Update ASAP: Google Fixes Android Flaw (CVE-2025The Hacker News·May 7, 05:27 UTC · May 7, 2025Exploit / PoC in the wildCVE-2025-2736360
MITRE Caldera RCE vulnerability with public PoC fixed, patch ASAP! (CVE-2025–27364)Help Net Security·Apr 2, 08:49 UTC · Apr 2, 2025Exploit / PoC60
Actively exploited Firefox zero-day fixed, update ASAP! (CVE-2024-9680)Help Net Security·Nov 26, 13:23 UTC · Nov 26, 2024Exploit / PoC in the wildCVE-2024-968060
15 QNAP NAS bugs and one PoC disclosed, update ASAP! (CVE-2024-27130)Help Net Security·May 21, 00:00 UTC · May 21, 2024Exploit / PoCCVE-2024-27130CVE-2023-50361CVE-2023-50364+2 CVEs60
Ivanti Sentry zero-day vulnerability exploited, patch ASAP! (CVE-2023-38035)Help Net Security·Aug 24, 12:34 UTC · Aug 24, 2023Exploit / PoC in the wildCVE-2023-3803560
Critical Microsoft RPC runtime bug: No PoC exploit yet, but patch ASAP! (CVE-2022-26809)Help Net Security·Apr 15, 00:00 UTC · Apr 15, 2022Exploit / PoCCVE-2022-26809160
Cisco plugs critical hole in WebEx, users urged to upgrade ASAPHelp Net Security·Jun 18, 12:51 UTC · Jun 18, 2020Exploit / PoC in the wildCVE-2018-011260
Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621)Help Net Security·Apr 13, 00:00 UTC · Apr 13, 2026Exploit / PoC in the wildCVE-2026-3462160
DarkSword's GitHub leak threatens to turn elite iPhone hacking into a tool for the massesCyberScoop·Mar 24, 21:34 UTC · Mar 24, 2026Exploit / PoC in the wild160
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
Dahua Camera flaws allow remote hacking. Update firmware nowSecurity Affairs·Jul 31, 05:55 UTC · Jul 31, 2025Exploit / PoCCVE-2025-31700CVE-2025-3170160
Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201)Help Net Security·Apr 17, 00:00 UTC · Apr 17, 2025Exploit / PoCCVE-2025-31200CVE-2025-31201CVE-2025-2420060
Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security toolsHelp Net Security·Oct 13, 00:00 UTC · Oct 13, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-9680+5 CVEs160
Critical Acronis Cyber Infrastructure vulnerability exploited in the wild (CVE-2023-45249)Help Net Security·Jul 29, 00:00 UTC · Jul 29, 2024Exploit / PoC in the wildCVE-2023-4524960
Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROIHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2024Exploit / PoCCVE-2024-6327CVE-2024-4111060
PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)Help Net Security·Jun 6, 10:01 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2024-4358CVE-2024-1800CVE-2023-3436260
High-risk Atlassian Confluence RCE fixed, PoC available (CVE-2024-21683)Help Net Security·Jun 3, 00:00 UTC · Jun 3, 2024Exploit / PoCCVE-2024-21683160
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
Hackers exploited Windows 0-day for 6 months after Microsoft knew of itArs Technica · Security·Mar 4, 22:47 UTC · Mar 4, 2024Exploit / PoC in the wildCVE-2024-2133860
Why the toothbrush DDoS story fooled us allCisco Talos·Feb 15, 19:00 UTC · Feb 15, 2024Exploit / PoCCVE-2022-073260
Two Ivanti ZeroInfosecurity Magazine·Jan 11, 09:30 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2023-35078+1 CVEs60
Microsoft patches zero-day exploited by attackers (CVE-2023-28252)Help Net Security·Apr 11, 00:00 UTC · Apr 11, 2023Exploit / PoC in the wildCVE-2023-28252CVE-2023-23376CVE-2023-21554+4 CVEs60
Week in review: Citrix and Fortinet RCEs, Microsoft fixes exploited zero-dayHelp Net Security·Dec 18, 00:00 UTC · Dec 18, 2022Exploit / PoCCVE-2022-20968CVE-2022-42475CVE-2022-27518+1 CVEs60
Apache fixes actively exploited web server zeroThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2021-4177360
Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devicesHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2022Exploit / PoC in the wildCVE-2022-41033CVE-2022-40684CVE-2022-36067+1 CVEs160
Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-dayHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2022Exploit / PoC in the wildCVE-2022-24521CVE-2022-26904CVE-2022-26809+1 CVEs60
Week in review: Patch Tuesday forecast, how to select a DLP solution, is it OK to publish PoC exploits?Help Net Security·May 9, 00:00 UTC · May 9, 2021Exploit / PoC in the wild60
Victims of Microsoft Exchange Server zeroCyberScoop·Mar 5, 15:14 UTC · Mar 5, 2021Exploit / PoC in the wild60
Exploits for vBulletin zero-day released, attacks are ongoingHelp Net Security·Aug 11, 00:00 UTC · Aug 11, 2020Exploit / PoCCVE-2019-1675960
Firefox 74.0.1 addresses two zeroSecurity Affairs·Apr 4, 16:22 UTC · Apr 4, 2020Exploit / PoC in the wildCVE-2020-6819CVE-2020-6820CVE-2019-1702660
Attackers are targeting vulnerable Fortigate and Pulse Secure SSL VPNsHelp Net Security·Aug 28, 10:05 UTC · Aug 28, 2019Exploit / PoC in the wildCVE-2019-11510CVE-2018-1337960
Magento sites under attack through easily exploitable SQLi flawHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2019Exploit / PoC in the wild60
Magento Attacked Through Card Skimming ExploitSecurity Affairs·Apr 6, 08:09 UTC · Apr 6, 2019Exploit / PoC60
WordPress Social Warfare plugin zeroSecurity Affairs·Mar 24, 11:01 UTC · Mar 24, 2019Exploit / PoC in the wild60
Google plugs Chrome zero-day exploited in the wildHelp Net Security·Mar 6, 00:00 UTC · Mar 6, 2019Exploit / PoC in the wildCVE-2019-578660
A cybersecurity power struggle is brewing at the National Security CouncilCyberScoop·Apr 21, 02:33 UTC · Apr 21, 2018Exploit / PoC60
The confrontation that fueled the fallout between Kaspersky and the U.S. governmentCyberScoop·Oct 10, 13:00 UTC · Oct 10, 2017Exploit / PoC in the wild60
SQLi flaw in the NextGEN Gallery plugin exposes at risk of hack more than 1 Million WordPress InstallsSecurity Affairs·Mar 1, 11:00 UTC · Mar 1, 2017Exploit / PoC in the wild60
Hacking Ubuntu Linux distro exploiting the CrashDB code injection issueSecurity Affairs·Dec 16, 14:34 UTC · Dec 16, 2016Exploit / PoCCVE-2016-9949CVE-2016-9950CVE-2016-9951160
The code of a Firefox Zero-Day Exploit used to unmask Tor Users is onlineSecurity Affairs·Nov 30, 12:38 UTC · Nov 30, 2016Exploit / PoC in the wild60