CISA adds bugs in Android and Novi Survey to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 18, 13:36 UTC · Apr 18, 2023Exploit / PoC in the wildCVE-2023-20963CVE-2023-2949260
CISA adds bugs in Chrome and macOS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 18, 13:30 UTC · Apr 18, 2023Exploit / PoC in the wildCVE-2019-8526CVE-2023-203360
Google fixed the first Chrome zeroSecurity Affairs·Apr 14, 19:50 UTC · Apr 14, 2023Exploit / PoC in the wildCVE-2023-203360
Apple released emergency updates to fix recently disclosed zeroSecurity Affairs·Apr 11, 10:37 UTC · Apr 11, 2023Exploit / PoC in the wildCVE-2023-28205CVE-2023-28206160
CISA adds zero-day bugs in iPhones, Macs, and iPads to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 11, 10:22 UTC · Apr 11, 2023Exploit / PoC in the wildCVE-2023-28205CVE-2023-2820660
Researchers disclose sandbox escape bug in vm2 sandbox librarySecurity Affairs·Apr 9, 20:34 UTC · Apr 9, 2023Exploit / PoCCVE-2023-29017CVE-2022-3606760
CISA adds Veritas Backup Exec flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 8, 22:16 UTC · Apr 8, 2023Exploit / PoC in the wildCVE-2021-27876CVE-2021-27877CVE-2021-27878+2 CVEs60
CISA adds Zimbra bug exploited in attacks against NATO countries to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 8, 22:11 UTC · Apr 8, 2023Exploit / PoC in the wildCVE-2022-2792660
Apple addressed two actively exploited zeroSecurity Affairs·Apr 7, 20:42 UTC · Apr 7, 2023Exploit / PoC in the wildCVE-2023-28205CVE-2023-28206CVE-2023-2352960
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
CISA adds bugs exploited by commercial surveillance spyware to Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 1, 18:06 UTC · Apr 1, 2023Exploit / PoC in the wildCVE-2021-30900CVE-2022-38181CVE-2023-0266+6 CVEs60
Hackers are actively exploiting a flaw in Elementor Pro WordPress pluginSecurity Affairs·Mar 31, 20:36 UTC · Mar 31, 2023Exploit / PoC in the wild60
Election workers in battleground states faced onslaught of malicious emails, researchers sayCyberScoop·Oct 12, 14:00 UTC · Oct 12, 2022Exploit / PoC in the wild60
Post-Roe reproductive privacy goes beyond period trackers, experts sayCyberScoop·Jul 1, 20:00 UTC · Jul 1, 2022Exploit / PoC in the wild60
CISA orders federal agencies to fix VMware flaws by May 23, 2022Security Affairs·May 19, 06:13 UTC · May 19, 2022Exploit / PoCCVE-2022-22972CVE-2022-22973CVE-2022-22954+1 CVEs60
VMware fixed a critical auth bypass issue in some of its productsSecurity Affairs·May 18, 21:29 UTC · May 18, 2022Exploit / PoC in the wildCVE-2022-22972CVE-2022-2297360
CISA adds Zyxel Firewalls flaw to Known Exploited Vulnerabilities CatalogSecurity Affairs·May 17, 07:11 UTC · May 17, 2022Exploit / PoC in the wildCVE-2022-30525CVE-2022-2294760
Zyxel fixed firewall unauthenticated remote command injection issueSecurity Affairs·May 17, 06:47 UTC · May 17, 2022Exploit / PoCCVE-2022-30525CVE-2022-26413CVE-2022-26414+1 CVEs60
Apple fixes the sixth zeroSecurity Affairs·May 16, 20:27 UTC · May 16, 2022Exploit / PoC in the wildCVE-2022-22675CVE-2022-22587CVE-2022-22594+2 CVEs60
CISA adds CVE-2022-1388 in F5 BIG-IP to Known Exploited Vulnerabilities CatalogSecurity Affairs·May 11, 21:45 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-138860
Google addresses actively exploited Android flaw in the kernelSecurity Affairs·May 5, 19:47 UTC · May 5, 2022Exploit / PoC in the wildCVE-2021-2260060
CISA adds new flaws to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 26, 11:41 UTC · Apr 26, 2022Exploit / PoC in the wild60
Pwn2Own Miami hacking contest awarded 400K for 26 unique ICS exploitsSecurity Affairs·Apr 22, 08:21 UTC · Apr 22, 2022Exploit / PoC60
Critical bug in popular chipsets exposes 2/3 of Android devices to hackSecurity Affairs·Apr 21, 20:17 UTC · Apr 21, 2022Exploit / PoCCVE-2021-0674CVE-2021-0675CVE-2021-3035160
CISA adds Win Print Spooler to Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 20, 09:42 UTC · Apr 20, 2022Exploit / PoC in the wildCVE-2022-2271860
VMware, Chrome flaws added to Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 18, 08:13 UTC · Apr 18, 2022Exploit / PoC in the wildCVE-2022-22960CVE-2022-1364CVE-2022-2452160
Google fixed third zeroSecurity Affairs·Apr 15, 10:25 UTC · Apr 15, 2022Exploit / PoC in the wildCVE-2022-1364CVE-2022-1096CVE-2022-060960
CISA adds Windows CLFS Driver Privilege Escalation flaw to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 14, 14:14 UTC · Apr 14, 2022Exploit / PoC in the wildCVE-2022-24521160
VMware Workspace ONE Access CVE-2022Security Affairs·Apr 14, 10:42 UTC · Apr 14, 2022Exploit / PoC in the wildCVE-2022-2295460
EU officials were targeted with Israeli surveillance softwareSecurity Affairs·Apr 13, 07:05 UTC · Apr 13, 2022Exploit / PoC60
NGINX project maintainers fix flaws in LDAP Reference ImplementationSecurity Affairs·Apr 12, 11:25 UTC · Apr 12, 2022Exploit / PoC60
CISA adds WatchGuard flaw to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 12, 08:36 UTC · Apr 12, 2022Exploit / PoC in the wildCVE-2022-23176CVE-2021-42287CVE-2021-42278+5 CVEs60
VMware released updates to fix Spring4Shell bug in multiple productsSecurity Affairs·Apr 5, 14:15 UTC · Apr 5, 2022Exploit / PoCCVE-2022-2296560
CISA adds Spring4Shell flaw to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 5, 14:15 UTC · Apr 5, 2022Exploit / PoC in the wildCVE-2022-22965CVE-2022-22675CVE-2022-22674+1 CVEs160
Facebook files suit against Ukrainian man who allegedly scraped data about 178 million usersCyberScoop·Oct 22, 20:06 UTC · Oct 22, 2021Exploit / PoC in the wild60
Misinformation flooded Parler around Capitol insurrection, research findsCyberScoop·Feb 18, 19:18 UTC · Feb 18, 2021Exploit / PoC in the wild60
White House must act now to boost trust in elections, experts sayCyberScoop·Feb 2, 15:09 UTC · Feb 2, 2021Exploit / PoC in the wild60
Matt Masterson, CISA’s top election security official, to step downCyberScoop·Dec 10, 23:39 UTC · Dec 10, 2020Exploit / PoC in the wild60
Postal Service left vulnerable IT applications unaddressed for years, inspector general findsCyberScoop·Sep 11, 17:54 UTC · Sep 11, 2020Exploit / PoC in the wild60
Is Emotet gang targeting companies with external SOC?Security Affairs·Oct 14, 17:49 UTC · Oct 14, 2019Exploit / PoC60