⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Attackers abuse SolarWinds Web Help Desk to install Zoho agents and VelociraptorSecurity Affairs·Feb 9, 12:28 UTC · Feb 9, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-26399CVE-2025-4053660
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
What security teams can learn from torrent metadataHelp Net Security·Jan 12, 00:00 UTC · Jan 12, 2026Exploit / PoC45
China-Linked UAT-7290 Targets Telecom Networks In South AsiaInfosecurity Magazine·Jan 8, 16:00 UTC · Jan 8, 2026Exploit / PoC60
ServiceNow agrees to buy cyber firm Armis for $7.75BCyberScoop·Dec 23, 14:44 UTC · Dec 23, 2025Exploit / PoC in the wild60
What cybersecurity leaders are reading to stay aheadHelp Net Security·Dec 18, 00:00 UTC · Dec 18, 2025Exploit / PoC57
How to Streamline Zero Trust Using the Shared Signals FrameworkThe Hacker News·Dec 9, 11:30 UTC · Dec 9, 2025Exploit / PoC60
Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSSThe Record·Dec 8, 16:31 UTC · Dec 8, 2025Exploit / PoC in the wildCVE-2025-5518260
Operational Cyber Threat IntelligenceRecorded Future·Nov 19, 00:00 UTC · Nov 19, 2025Exploit / PoC in the wild60
Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This YearThe Hacker News·Nov 18, 18:08 UTC · Nov 18, 2025Exploit / PoC in the wildCVE-2025-5948960
Strix: Open-source AI agents for penetration testingHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2025Exploit / PoC45
China-linked UNC6384 exploits Windows zeroSecurity Affairs·Nov 1, 14:11 UTC · Nov 1, 2025Exploit / PoC60
PoC code drops for remotely exploitable BIND 9 DNS flaw (CVE-2025-40778)Help Net Security·Oct 28, 00:00 UTC · Oct 28, 2025Exploit / PoCCVE-2025-4077860
Mem3nt0 moriKaspersky Securelist·Oct 27, 03:00 UTC · Oct 27, 2025Exploit / PoC in the wildCVE-2025-278360
New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without PermissionsThe Hacker News·Oct 20, 18:54 UTC · Oct 20, 2025Exploit / PoC in the wildCVE-2025-4856160
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Dutch Authorities Arrest Teens in Foreign Interference CaseInfosecurity Magazine·Sep 29, 17:00 UTC · Sep 29, 2025Exploit / PoC60
How security teams are putting AI to work right nowHelp Net Security·Aug 18, 00:00 UTC · Aug 18, 2025Exploit / PoC45
Iranian hackers were more coordinated, aligned during Israel conflict than it seemedCyberScoop·Aug 5, 17:39 UTC · Aug 5, 2025Exploit / PoC in the wild60
Critical Golden dMSA Attack in Windows Server 2025 Enables CrossThe Hacker News·Jul 21, 06:31 UTC · Jul 21, 2025Exploit / PoC60
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 20, 13:38 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-2525760
Nvidia chips become the first GPUs to fall to Rowhammer bitArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2025Exploit / PoC45
NightEagle APT Exploits Microsoft Exchange Flaw to Target China's Military and Tech SectorsThe Hacker News·Jul 10, 04:17 UTC · Jul 10, 2025Exploit / PoC60
Threat Intelligence Tweaks That’ll Take Your Security to the Next LevelRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC45
U.S. CISA adds Linux Kernel flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 18, 11:55 UTC · Jun 18, 2025Exploit / PoC in the wildCVE-2023-038660
#Infosec2025: Startups Focus on Visibility and Governance, not AIInfosecurity Magazine·Jun 4, 09:30 UTC · Jun 4, 2025Exploit / PoC57
Using an agent for the Mythic framework: pros and cons in pentestingKaspersky Securelist·May 13, 10:00 UTC · May 13, 2025Exploit / PoC60
SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance ModelsThe Hacker News·May 5, 15:51 UTC · May 5, 2025Exploit / PoC in the wildCVE-2023-44221CVE-2024-38475CVE-2021-2003560
U.S. CISA adds SonicWall SMA100 and Apache HTTP Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 2, 07:50 UTC · May 2, 2025Exploit / PoC in the wildCVE-2024-38475CVE-2023-4422160
Quantum computer threat spurring quiet overhaul of internet securityCyberScoop·May 1, 20:51 UTC · May 1, 2025Exploit / PoC in the wild60
Two SonicWall SMA100 flaws actively exploited in the wildSecurity Affairs·May 1, 08:31 UTC · May 1, 2025Exploit / PoC in the wildCVE-2023-44221CVE-2024-3847560
Dutch Warn of “Whole of Society” Russian CyberInfosecurity Magazine·Apr 23, 09:45 UTC · Apr 23, 2025Exploit / PoC60
Focus on what matters most: Exposure management and your attack surfaceHelp Net Security·Apr 8, 17:17 UTC · Apr 8, 2025Exploit / PoCCVE-2024-340060
Google hopes its experimental AI model can unearth new security use casesCyberScoop·Apr 8, 01:07 UTC · Apr 8, 2025Exploit / PoC in the wild60
Google fixed the first actively exploited Chrome zeroSecurity Affairs·Mar 26, 12:33 UTC · Mar 26, 2025Exploit / PoC in the wildCVE-2025-2783CVE-2024-1048760
WhatsApp fixed zero-day used to deploy Paragon Graphite spywareSecurity Affairs·Mar 20, 00:12 UTC · Mar 20, 2025Exploit / PoC60
Why Most Microsegmentation Projects Fail—And How Andelyn Biosciences Got It RightThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Exploit / PoC60
Here’s what Google is (and isn’t) planning with SMS account verificationCyberScoop·Feb 27, 21:28 UTC · Feb 27, 2025Exploit / PoC in the wild60