U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
U.S. CISA adds Sitecore CMS and XP, and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 27, 12:31 UTC · Mar 27, 2025Exploit / PoC in the wildCVE-2019-9875CVE-2019-9874CVE-2025-3015460
Tj-actions Supply Chain Attack Traced Back to GitHub Token CompromiseInfosecurity Magazine·Apr 4, 12:00 UTC · Apr 4, 2025Exploit / PoC in the wildCVE-2025-3006660
More evidence your AI agents can be turned against youCyberScoop·Dec 5, 20:48 UTC · Dec 5, 2025Exploit / PoC in the wild60
U.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 27, 10:15 UTC · Mar 27, 2026Exploit / PoC in the wildCVE-2026-3363460
Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROIHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2024Exploit / PoCCVE-2024-6327CVE-2024-4111060
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain AttacksThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wild60
Compromised AsyncAPI npm Packages Deliver MultiThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC157
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain AttacksThe Hacker News·Aug 19, 04:18 UTC · Aug 19, 2025Exploit / PoC157
Zen-AI-Pentest: Open-source AI-powered penetration testing frameworkHelp Net Security·Feb 11, 00:00 UTC · Feb 11, 2026Exploit / PoC45
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow SecretsThe Hacker News·Aug 7, 08:18 UTC · Aug 7, 2026Exploit / PoC in the wildCVE-2026-12537CVE-2026-54316160
Less panic patching, more precisionCisco Talos·May 28, 18:00 UTC · May 28, 2026Exploit / PoC in the wild60
U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 28, 13:14 UTC · May 28, 2026Exploit / PoC in the wildCVE-2026-8398CVE-2026-45321CVE-2026-4802760
Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active AttacksThe Hacker News·Jan 13, 07:05 UTC · Jan 13, 2026Exploit / PoC in the wildCVE-2025-8110CVE-2024-5594760
Protect AI emerges from stealth and raises $13.5 millionHelp Net Security·Dec 20, 10:36 UTC · Dec 20, 2022Exploit / PoC160
Nightmare Eclipse incident shows the researcherCyberScoop·Jun 5, 14:48 UTC · Jun 5, 2026Exploit / PoC60
Codecov dev tool hit in another supply chain hackCyberScoop·Apr 16, 16:21 UTC · Apr 16, 2021Exploit / PoC in the wild60
Top 10 Takeaways from Predict 2025: Turning Intelligence Into ActionRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025Exploit / PoC in the wild60
Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI ModelsThe Hacker News·Sep 24, 13:55 UTC · Sep 24, 2025Exploit / PoCCVE-2025-10643CVE-2025-1064460
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsThe Hacker News·Jun 10, 17:30 UTC · Jun 10, 2026Exploit / PoC in the wildCVE-2026-33825CVE-2026-45498CVE-2026-41091160
Zero-Day Flaw Discovered in Quarkus Java FrameworkInfosecurity Magazine·Nov 30, 16:00 UTC · Nov 30, 2022Exploit / PoCCVE-2022-4116160
Critical Apache Struts flaw CVE-2018Security Affairs·Aug 28, 16:07 UTC · Aug 28, 2018Exploit / PoCCVE-2018-11776CVE-2017-563860
Chinese Hackers Target France in Ivanti ZeroInfosecurity Magazine·Jul 2, 12:00 UTC · Jul 2, 2025Exploit / PoCCVE-2024-8190CVE-2024-8963CVE-2024-9380160
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
Massive supply-chain attack compromises 440 packages under four hoursCyberScoop·Aug 4, 22:07 UTC · Aug 4, 2026Exploit / PoC60
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AICyberScoop·May 8, 13:14 UTC · May 8, 2026Exploit / PoC in the wild60
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from BoltThe Hacker News·Jul 6, 11:30 UTC · Jul 6, 2026Exploit / PoC45
ShadowLeak Zero-Click Flaw Leaks Gmail Data via OpenAI ChatGPT Deep Research AgentThe Hacker News·Sep 20, 05:32 UTC · Sep 20, 2025Exploit / PoC45
GitHub to review its exploit-hosting policy in light of recent scandalThe Record·Dec 7, 00:00 UTC · Dec 7, 2022Exploit / PoC45
Experts warn of possible attacks after PoC code for CVE-2018Security Affairs·Aug 27, 15:13 UTC · Aug 27, 2018Exploit / PoCCVE-2018-11776CVE-2017-563860
Proof It's Possible to Hack German Elections; Hackers Tamper with VotingThe Hacker News·Sep 7, 17:33 UTC · Sep 7, 2017Exploit / PoC60
PoC rootkit Curing evades traditional Linux detection systemsSecurity Affairs·Apr 28, 09:38 UTC · Apr 28, 2025Exploit / PoC60
DoubleAgent attack uses built-in Windows tool to hijack applicationsHelp Net Security·Nov 21, 11:35 UTC · Nov 21, 2023Exploit / PoC60
Do robots dream of secure networking? Teaching cybersecurity to AI systemsCisco Talos·Nov 6, 14:25 UTC · Nov 6, 2025Exploit / PoC45
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860
Cursor’s AI coding agent morphed ‘into local shell’ with oneCyberScoop·Aug 1, 19:51 UTC · Aug 1, 2025Exploit / PoC in the wildCVE-2025-5413560
BlueHammer: Windows zero-day exploit leakedHelp Net Security·Jun 30, 11:31 UTC · Jun 30, 2026Exploit / PoC in the wildCVE-2026-3382560