U.S. CISA adds JQuery flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 24, 19:59 UTC · Jan 24, 2025Exploit / PoC in the wildCVE-2020-1102360
Pwn2Own Automotive 2025 Day 1: organizers awarded $382,750 for 16 zeroSecurity Affairs·Jan 22, 22:01 UTC · Jan 22, 2025Exploit / PoC60
Closing software-understanding gap is critical to national security, CISA saysCyberScoop·Jan 17, 17:11 UTC · Jan 17, 2025Exploit / PoC in the wild60
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [30 Dec]The Hacker News·Jan 8, 11:22 UTC · Jan 8, 2025Exploit / PoCCVE-2024-3393CVE-2019-3568CVE-2024-56337+7 CVEs160
LDAPNightmare, a PoC exploit targets Windows LDAP flaw CVE-2024Security Affairs·Jan 3, 09:42 UTC · Jan 3, 2025Exploit / PoCCVE-2024-49113CVE-2024-49112160
An X user claimed a 7-Zip zero-day vulnerability, but 7Security Affairs·Dec 31, 00:09 UTC · Dec 31, 2024Exploit / PoC60
U.S. CISA adds CyberPanel flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 10, 23:47 UTC · Dec 10, 2024Exploit / PoC in the wildCVE-2024-5137860
NachoVPN Tool Exploits Flaws in Popular VPN Clients for System CompromiseThe Hacker News·Dec 3, 10:17 UTC · Dec 3, 2024Exploit / PoC in the wildCVE-2024-5921CVE-2024-2901460
Advanced threat predictions for 2025Kaspersky Securelist·Nov 25, 10:02 UTC · Nov 25, 2024Exploit / PoCCVE-2024-23222CVE-2024-23225CVE-2024-23296+3 CVEs60
Cybersecurity jobs available right now: October 16, 2024Help Net Security·Nov 25, 09:23 UTC · Nov 25, 2024Exploit / PoC45
The UN cybercrime convention threatens security research. The US should do something about itCyberScoop·Nov 14, 12:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
U.S. CISA adds Palo Alto Expedition, Android, CyberPanel and Nostromo nhttpd bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 7, 22:49 UTC · Nov 7, 2024Exploit / PoC in the wildCVE-2024-43093CVE-2024-51567CVE-2019-16278+2 CVEs60
Samsung zeroSecurity Affairs·Oct 22, 15:42 UTC · Oct 22, 2024Exploit / PoC in the wildCVE-2024-4406860
WordPress plugin Jetpack fixes nearly decadeThe Record·Oct 15, 14:11 UTC · Oct 15, 2024Exploit / PoC in the wild60
Google Pixel 9 supports new security features to mitigate baseband attacksSecurity Affairs·Oct 6, 08:44 UTC · Oct 6, 2024Exploit / PoC60
Cybersecurity Researchers Warn of New Rust-Based Splinter PostThe Hacker News·Sep 25, 12:38 UTC · Sep 25, 2024Exploit / PoC145
Android camera apps could be hijacked to spy on usersHelp Net Security·Sep 18, 09:34 UTC · Sep 18, 2024Exploit / PoCCVE-2019-223450
U.S. CISA adds SonicWall SonicOS, ImageMagick and Linux Kernel bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 10, 07:18 UTC · Sep 10, 2024Exploit / PoC in the wildCVE-2016-3714CVE-2017-1000253CVE-2024-4076660
Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival HijackThe Hacker News·Sep 5, 09:14 UTC · Sep 5, 2024Exploit / PoC in the wild60
Google to Remove App that Made Google Pixel Devices Vulnerable to AttacksThe Hacker News·Sep 4, 09:01 UTC · Sep 4, 2024Exploit / PoC in the wild60
North Korea-linked APT Citrine Sleet exploit Chrome zero-day to deliver FudModule rootkitSecurity Affairs·Aug 31, 18:22 UTC · Aug 31, 2024Exploit / PoCCVE-2024-7971CVE-2024-3810660
Fortra fixed 2 severe issues in FileCatalyst Workflow, including a critical flawSecurity Affairs·Aug 30, 19:47 UTC · Aug 30, 2024Exploit / PoC in the wildCVE-2024-6633CVE-2024-663260
Microsoft Fixes ASCII Smuggling Flaw That Enabled Data Theft from Microsoft 365 CopilotThe Hacker News·Aug 29, 10:57 UTC · Aug 29, 2024Exploit / PoC157
Securing remote access to mission-critical OT assetsHelp Net Security·Jul 30, 00:00 UTC · Jul 30, 2024Exploit / PoC in the wild60
Cyber firm KnowBe4 hired a fake IT worker from North KoreaCyberScoop·Jul 24, 15:34 UTC · Jul 24, 2024Exploit / PoC in the wild60
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
Critical Ghostscript flaw exploited in the wild. Patch it now!Security Affairs·Jul 8, 18:12 UTC · Jul 8, 2024Exploit / PoC in the wildCVE-2024-29510CVE-2024-29509CVE-2024-29506+3 CVEs60
Researchers uncover rare, difficult-toCyberScoop·Jul 3, 00:04 UTC · Jul 3, 2024Exploit / PoCCVE-2024-638760
‘RegreSSHion’ bug raises alarms but experts question chances of widespread exploitationThe Record·Jul 2, 21:17 UTC · Jul 2, 2024Exploit / PoC in the wildCVE-2024-6387CVE-2006-505160
Dangling Domains: Security Threats, Detection and PrevalencePalo Alto Unit 42·Jun 6, 01:30 UTC · Jun 6, 2024Exploit / PoC45
Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation MethodologiesPalo Alto Unit 42·Jun 5, 13:30 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2022-21882CVE-2021-1732CVE-2022-1732160
Fake Tom Cruise warns of violence at Paris Olympics in proCyberScoop·Jun 3, 04:00 UTC · Jun 3, 2024Exploit / PoC in the wild60
May 2024 Patch Tuesday: Microsoft fixes exploited zero-days (CVE-2024-30051, CVE-2024-30040)Help Net Security·May 31, 08:23 UTC · May 31, 2024Exploit / PoC in the wildCVE-2024-30051CVE-2024-30040CVE-2023-36033+2 CVEs160
Russian influence op keeps trying but struggles to win hearts and mindsCyberScoop·May 29, 15:54 UTC · May 29, 2024Exploit / PoC in the wild60
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
Three bills governing AI in elections pass Senate committeeCyberScoop·May 15, 17:29 UTC · May 15, 2024Exploit / PoC in the wild60
China-Linked Hackers Used ROOTROT Webshell in MITRE Network IntrusionThe Hacker News·May 7, 12:55 UTC · May 7, 2024Exploit / PoC60
Pro-Russia hacktivists attacking vital tech in water and other sectors, agencies sayCyberScoop·May 1, 18:35 UTC · May 1, 2024Exploit / PoC in the wild60
Dormakaba Locks Used in Millions of Hotel Rooms Could Be Cracked in SecondsThe Hacker News·Mar 29, 14:54 UTC · Mar 29, 2024Exploit / PoC60
Drozer: Open-source Android security assessment frameworkHelp Net Security·Mar 27, 00:00 UTC · Mar 27, 2024Exploit / PoC45