CISA alerts federal agencies of widespread attacks using Cisco zeroCyberScoop·Sep 25, 19:05 UTC · Sep 25, 2025Exploit / PoC in the wildCVE-2025-20333CVE-2025-20363CVE-2025-2036260
Contain or be contained: The security imperative of controlling autonomous AICyberScoop·Sep 25, 13:30 UTC · Sep 25, 2025Exploit / PoC in the wild60
Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI ModelsThe Hacker News·Sep 24, 13:55 UTC · Sep 24, 2025Exploit / PoCCVE-2025-10643CVE-2025-10644160
Libraesva ESG zero-day vulnerability exploited by attackers (CVE-2025-59689)Help Net Security·Sep 24, 00:00 UTC · Sep 24, 2025Exploit / PoCCVE-2025-5968960
How a fake ICS network can reveal real cyberattacksHelp Net Security·Sep 17, 00:00 UTC · Sep 17, 2025Exploit / PoC60
Check Point acquires AI security firm Lakera in push for enterprise AI protectionCyberScoop·Sep 16, 17:23 UTC · Sep 16, 2025Exploit / PoC in the wild60
The npm incident frightened everyone, but ended up being nothing to fret aboutCyberScoop·Sep 10, 14:35 UTC · Sep 10, 2025Exploit / PoC in the wild60
Experts warn of actively exploited FreePBX zeroSecurity Affairs·Aug 29, 13:20 UTC · Aug 29, 2025Exploit / PoC in the wildCVE-2025-5781960
WinRAR Zero-Day Under Active ExploitationThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Exploit / PoC in the wildCVE-2025-8088CVE-2023-38831CVE-2025-6218+2 CVEs60
PoC exploit for critical Erlang/OTP SSH bug is public (CVE-2025-32433)Help Net Security·Aug 14, 09:20 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2025-3243360
NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI ServersThe Hacker News·Aug 6, 09:08 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2025-23319CVE-2025-23320CVE-2025-23334+3 CVEs60
Cursor’s AI coding agent morphed ‘into local shell’ with oneCyberScoop·Aug 1, 19:51 UTC · Aug 1, 2025Exploit / PoC in the wildCVE-2025-5413560
CISA says it will release telecom security report sought by Sen. Wyden to lift hold on Plankey nominationCyberScoop·Jul 29, 18:23 UTC · Jul 29, 2025Exploit / PoC in the wild60
U.S. CISA adds Wing FTP Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 16, 00:01 UTC · Jul 16, 2025Exploit / PoC in the wildCVE-2025-4781260
GPUHammer: New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUsThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Exploit / PoC45
PerfektBlue Bluetooth attack allows hacking infotainment systems of Mercedes, Volkswagen, and SkodaSecurity Affairs·Jul 10, 18:29 UTC · Jul 10, 2025Exploit / PoCCVE-2024-45434CVE-2024-45431CVE-2024-45433+1 CVEs60
U.S. CISA adds MRLG, PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 8, 14:13 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+1 CVEs60
AT&T deploys new account lock feature to counter SIM swappingCyberScoop·Jul 1, 18:23 UTC · Jul 1, 2025Exploit / PoC in the wild60
Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053)Help Net Security·Jun 16, 13:26 UTC · Jun 16, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-33073CVE-2025-33070+6 CVEs60
Researchers cause GitLab AI developer assistant to turn safe code maliciousArs Technica · Security·May 23, 19:06 UTC · May 23, 2025Exploit / PoC60
Chinese cyber spies are using Ivanti EPMM flaws to breach EU, US organizationsHelp Net Security·May 23, 00:00 UTC · May 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network AttacksThe Hacker News·May 22, 12:07 UTC · May 22, 2025Exploit / PoCCVE-2025-4427CVE-2025-4428CVE-2025-3132460
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
APT group exploited Output Messenger Zero-Day to target Kurdish military operating in IraqSecurity Affairs·May 13, 10:34 UTC · May 13, 2025Exploit / PoCCVE-2025-2792060
NSO Group must pay WhatsApp over $167M in damages for attacks on its usersSecurity Affairs·May 7, 08:57 UTC · May 7, 2025Exploit / PoCCVE-2019-356860
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
Apple backported fixes for three actively exploited flaws to older devicesSecurity Affairs·Apr 2, 08:52 UTC · Apr 2, 2025Exploit / PoC in the wildCVE-2025-24085CVE-2025-24200CVE-2025-2420160
Democratic groups sue to block Trump administration’s elections orderCyberScoop·Apr 1, 17:12 UTC · Apr 1, 2025Exploit / PoC in the wild60
EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC MalwareThe Hacker News·Mar 28, 04:34 UTC · Mar 28, 2025Exploit / PoCCVE-2025-2663360
Poisoned Windows shortcuts found to be a favorite of Chinese, Russian, N. Korean state hackersThe Record·Mar 18, 20:27 UTC · Mar 18, 2025Exploit / PoC in the wild60
Silk Typhoon Shifts Tactics to Exploit Common IT SolutionsInfosecurity Magazine·Mar 5, 16:30 UTC · Mar 5, 2025Exploit / PoC in the wildCVE-2025-028260
Here’s what Google is (and isn’t) planning with SMS account verificationCyberScoop·Feb 27, 21:28 UTC · Feb 27, 2025Exploit / PoC in the wild60
Microsoft Fixes Another Two Actively Exploited ZeroInfosecurity Magazine·Feb 12, 09:45 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2025-21391CVE-2025-21418CVE-2025-21194+1 CVEs60
Cybercrime gang exploited VeraCore zero-day vulnerabilities for years (CVE-2025-25181, CVE-2024-57968)Help Net Security·Feb 11, 13:53 UTC · Feb 11, 2025Exploit / PoCCVE-2025-25181CVE-2024-57968160
Apple fixes iPhone and iPad bug actively exploited in ‘extremely sophisticated attacks’Security Affairs·Feb 10, 23:53 UTC · Feb 10, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2023-41064CVE-2023-41061+1 CVEs60
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW ProtectionsThe Hacker News·Feb 6, 03:48 UTC · Feb 6, 2025Exploit / PoC in the wildCVE-2025-041160
From credit card fraud to zero-day exploits: Xe Group expanding cybercriminal effortsCyberScoop·Feb 3, 14:03 UTC · Feb 3, 2025Exploit / PoC60
U.S. CISA adds Apple products' flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 29, 20:39 UTC · Jan 29, 2025Exploit / PoC in the wildCVE-2025-2408560
Apple fixed the first actively exploited zeroSecurity Affairs·Jan 27, 23:28 UTC · Jan 27, 2025Exploit / PoC in the wildCVE-2025-2408560