Cisco Warns of Critical Flaw Affecting OnThe Hacker News·Jul 18, 13:13 UTC · Jul 18, 2024Exploit / PoC in the wildCVE-2024-20419CVE-2024-20401CVE-2024-34102+2 CVEs60