Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13The Hacker News·Mar 26, 10:55 UTC · Mar 26, 2026Exploit / PoC in the wildCVE-2024-23222CVE-2022-48503CVE-2023-43000+9 CVEs60
Coruna framework: an exploit kit and ties to Operation TriangulationKaspersky Securelist·Mar 26, 08:00 UTC · Mar 26, 2026Exploit / PoCCVE-2023-32434CVE-2023-3860660
2025 Talos Year in Review: Speed, scale, and staying powerCisco Talos·Mar 23, 12:01 UTC · Mar 23, 2026Exploit / PoC in the wild60
DarkSword: Researchers uncover another iOS exploit kitHelp Net Security·Mar 19, 00:00 UTC · Mar 19, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-43510CVE-2025-43520+3 CVEs160
Google uncovers Coruna iOS Exploit Kit targeting iOS 13Security Affairs·Mar 5, 09:03 UTC · Mar 5, 2026Exploit / PoCCVE-2021-30952CVE-2022-48503CVE-2023-43000+9 CVEs60
Russia-linked APT28 exploited MSHTML zero-day CVE-2026Security Affairs·Mar 2, 14:46 UTC · Mar 2, 2026Exploit / PoCCVE-2026-2151360
How 'silent probing' can make your security playbook a liabilityCyberScoop·Mar 2, 11:00 UTC · Mar 2, 2026Exploit / PoC in the wild60
ClawJacked flaw exposed OpenClaw users to data theftSecurity Affairs·Mar 2, 09:42 UTC · Mar 2, 2026Exploit / PoC60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact DataThe Hacker News·Feb 12, 05:21 UTC · Feb 12, 2026Exploit / PoCCVE-2026-1281CVE-2026-134060
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active AttacksThe Hacker News·Jan 13, 07:05 UTC · Jan 13, 2026Exploit / PoC in the wildCVE-2025-8110CVE-2024-5594760
‘Elon Musk is playing with fire:’ All the legal risks that apply to Grok’s deepfake disasterCyberScoop·Jan 8, 18:51 UTC · Jan 8, 2026Exploit / PoC in the wild60
Why cybersecurity cannot hire its way through the AI eraCyberScoop·Jan 7, 12:00 UTC · Jan 7, 2026Exploit / PoC in the wild60
How to determine if agentic AI browsers are safe enough for your enterpriseCyberScoop·Dec 23, 12:00 UTC · Dec 23, 2025Exploit / PoC in the wild60
Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 releasedHelp Net Security·Dec 21, 00:00 UTC · Dec 21, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-40602CVE-2025-14174+1 CVEs160
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web ManagerSecurity Affairs·Dec 19, 08:53 UTC · Dec 19, 2025Exploit / PoC in the wildCVE-2025-2039360
U.S. CISA adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 15, 19:00 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-43529CVE-2025-14611CVE-2025-1417460
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
More evidence your AI agents can be turned against youCyberScoop·Dec 5, 20:48 UTC · Dec 5, 2025Exploit / PoC in the wild60
Chinese hackers exploiting React2Shell bug impacting countless websites, Amazon researchers sayThe Record·Dec 5, 16:22 UTC · Dec 5, 2025Exploit / PoC in the wildCVE-2025-5518260
Spy vs. spy: How GenAI is powering defenders and attackersCisco Talos·Dec 4, 11:00 UTC · Dec 4, 2025Exploit / PoC60
When trust turns toxic: Lessons from the Salesloft Drift incidentCyberScoop·Nov 24, 11:00 UTC · Nov 24, 2025Exploit / PoC in the wild60
The realities of CISO burnout and exhaustionCyberScoop·Nov 18, 11:00 UTC · Nov 18, 2025Exploit / PoC60
Week in review: Windows kernel flaw patched, suspected Fortinet FortiWeb zero-day exploitedHelp Net Security·Nov 16, 00:00 UTC · Nov 16, 2025Exploit / PoC in the wildCVE-2025-12480CVE-2025-21042CVE-2025-62215+2 CVEs60
Samsung Mobile Flaw Exploited as ZeroThe Hacker News·Nov 11, 11:21 UTC · Nov 11, 2025Exploit / PoC in the wildCVE-2025-21042CVE-2025-21043CVE-2025-55177+1 CVEs60
Week in review: WSUS vulnerability exploited to drop Skuld infostealer, PoC for BIND 9 DNS flaw publishedHelp Net Security·Nov 2, 00:00 UTC · Nov 2, 2025Exploit / PoCCVE-2025-2783CVE-2025-40778CVE-2025-59287+1 CVEs160
Diplomatic entities in Belgium and Hungary hacked in ChinaThe Record·Oct 30, 18:17 UTC · Oct 30, 2025Exploit / PoC60
Reducing abuse of Microsoft 365 Exchange Online’s Direct SendCisco Talos·Oct 21, 10:00 UTC · Oct 21, 2025Exploit / PoC60
Top 10 Takeaways from Predict 2025: Turning Intelligence Into ActionRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025Exploit / PoC in the wild60
Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS FilesThe Hacker News·Oct 10, 06:52 UTC · Oct 10, 2025Exploit / PoC in the wildCVE-2025-2791560
U.S. CISA adds Synacor Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 21:39 UTC · Oct 7, 2025Exploit / PoC in the wildCVE-2025-2791560
Zimbra users targeted in zeroSecurity Affairs·Oct 7, 21:32 UTC · Oct 7, 2025Exploit / PoCCVE-2025-2791560
F5 to acquire AI security firm CalypsoAI for $180 millionCyberScoop·Sep 11, 17:55 UTC · Sep 11, 2025Exploit / PoC in the wild60
Critical infrastructure security tech needs to be as good as our smartphones, top NSC cyber official saysCyberScoop·Sep 9, 22:19 UTC · Sep 9, 2025Exploit / PoC in the wild60
MeetC2 - A serverless C2 framework that leverages Google Calendar APIs as a communication channelSecurity Affairs·Sep 6, 09:39 UTC · Sep 6, 2025Exploit / PoC45
NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs·Aug 28, 10:48 UTC · Aug 28, 2025Exploit / PoCCVE-2024-21887CVE-2023-46805CVE-2024-3400+3 CVEs160
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860