Lumu Playback strengthens threat detectionHelp Net Security·Feb 20, 00:00 UTC · Feb 20, 2025Exploit / PoC60
U.S. CISA adds Apple iOS and iPadOS and Mitel SIP Phones flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 15, 17:37 UTC · Feb 15, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2024-4171060
Apple Patches Actively Exploited iOS Zero-Day CVE-2025The Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2025-2408560
Apple fixes security flaw allowing thirdThe Record·Feb 11, 19:43 UTC · Feb 11, 2025Exploit / PoC in the wildCVE-2025-2420060
Apple fixes iPhone and iPad bug actively exploited in ‘extremely sophisticated attacks’Security Affairs·Feb 10, 23:53 UTC · Feb 10, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2023-41064CVE-2023-41061+1 CVEs60
Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)Help Net Security·Jan 9, 00:00 UTC · Jan 9, 2025Exploit / PoCCVE-2025-028260
Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282)Help Net Security·Jan 8, 00:00 UTC · Jan 8, 2025Exploit / PoCCVE-2025-0282CVE-2025-028360
Treasury workstations hacked by ChinaCyberScoop·Dec 31, 01:29 UTC · Dec 31, 2024Exploit / PoC in the wild60
Chinese Hackers Exploit Visual Studio Code in Southeast Asian CyberattacksThe Hacker News·Dec 10, 09:03 UTC · Dec 10, 2024Exploit / PoCCVE-2024-2491960
Trustwave and Cybereason announce mergerCyberScoop·Nov 12, 20:42 UTC · Nov 12, 2024Exploit / PoC in the wild60
Fortinet Confirms Exploitation of Critical FortiManager ZeroInfosecurity Magazine·Oct 24, 11:45 UTC · Oct 24, 2024Exploit / PoC in the wildCVE-2024-47575CVE-2024-2311360
Samsung zeroSecurity Affairs·Oct 22, 15:42 UTC · Oct 22, 2024Exploit / PoC in the wildCVE-2024-4406860
Google Patches New Android Kernel Vulnerability Exploited in the WildThe Hacker News·Aug 10, 07:15 UTC · Aug 10, 2024Exploit / PoC in the wildCVE-2024-36971CVE-2024-32896CVE-2024-29745+2 CVEs60
Chinese Hackers Exploiting Cisco Switches ZeroThe Hacker News·Jul 2, 15:34 UTC · Jul 2, 2024Exploit / PoC in the wildCVE-2024-20399CVE-2024-076960
Google Warns of Pixel Firmware Security Flaw Exploited as ZeroThe Hacker News·Jun 28, 04:04 UTC · Jun 28, 2024Exploit / PoC in the wildCVE-2024-32896CVE-2024-29745CVE-2024-29748+1 CVEs60
Palo Alto firewalls: Public exploits, rising attacks, ineffective mitigationHelp Net Security·Apr 30, 13:31 UTC · Apr 30, 2024Exploit / PoCCVE-2024-340060
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 20:17 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2024-20353CVE-2024-20359CVE-2024-4040+1 CVEs60
Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networksSecurity Affairs·Apr 24, 20:31 UTC · Apr 24, 2024Exploit / PoCCVE-2024-20353CVE-2024-20359CVE-2018-0101160
Securing Perimeter Products Must Be a Priority, Says NCSCInfosecurity Magazine·Mar 4, 10:15 UTC · Mar 4, 2024Exploit / PoC in the wild60
Week in review: 10 cybersecurity frameworks you need to know, exploited Chrome zero-day fixedHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2024Exploit / PoC in the wildCVE-2023-36025CVE-2023-22527CVE-2024-0519+3 CVEs60
Experts warn of mass exploitation of Ivanti Connect Secure VPN flawsSecurity Affairs·Jan 16, 10:40 UTC · Jan 16, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760
Two zero-day bugs in Ivanti Connect Secure actively exploitedSecurity Affairs·Jan 11, 15:03 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760
New PoC Exploit for Apache ActiveMQ Flaw Could Let Attackers Fly Under the RadarThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2023Exploit / PoC in the wildCVE-2023-4660460
Alert: PoC Exploits Released for Citrix and VMware VulnerabilitiesThe Hacker News·Nov 2, 12:20 UTC · Nov 2, 2023Exploit / PoC in the wildCVE-2023-34051CVE-2023-4966CVE-2023-35182+2 CVEs60
iOS Zero-Day Attacks: Experts Uncover Deeper Insights into Operation TriangulationThe Hacker News·Oct 30, 03:14 UTC · Oct 30, 2023Exploit / PoC in the wildCVE-2023-32434CVE-2023-3243560
Chinese Hacker Steals Microsoft Signing Key, Spies on US GovernmentInfosecurity Magazine·Sep 7, 13:00 UTC · Sep 7, 2023Exploit / PoC60
Experts released PoC exploit for Ivanti Sentry CVE-2023Security Affairs·Aug 27, 15:03 UTC · Aug 27, 2023Exploit / PoC in the wildCVE-2023-3803560
Ivanti Sentry zero-day vulnerability exploited, patch ASAP! (CVE-2023-38035)Help Net Security·Aug 24, 12:34 UTC · Aug 24, 2023Exploit / PoC in the wildCVE-2023-3803560
Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD TokensThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Exploit / PoC in the wild160
Chinese Hackers Using Never-Before-Seen Tactics for Critical Infrastructure AttacksThe Hacker News·Jun 27, 05:21 UTC · Jun 27, 2023Exploit / PoCCVE-2021-4053960
20 cybersecurity projects on GitHub you should check outHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2023Exploit / PoC45
KeePass flaw allows retrieval of master password, PoC is public (CVE-2023-32784)Help Net Security·Jun 5, 18:33 UTC · Jun 5, 2023Exploit / PoCCVE-2023-3278450
Week in review: MOVEit Transfer critical zero-day vulnerability, Kali Linux 2023.2 releasedHelp Net Security·Jun 4, 00:00 UTC · Jun 4, 2023Exploit / PoC in the wildCVE-2023-28771CVE-2023-2868CVE-2023-2798860
KeePass 2.X Master Password Dumper allows retrieving the KeePass master passwordSecurity Affairs·May 18, 20:17 UTC · May 18, 2023Exploit / PoCCVE-2023-3278450
Aqua Security strengthens software supply chain security with pipeline integrity scanningHelp Net Security·May 10, 00:00 UTC · May 10, 2023Exploit / PoC60
ExtraHop simplifies approach to intrusion detection for security teams with new solutionsHelp Net Security·Apr 26, 00:00 UTC · Apr 26, 2023Exploit / PoC60
GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud PlatformThe Hacker News·Apr 22, 05:34 UTC · Apr 22, 2023Exploit / PoC60
Homeland Security chief Mayorkas announces 90CyberScoop·Apr 21, 16:20 UTC · Apr 21, 2023Exploit / PoC in the wild60
China-linked APT likely linked to Fortinet zeroSecurity Affairs·Mar 17, 19:35 UTC · Mar 17, 2023Exploit / PoCCVE-2022-4132860