Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD TokensThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Exploit / PoC in the wild160
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
Chinese hackers forged authentication tokens to breach government emailsHelp Net Security·Jul 14, 19:08 UTC · Jul 14, 2023Exploit / PoC in the wild60
Yubico CEO: Two-factor authentication should mirror seat belt's historyCyberScoop·Apr 18, 13:22 UTC · Apr 18, 2018Exploit / PoC in the wild60
Week in review: AD password reset best practices, new issue of (IN)SECUREHelp Net Security·Dec 15, 00:00 UTC · Dec 15, 2019Exploit / PoC in the wild60
How to improve your organization's Active Directory security postureHelp Net Security·Jul 6, 00:00 UTC · Jul 6, 2021Exploit / PoC60
Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh serversHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-24016CVE-2025-43200+1 CVEs60
Exclusive: Kevin Mandia joins SpecterOps as chair of the boardCyberScoop·Oct 1, 12:00 UTC · Oct 1, 2024Exploit / PoC in the wild60
Chinese Hacker Steals Microsoft Signing Key, Spies on US GovernmentInfosecurity Magazine·Sep 7, 13:00 UTC · Sep 7, 2023Exploit / PoC60
Researcher releases PoC code for critical Atlassian Crowd RCE flawHelp Net Security·Aug 3, 11:37 UTC · Aug 3, 2020Exploit / PoCCVE-2019-1158060
From summer camp to grind seasonCisco Talos·Sep 4, 18:02 UTC · Sep 4, 2025Exploit / PoCCVE-2025-5517760
IBM joins other tech giants and removes Russian state controlled network from its cloud serviceCyberScoop·Jul 12, 16:00 UTC · Jul 12, 2022Exploit / PoC60
MOVEit Transfer Under Attack: Zero-Day Vulnerability Actively Being ExploitedThe Hacker News·Jun 7, 08:52 UTC · Jun 7, 2023Exploit / PoC in the wildCVE-2023-3436260
New Silver SAML Attack Evades Golden SAML Defenses in Identity SystemsThe Hacker News·Mar 11, 04:52 UTC · Mar 11, 2024Exploit / PoC in the wild60
Microsoft launches ‘Zero Day Quest’ competition to enhance cloud and AI securityCyberScoop·Nov 19, 20:12 UTC · Nov 19, 2024Exploit / PoC60
Critical Flaws Discovered in Azure App That Microsoft Secretly Installs on Linux VMsThe Hacker News·Sep 17, 19:17 UTC · Sep 17, 2021Exploit / PoCCVE-2021-38647CVE-2021-38648CVE-2021-38645+1 CVEs60
Microsoft IDs developers behind alleged generative AI hacking-forCyberScoop·Feb 27, 18:30 UTC · Feb 27, 2025Exploit / PoC in the wild160
RSA Conference announces initial 2019 keynote speakersHelp Net Security·Mar 9, 19:18 UTC · Mar 9, 2023Exploit / PoC in the wildCVE-2026-8749160
Microsoft fixes exploited zero-day in Windows CSRSS (CVE-2022-22047)Help Net Security·Jul 12, 00:00 UTC · Jul 12, 2022Exploit / PoC in the wildCVE-2022-22047CVE-2022-30216CVE-2022-22029+1 CVEs160
September 2019 Patch Tuesday: Microsoft plugs two actively exploited zero-daysHelp Net Security·Sep 14, 06:24 UTC · Sep 14, 2019Exploit / PoC in the wildCVE-2019-1214CVE-2019-1215CVE-2019-1257+10 CVEs60
U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 11, 07:37 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21510CVE-2026-21513CVE-2026-21514+3 CVEs160
U.S. CISA adds a flaw in Microsoft Windows to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 14, 11:45 UTC · Jan 14, 2026Exploit / PoC in the wildCVE-2026-2080560
Microsoft Releases Fix for Zero-Day Flaw in July 2022 Security Patch RolloutThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2022Exploit / PoC in the wildCVE-2022-22047CVE-2022-22026CVE-2022-22049+14 CVEs60
Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)Help Net Security·May 12, 08:27 UTC · May 12, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs160
Microsoft patches two actively exploited zero-days (CVE-2024-29988, CVE-2024-26234)Help Net Security·Apr 9, 00:00 UTC · Apr 9, 2024Exploit / PoC in the wildCVE-2024-29988CVE-2024-26234CVE-2024-21412+9 CVEs60
Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android usersHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2024Exploit / PoC in the wildCVE-2023-45249CVE-2024-3708560
Microsoft Patch Tuesday matches last year’s zero-day high with six actively exploited vulnerabilitiesCyberScoop·Feb 10, 20:50 UTC · Feb 10, 2026Exploit / PoC in the wildCVE-2026-21510CVE-2026-21513CVE-2026-21514+5 CVEs160
Microsoft opens up coronavirus threat data to the publicCyberScoop·May 14, 22:25 UTC · May 14, 2020Exploit / PoC in the wild160
China-linked Murky Panda targets and moves laterally through cloud servicesHelp Net Security·Aug 22, 00:00 UTC · Aug 22, 2025Exploit / PoCCVE-2023-3519CVE-2025-392860
Microsoft fixed a flaw in Power Platform after being criticizedSecurity Affairs·Aug 6, 15:10 UTC · Aug 6, 2023Exploit / PoC in the wild60
Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039)Help Net Security·Nov 26, 13:25 UTC · Nov 26, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-43639+3 CVEs60
CISA adds Progress MOVEit Transfer zero-day to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 2, 21:37 UTC · Jun 2, 2023Exploit / PoC in the wildCVE-2023-3436260
Researcher Explains Release of Undisclosed ZeroInfosecurity Magazine·Jul 2, 12:51 UTC · Jul 2, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2026-58049CVE-2026-58050+10 CVEs160
Domain fronting has a dwindling futureCyberScoop·Jul 24, 16:56 UTC · Jul 24, 2018Exploit / PoC in the wild60
Tenable CEO accuses Microsoft of negligence in addressing security flawCyberScoop·Aug 2, 18:12 UTC · Aug 2, 2023Exploit / PoC160
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
Microsoft Addresses Critical Power Platform Flaw After Delays and CriticismThe Hacker News·Aug 5, 07:38 UTC · Aug 5, 2023Exploit / PoC in the wild60
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs60