Google provides rules to detect tens of cracked versions of Cobalt StrikeSecurity Affairs·Nov 21, 11:41 UTC · Nov 21, 2022Exploit / PoC45
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt StrikeThe Hacker News·May 26, 05:19 UTC · May 26, 2026Exploit / PoCCVE-2026-542660
Hackers Deploy Open-Source Tool Sliver C2, Replacing Cobalt Strike, MetasploitInfosecurity Magazine·Jan 23, 18:00 UTC · Jan 23, 2023Exploit / PoC45
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
Hackers Targeting Myanmar Use Domain Fronting to Hide Malicious ActivitiesThe Hacker News·Nov 17, 15:13 UTC · Nov 17, 2021Exploit / PoC45
Using an agent for the Mythic framework: pros and cons in pentestingKaspersky Securelist·May 13, 10:00 UTC · May 13, 2025Exploit / PoC60
Threat Source newsletter (Aug. 4, 2022) — BlackHat 2022 previewCisco Talos·Aug 4, 18:00 UTC · Aug 4, 2022Exploit / PoC in the wildCVE-2022-2613860
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Cybercriminals capitalize on poorly configured cloud environmentsHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2024Exploit / PoC60
Notepad++ infrastructure hack likely tied to ChinaSecurity Affairs·Feb 3, 09:35 UTC · Feb 3, 2026Exploit / PoC60
2025 Year in Review: Malicious, InfrastructureRecorded Future·Mar 20, 00:00 UTC · Mar 20, 2026Exploit / PoC57
Adversarial groups adapt to exploit systems in new waysHelp Net Security·Oct 28, 00:00 UTC · Oct 28, 2024Exploit / PoC45
CISA adds bugs exploited by commercial surveillance spyware to Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 1, 18:06 UTC · Apr 1, 2023Exploit / PoC in the wildCVE-2021-30900CVE-2022-38181CVE-2023-0266+6 CVEs60
Notepad++ supply chain attack: Researchers reveal details, IoCs, targetsHelp Net Security·Feb 17, 10:13 UTC · Feb 17, 2026Exploit / PoC60
OPERA1ER APT Hackers Targeted Dozens of Financial Organizations in AfricaThe Hacker News·Jan 5, 12:22 UTC · Jan 5, 2023Exploit / PoC60
Log4Shell was in the wild at least nine days before public disclosureSecurity Affairs·Dec 13, 09:47 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-22448CVE-2021-4422860
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure EntitiesThe Hacker News·Feb 7, 11:03 UTC · Feb 7, 2026Exploit / PoC60
Rust Payloads Exploiting Ivanti 0Infosecurity Magazine·Jan 30, 15:00 UTC · Jan 30, 2024Exploit / PoCCVE-2024-21887CVE-2023-4680560
Bank heist with FIN7 traits went down while leaders were on the run, research suggestsCyberScoop·Jun 4, 12:55 UTC · Jun 4, 2019Exploit / PoC in the wild60
Russian cyberspies targeted the Slovak government for monthsThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoC60
ShadowSilk Hits 35 Organizations in Central Asia and APAC Using Telegram BotsThe Hacker News·Aug 28, 03:59 UTC · Aug 28, 2025Exploit / PoCCVE-2018-7600CVE-2018-76020CVE-2024-2795650
Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government NetworksThe Hacker News·May 23, 04:01 UTC · May 23, 2025Exploit / PoC in the wildCVE-2025-094460
Threat actors target the infoSec community with fake PoC exploitsSecurity Affairs·May 23, 18:21 UTC · May 23, 2022Exploit / PoCCVE-2022-26809CVE-2022-2450060
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
Financial hacking teams FIN7, Cobalt Group update tactics to haunt banks and retailCyberScoop·Aug 14, 15:18 UTC · Aug 14, 2019Exploit / PoC in the wild60
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
Ongoing exploitation of Cisco Catalyst SDCisco Talos·May 14, 16:02 UTC · May 14, 2026Exploit / PoC in the wildCVE-2026-20182CVE-2026-20133CVE-2026-20128+2 CVEs160
One Missed Threat Per Week: What 25M Alerts Reveal About LowThe Hacker News·May 8, 10:30 UTC · May 8, 2026Exploit / PoC60
UAT-7290 targets high value telecommunications infrastructure in South AsiaCisco Talos·Jan 8, 11:00 UTC · Jan 8, 2026Exploit / PoC60
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency MitigationThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Exploit / PoC in the wildCVE-2025-55182CVE-2021-4422860
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
Underground AI models promise to be hackers ‘cyber pentesting waifu’CyberScoop·Nov 26, 01:13 UTC · Nov 26, 2025Exploit / PoC in the wild60
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe Hacker News·Jul 8, 05:08 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+3 CVEs60
Log4Shell: How It’s Exploited and Mitigating DamageRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2021-4422860
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper BackdoorThe Hacker News·Jun 18, 10:32 UTC · Jun 18, 2025Exploit / PoC in the wildCVE-2025-2783CVE-2024-647360
U.S. CISA adds Trimble Cityworks flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 7, 21:54 UTC · Feb 7, 2025Exploit / PoC in the wildCVE-2025-099460
Mandiant devised a technique to bypass browser isolation using QR codesSecurity Affairs·Dec 9, 12:12 UTC · Dec 9, 2024Exploit / PoC45