Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack SupportThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoCCVE-2025-808850
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure EntitiesThe Hacker News·Feb 7, 11:03 UTC · Feb 7, 2026Exploit / PoC60
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
‘Stranger Things’ emerge when OT security is stuck in the pastCyberScoop·Nov 26, 12:00 UTC · Nov 26, 2025Exploit / PoC in the wild60
Amazon warns of global rise in specialized cyberCyberScoop·Nov 19, 18:23 UTC · Nov 19, 2025Exploit / PoC in the wild60
Trick, treat, repeatCisco Talos·Oct 30, 18:00 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-5928760
New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without PermissionsThe Hacker News·Oct 20, 18:54 UTC · Oct 20, 2025Exploit / PoC in the wildCVE-2025-4856160
From summer camp to grind seasonCisco Talos·Sep 4, 18:02 UTC · Sep 4, 2025Exploit / PoCCVE-2025-5517760
New Sni5Gect Attack Crashes Phones and Downgrades 5G to 4G without Rogue Base StationThe Hacker News·Aug 26, 17:23 UTC · Aug 26, 2025Exploit / PoC45
Microsoft uncovers macOS flaw allowing bypass TCC protectionsSecurity Affairs·Jul 29, 00:01 UTC · Jul 29, 2025Exploit / PoCCVE-2025-31199CVE-2024-44133150
Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh serversHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-24016CVE-2025-43200+1 CVEs60
Unverified code is the next national security threatCyberScoop·Jun 9, 15:56 UTC · Jun 9, 2025Exploit / PoC in the wild60
Week in review: MITRE ATT&CK v17.0 released, PoC for Erlang/OTP SSH bug is publicHelp Net Security·Apr 27, 00:00 UTC · Apr 27, 2025Exploit / PoCCVE-2025-32433CVE-2025-34028CVE-2025-2761060
Apple backported fixes for three actively exploited flaws to older devicesSecurity Affairs·Apr 2, 08:52 UTC · Apr 2, 2025Exploit / PoC in the wildCVE-2025-24085CVE-2025-24200CVE-2025-2420160
Week in review: Botnet hits M365 accounts, PoC for Ivanti Endpoint Manager vulnerabilities releasedHelp Net Security·Mar 2, 00:00 UTC · Mar 2, 2025Exploit / PoCCVE-2024-13159CVE-2025-2336360
CISA’s AI cybersecurity playbook calls for greater collaboration, but trust is key to successful executionCyberScoop·Feb 26, 12:00 UTC · Feb 26, 2025Exploit / PoC in the wild60
Apple fixes iPhone and iPad bug actively exploited in ‘extremely sophisticated attacks’Security Affairs·Feb 10, 23:53 UTC · Feb 10, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2023-41064CVE-2023-41061+1 CVEs60
U.S. CISA adds Apple products' flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 29, 20:39 UTC · Jan 29, 2025Exploit / PoC in the wildCVE-2025-2408560
Apple fixed the first actively exploited zeroSecurity Affairs·Jan 27, 23:28 UTC · Jan 27, 2025Exploit / PoC in the wildCVE-2025-2408560
The Mask APT is back after 10 years of silenceSecurity Affairs·Dec 18, 08:20 UTC · Dec 18, 2024Exploit / PoC60
The Mask APT Resurfaces with Sophisticated MultiThe Hacker News·Dec 18, 04:08 UTC · Dec 18, 2024Exploit / PoCCVE-2012-0773160
An opportunity for Trump’s deregulation journey: Cybersecurity harmonizationCyberScoop·Nov 25, 14:06 UTC · Nov 25, 2024Exploit / PoC in the wild60
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs260
Google Warns of Actively Exploited CVE-2024The Hacker News·Nov 8, 04:09 UTC · Nov 8, 2024Exploit / PoC in the wildCVE-2024-43093CVE-2024-43047CVE-2024-3289660
U.S. CISA adds Palo Alto Expedition, Android, CyberPanel and Nostromo nhttpd bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 7, 22:49 UTC · Nov 7, 2024Exploit / PoC in the wildCVE-2024-43093CVE-2024-51567CVE-2019-16278+2 CVEs60
Authlete 3.0 empowers organizations to improve how they issue and manage user credentialsHelp Net Security·Nov 6, 00:00 UTC · Nov 6, 2024Exploit / PoC45
Android flaw may be under limited, targeted exploitationSecurity Affairs·Nov 5, 08:51 UTC · Nov 5, 2024Exploit / PoC in the wildCVE-2024-43093CVE-2024-43047CVE-2024-3289660
Google’s AI Tool Big Sleep Finds Zero-Day Vulnerability in SQLite Database EngineThe Hacker News·Nov 4, 10:04 UTC · Nov 4, 2024Exploit / PoC60
Invisible text that AI chatbots understand and humans can’t? Yep, it’s a thing.Ars Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2024Exploit / PoC145
Cybersecurity Researchers Warn of New Rust-Based Splinter PostThe Hacker News·Sep 25, 12:38 UTC · Sep 25, 2024Exploit / PoC145
Here’s what corporate boards are asking Kevin Mandia aboutCyberScoop·Sep 20, 15:02 UTC · Sep 20, 2024Exploit / PoC in the wild60
The best and worst ways to get users to improve their account securityCisco Talos·Sep 5, 18:00 UTC · Sep 5, 2024Exploit / PoCCVE-2024-797160
Google warns of an actively exploited Android kernel flawSecurity Affairs·Sep 4, 20:39 UTC · Sep 4, 2024Exploit / PoC in the wildCVE-2024-36971CVE-2024-3289660
Zero-Day Exploit Detection Using Machine LearningPalo Alto Unit 42·Jun 5, 17:53 UTC · Jun 5, 2024Exploit / PoCCVE-2022-26134CVE-2022-31446160
Resilience isn't enough, NATO must be 'proactive' for cyberdefense, warns officialThe Record·Jun 3, 12:01 UTC · Jun 3, 2024Exploit / PoC60
New Research Exposes Security Risks in ChatGPT PluginsInfosecurity Magazine·Mar 13, 13:00 UTC · Mar 13, 2024Exploit / PoC60
Week in review: AnyDesk phishing campaign targets employees, Microsoft fixes exploited zero-daysHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23313CVE-2023-43770+5 CVEs160
Zimbra zero-day exploited to steal government emails by 4 groupsSecurity Affairs·Nov 16, 20:49 UTC · Nov 16, 2023Exploit / PoCCVE-2023-3758060