⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active ExploitationThe Hacker News·Apr 8, 15:56 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [30 Dec]The Hacker News·Jan 8, 11:22 UTC · Jan 8, 2025Exploit / PoCCVE-2024-3393CVE-2019-3568CVE-2024-56337+7 CVEs160
National Cyber Director Harry Coker looks back (and ahead) on the Cyber Director officeCyberScoop·Jan 8, 00:52 UTC · Jan 8, 2025Exploit / PoC in the wild60
DoubleClickjacking allows clickjacking on major websitesSecurity Affairs·Jan 2, 17:34 UTC · Jan 2, 2025Exploit / PoC60
Evilginx: Open-source man-in-the-middle attack frameworkHelp Net Security·Dec 23, 00:00 UTC · Dec 23, 2024Exploit / PoC60
Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival HijackThe Hacker News·Sep 5, 09:14 UTC · Sep 5, 2024Exploit / PoC in the wild60
Obfuscation: There Are Two Sides To EverythingThe Hacker News·Aug 1, 11:07 UTC · Aug 1, 2024Exploit / PoC60
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022Palo Alto Unit 42·Jun 5, 20:43 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2022-22954CVE-2022-22960CVE-2022-22972+8 CVEs60
Researcher Uncovers Flaws in Cox Modems, Potentially Impacting MillionsThe Hacker News·Jun 3, 10:48 UTC · Jun 3, 2024Exploit / PoC in the wild60
Usage of TLS in DDNS Services leads to Information Disclosure in Multiple VendorsSecurity Affairs·May 24, 08:58 UTC · May 24, 2024Exploit / PoC60
EPA will step up inspections of water sector cybersecurityCyberScoop·May 20, 22:33 UTC · May 20, 2024Exploit / PoC in the wild60
Expand your library with these cybersecurity booksHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2024Exploit / PoC in the wildCVE-2026-8749160
Why the toothbrush DDoS story fooled us allCisco Talos·Feb 15, 19:00 UTC · Feb 15, 2024Exploit / PoCCVE-2022-073260
Raspberry Robin spotted using two new 1Security Affairs·Feb 11, 19:37 UTC · Feb 11, 2024Exploit / PoC in the wildCVE-2023-36802CVE-2023-2936060
DHS council seeks to simplify cyber incident reporting rulesCyberScoop·Sep 20, 14:56 UTC · Sep 20, 2023Exploit / PoC in the wild60
Intelligence community to meet with civil liberties groups on controversial surveillance toolCyberScoop·Sep 6, 21:38 UTC · Sep 6, 2023Exploit / PoC in the wild60
Week in review: Microsoft, Apple patch exploited zero-days, tips for getting hired in cybersecurityHelp Net Security·Feb 19, 00:00 UTC · Feb 19, 2023Exploit / PoC in the wildCVE-2023-21715CVE-2023-23376CVE-2023-21823+2 CVEs60
First Fully Weaponized Spectre Exploit Discovered OnlineThe Record·Jan 30, 00:00 UTC · Jan 30, 2023Exploit / PoC in the wild60
Attack of drones: airborne cybersecurity nightmareSecurity Affairs·Dec 2, 21:22 UTC · Dec 2, 2022Exploit / PoC57
Cyberspace Solarium Commission members push to advance remaining recommendationsCyberScoop·Sep 21, 09:30 UTC · Sep 21, 2022Exploit / PoC in the wild60
Cyber Command's rotation 'problem' exacerbates talent shortage amid growing digital threatCyberScoop·Aug 19, 10:46 UTC · Aug 19, 2022Exploit / PoC60
CIA 'secret bulk collection program' picked up some Americans' data, senators revealCyberScoop·Feb 11, 14:46 UTC · Feb 11, 2022Exploit / PoC in the wild60
IT threat evolution Q3 2021Kaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021Exploit / PoCCVE-2021-4044460
ChaosDB, a Critical Cosmos DB flaw affected thousands of Microsoft Azure CustomersSecurity Affairs·Aug 27, 17:36 UTC · Aug 27, 2021Exploit / PoC60
DeepDotWeb boss pleads guilty to laundering millionsCyberScoop·Apr 1, 14:04 UTC · Apr 1, 2021Exploit / PoC in the wild60
Russia, Iran ran influence operations aimed at 2020 elections, US saysCyberScoop·Mar 16, 19:15 UTC · Mar 16, 2021Exploit / PoC in the wild60
Zero-day vulnerabilities in Microsoft Exchange ServerKaspersky Securelist·Mar 4, 17:20 UTC · Mar 4, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Expert discloses PoC code for critical RCEs in Cisco Security ManagerSecurity Affairs·Nov 17, 21:14 UTC · Nov 17, 2020Exploit / PoC60
Friday Squid Blogging: Saving the Humboldt SquidSchneier on Security·Oct 9, 21:02 UTC · Oct 9, 2020Exploit / PoC145
Microsoft failed to fix LSASS elevation of privilege flawSecurity Affairs·Aug 13, 15:50 UTC · Aug 13, 2020Exploit / PoCCVE-2020-150950
Suspected Chinese hackers targeting Vatican in advance of Beijing negotiationsCyberScoop·Jul 29, 21:29 UTC · Jul 29, 2020Exploit / PoC in the wild60
‘Vendetta’ hackers are posing as Taiwan's CDC in dataCyberScoop·Jun 15, 18:59 UTC · Jun 15, 2020Exploit / PoC in the wild60
Shoddy US government review of Chinese telcos endangered national security, Senate panel findsCyberScoop·Jun 9, 19:02 UTC · Jun 9, 2020Exploit / PoC in the wild60
Coronavirus conspiracy theorists threaten 5G cell towers, DHS memo warnsCyberScoop·Jun 8, 12:10 UTC · Jun 8, 2020Exploit / PoC in the wild60
Google finds Indian hack-for-hire firms exploiting coronavirus fears via spearphishing schemesCyberScoop·May 27, 20:47 UTC · May 27, 2020Exploit / PoC in the wild60
Privacy groups are still trying to get documents unsealed in Facebook encryption caseCyberScoop·Apr 28, 21:13 UTC · Apr 28, 2020Exploit / PoC in the wild60
European police remove 26,000 pieces of Islamic State content from social mediaCyberScoop·Nov 26, 15:30 UTC · Nov 26, 2019Exploit / PoC in the wild60
Russia's GRU propped up fake media personas, mostly failed at social media promotion after DNC hackCyberScoop·Nov 13, 15:26 UTC · Nov 13, 2019Exploit / PoC in the wild60
eIDAS flaws allowed attackers to impersonate any EU citizen or businessSecurity Affairs·Oct 31, 07:57 UTC · Oct 31, 2019Exploit / PoC60