How Cisco Talos powers the solutions protecting your organizationCisco Talos·Jan 7, 11:00 UTC · Jan 7, 2026Exploit / PoC60
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wildCisco Talos·Dec 10, 19:37 UTC · Dec 10, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
Alchimist: A new attack framework in Chinese for Mac, Linux and WindowsCisco Talos·Oct 13, 12:00 UTC · Oct 13, 2022Exploit / PoC in the wildCVE-2021-4034160
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilitiesCisco Talos·Jun 11, 14:03 UTC · Jun 11, 2025Exploit / PoCCVE-2024-48877CVE-2024-52035CVE-2024-54028+6 CVEs60
Experts released PoC exploits for bugs in Netgear Orbi routersSecurity Affairs·Mar 22, 18:15 UTC · Mar 22, 2023Exploit / PoC in the wildCVE-2022-37337CVE-2022-38452CVE-2022-36429+1 CVEs60
Zoom has partially fixed two new flaws, with other security hurdles aheadCyberScoop·Jun 5, 16:00 UTC · Jun 5, 2020Exploit / PoC in the wild60
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web ManagerSecurity Affairs·Dec 19, 08:53 UTC · Dec 19, 2025Exploit / PoC in the wildCVE-2025-2039360
China-Linked UAT-7290 Targets Telecom Networks In South AsiaInfosecurity Magazine·Jan 8, 16:00 UTC · Jan 8, 2026Exploit / PoC60
Cisco warns of active exploitation of IOS XE zeroSecurity Affairs·Oct 16, 19:52 UTC · Oct 16, 2023Exploit / PoC in the wildCVE-2023-2019860
CISA adds Cisco IOS XE flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 23, 19:49 UTC · Oct 23, 2023Exploit / PoC in the wildCVE-2021-1435CVE-2023-2019860
Talos Team discovered serious issues in Aerospike Database ServerSecurity Affairs·Jan 15, 12:23 UTC · Jan 15, 2017Exploit / PoCCVE-2016-9050CVE-2016-9052CVE-2016-905460
Watch out, hackers are targeting CVE-2018Security Affairs·Dec 21, 13:30 UTC · Dec 21, 2019Exploit / PoC in the wildCVE-2018-029660
Cisco zero-day under ongoing attack by persistent threat groupCyberScoop·May 15, 14:16 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-20182CVE-2026-20122CVE-2026-20128+2 CVEs60
Hackers abused Cisco SD-WAN zero-day since 2023 to gain full admin controlSecurity Affairs·Feb 26, 14:43 UTC · Feb 26, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2022-2077560
Log4Shell was in the wild at least nine days before public disclosureSecurity Affairs·Dec 13, 09:47 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-22448CVE-2021-4422860
A zero day flaw in OpenJPEG JPEG 2000 could lead arbitrary code executionSecurity Affairs·Oct 2, 17:35 UTC · Oct 2, 2016Exploit / PoCCVE-2016-833260
An issue in the Linux Kernel could allow the hack of your systemSecurity Affairs·Apr 29, 16:53 UTC · Apr 29, 2021Exploit / PoCCVE-2020-2858850
China-linked APT UAT-8837 targets North American critical infrastructureSecurity Affairs·Jan 17, 15:50 UTC · Jan 17, 2026Exploit / PoCCVE-2025-5369060
Experts disclose critical flaws in Advantech router monitoring toolSecurity Affairs·Jul 19, 17:53 UTC · Jul 19, 2021Exploit / PoC in the wildCVE-2021-21799CVE-2021-21800CVE-2021-21801+3 CVEs60
VMware addresses a DoS flaw in Workstation and Fusion productsSecurity Affairs·Mar 17, 18:50 UTC · Mar 17, 2018Exploit / PoCCVE-2018-695760
Experts observed the active exploitation of the CVE-2017Security Affairs·Sep 9, 07:28 UTC · Sep 9, 2017Exploit / PoC in the wildCVE-2017-980560
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Reducing abuse of Microsoft 365 Exchange Online’s Direct SendCisco Talos·Oct 21, 10:00 UTC · Oct 21, 2025Exploit / PoC60
Bitter APT adds Bangladesh to their targetsCisco Talos·May 11, 12:00 UTC · May 11, 2022Exploit / PoCCVE-2017-11882CVE-2018-0798CVE-2018-0802+1 CVEs60
IT threat evolution Q2 2018Kaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2018Exploit / PoCCVE-2018-817460
Cisco email security appliances rooted and backdoored via still unpatched zero-dayHelp Net Security·Jan 16, 14:17 UTC · Jan 16, 2026Exploit / PoCCVE-2025-20393CVE-2025-5777CVE-2025-7775160
Talos: Remcos software is a surveillance tool posing as legitimate softwareCyberScoop·Aug 22, 16:00 UTC · Aug 22, 2018Exploit / PoC in the wild60
Critical Infrastructure at Risk: Advanced Actors Target Smart Install ClientCisco Talos·Apr 5, 13:55 UTC · Apr 5, 2018Exploit / PoC60
Threat Source newsletter (April 27, 2023) — New Cisco Secure offerings and extra security from DuoCisco Talos·Apr 27, 18:00 UTC · Apr 27, 2023Exploit / PoCCVE-2023-2735060
Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networksSecurity Affairs·Apr 24, 20:31 UTC · Apr 24, 2024Exploit / PoCCVE-2024-20353CVE-2024-20359CVE-2018-0101160
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 20:17 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2024-20353CVE-2024-20359CVE-2024-4040+1 CVEs60
Tens of thousands Cisco IOS XE devices were hacked by exploiting CVE-2023Security Affairs·Oct 20, 10:13 UTC · Oct 20, 2023Exploit / PoC in the wildCVE-2023-2019860
Less panic patching, more precisionCisco Talos·May 28, 18:00 UTC · May 28, 2026Exploit / PoC in the wild60
Cisco Smart Install Protocol misuse could expose critical infrastructure to attacksSecurity Affairs·Apr 6, 04:50 UTC · Apr 6, 2018Exploit / PoCCVE-2018-017160
Talos release protection against zero-day vulnerability (CVE-2021Cisco Talos·Sep 9, 15:38 UTC · Sep 9, 2021Exploit / PoC in the wildCVE-2021-4044460
Hafnium Update: Continued Microsoft Exchange Server ExploitationCisco Talos·Mar 10, 00:52 UTC · Mar 10, 2021Exploit / PoC60
How hackers used a PowerPoint file to spy on Tibet’s government-inCyberScoop·Feb 4, 21:07 UTC · Feb 4, 2019Exploit / PoC in the wild60
Threat Advisory: Zero-day vulnerability in Microsoft diagnostic tool MSDT could lead to code executionCisco Talos·Jun 1, 14:19 UTC · Jun 1, 2022Exploit / PoCCVE-2022-3019060
U.S. CISA adds Cisco SD-WAN flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 26, 15:04 UTC · Feb 26, 2026Exploit / PoC in the wildCVE-2022-20775CVE-2026-2012760