Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug FlagThe Hacker News·Jun 3, 14:56 UTC · Jun 3, 2026Exploit / PoCCVE-2026-41100CVE-2026-41101CVE-2026-41102+1 CVEs150
Zero trust physical security needs trust decisions at the edgeHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Exploit / PoC60
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AICyberScoop·May 8, 13:14 UTC · May 8, 2026Exploit / PoC in the wild60
NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forwardHelp Net Security·Apr 16, 00:00 UTC · Apr 16, 2026Exploit / PoC in the wild60
New Rowhammer attacks give complete control of machines running Nvidia GPUsArs Technica · Security·Apr 2, 17:00 UTC · Apr 2, 2026Exploit / PoC45
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security·Mar 29, 00:00 UTC · Mar 29, 2026Exploit / PoC in the wildCVE-2025-53521CVE-2026-21992CVE-2026-305560
Ubiquiti defect poses account takeover risk for UniFi Networking Application usersCyberScoop·Mar 20, 16:22 UTC · Mar 20, 2026Exploit / PoC in the wildCVE-2026-22557CVE-2026-2255860
DOJ seizes piracy sites, Italian police dismantle illegal IPTV operationCyberScoop·Jan 30, 18:29 UTC · Jan 30, 2026Exploit / PoC in the wild60
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 28, 19:26 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-2485860
Industry, government, nonprofits weigh voluntary rules for commercial hacking toolsCyberScoop·Jan 26, 14:11 UTC · Jan 26, 2026Exploit / PoC in the wild60
CrowdStrike is buying Seraphic Security to lock down the browser, where work actually happensCyberScoop·Jan 13, 15:25 UTC · Jan 13, 2026Exploit / PoC in the wild60
How to determine if agentic AI browsers are safe enough for your enterpriseCyberScoop·Dec 23, 12:00 UTC · Dec 23, 2025Exploit / PoC in the wild60
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 17, 08:17 UTC · Dec 17, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-5971960
Fortinet fixed two critical authenticationSecurity Affairs·Dec 10, 22:04 UTC · Dec 10, 2025Exploit / PoCCVE-2025-59718CVE-2025-5971960
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
Too many Cisco ASA firewalls still unsecure despite zero-day attack alertsHelp Net Security·Nov 13, 12:09 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20333CVE-2025-20362CVE-2025-2035260
Microsoft Uncovers 'Whisper Leak' Attack That Identifies AI Chat Topics in Encrypted TrafficThe Hacker News·Nov 10, 08:00 UTC · Nov 10, 2025Exploit / PoC60
Trump administration planning expansion of U.S. quantum strategyCyberScoop·Sep 19, 15:42 UTC · Sep 19, 2025Exploit / PoC in the wild60
Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585)Help Net Security·Sep 18, 00:00 UTC · Sep 18, 2025Exploit / PoC in the wildCVE-2025-10585CVE-2025-655460
Default Cursor setting can be exploited to run malicious code on developers' machinesHelp Net Security·Sep 11, 00:00 UTC · Sep 11, 2025Exploit / PoC145
Automating Threat Intelligence Actions With Splunk SOAR PlaybooksRecorded Future·Sep 8, 00:00 UTC · Sep 8, 2025Exploit / PoC60
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter EnvironmentsThe Hacker News·Jul 29, 04:24 UTC · Jul 29, 2025Exploit / PoCCVE-2023-34048CVE-2023-20867CVE-2022-138860
Experts uncover critical flaws in Kigen eSIM affecting billionsSecurity Affairs·Jul 14, 11:09 UTC · Jul 14, 2025Exploit / PoC60
NightEagle APT Exploits Microsoft Exchange Flaw to Target China's Military and Tech SectorsThe Hacker News·Jul 10, 04:17 UTC · Jul 10, 2025Exploit / PoC60
Experts published a detailed analysis of Cisco IOS XE WLC flaw CVE-2025Security Affairs·Jun 2, 06:58 UTC · Jun 2, 2025Exploit / PoC in the wildCVE-2025-2018860
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
U.S. CISA adds Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 14, 20:36 UTC · May 14, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+2 CVEs60
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
CISA reverses course, extends MITRE CVE contractCyberScoop·Apr 16, 14:52 UTC · Apr 16, 2025Exploit / PoC in the wild60
Critical flaws fixed in Nagios Log ServerHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2025Exploit / PoCCVE-2025-2947160
Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085)Help Net Security·Apr 1, 09:15 UTC · Apr 1, 2025Exploit / PoC in the wildCVE-2025-2408560
What’s in Your Head? A Plastic Spoon and Lost Baby Memories404 Media·Mar 22, 13:00 UTC · Mar 22, 2025Exploit / PoC45
10 Critical Network Pentest Findings IT Teams OverlookThe Hacker News·Mar 21, 11:01 UTC · Mar 21, 2025Exploit / PoCCVE-2019-070860
Why Most Microsegmentation Projects Fail—And How Andelyn Biosciences Got It RightThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Exploit / PoC60
China Accuses NSA's TAO Unit of Hacking its Military Research UniversityThe Hacker News·Mar 3, 09:33 UTC · Mar 3, 2025Exploit / PoC60
Serbian student activist’s phone hacked using Cellebrite zero-day exploitSecurity Affairs·Mar 3, 09:08 UTC · Mar 3, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-5030260