U.S. CISA adds Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 14, 00:12 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2013-3893CVE-2007-0671CVE-2025-808860
U.S. CISA adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 26, 22:32 UTC · May 26, 2026Exploit / PoC in the wildCVE-2009-0238CVE-2026-32201160
Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321, CVE-2021-42292)Help Net Security·Nov 9, 00:00 UTC · Nov 9, 2021Exploit / PoC in the wildCVE-2021-42321CVE-2021-42292CVE-2021-38666+2 CVEs60
Bitter APT adds Bangladesh to their targetsCisco Talos·May 11, 12:00 UTC · May 11, 2022Exploit / PoCCVE-2017-11882CVE-2018-0798CVE-2018-0802+1 CVEs60
63 New Flaws (Including 0The Hacker News·Nov 15, 00:00 UTC · Nov 15, 2018Exploit / PoC in the wildCVE-2018-8589CVE-2018-8584CVE-2018-8566+47 CVEs60
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug FlagThe Hacker News·Jun 3, 14:56 UTC · Jun 3, 2026Exploit / PoCCVE-2026-41100CVE-2026-41101CVE-2026-41102+1 CVEs150
Chinese Hackers Exploited New ZeroThe Hacker News·Dec 28, 11:07 UTC · Dec 28, 2023Exploit / PoC in the wildCVE-2023-7102CVE-2023-2868CVE-2023-710160
Bitter APT Hackers Add Bangladesh to Their List of Targets in South AsiaThe Hacker News·May 12, 01:27 UTC · May 12, 2022Exploit / PoCCVE-2021-1732CVE-2021-28310CVE-2017-11882+2 CVEs60
Researchers say this attack is a bad bug. Microsoft says it's a feature.CyberScoop·Oct 13, 17:51 UTC · Oct 13, 2017Exploit / PoC in the wild160
How hackers used a PowerPoint file to spy on Tibet’s government-inCyberScoop·Feb 4, 21:07 UTC · Feb 4, 2019Exploit / PoC in the wild60
Anonymous offshoots rush to avenge Assange arrest with cyberattacksCyberScoop·Apr 19, 13:58 UTC · Apr 19, 2019Exploit / PoC in the wild60
NATO countries' refugee management may have been targeted by BelarusCyberScoop·Mar 2, 15:51 UTC · Mar 2, 2022Exploit / PoC in the wild60
South Korea Warns of Flash Zero-Day flaw exploited by North Korea in surgical attacksSecurity Affairs·Feb 1, 22:17 UTC · Feb 1, 2018Exploit / PoCCVE-2018-487860
CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities CatalogThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Exploit / PoC in the wildCVE-2025-8875CVE-2025-8876CVE-2013-3893+1 CVEs60
U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 14, 08:03 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2025-8875CVE-2025-887660
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilitiesCisco Talos·Jun 11, 14:03 UTC · Jun 11, 2025Exploit / PoCCVE-2024-48877CVE-2024-52035CVE-2024-54028+6 CVEs60
More on the Chinese Zero-Day Microsoft Exchange HackSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2021Exploit / PoC60
Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widensHelp Net Security·Dec 3, 00:00 UTC · Dec 3, 2023Exploit / PoC in the wildCVE-2023-46214CVE-2023-49103CVE-2023-41998+5 CVEs260
Zerodium Offers $1.5 Million Bounty For iOS ZeroThe Hacker News·Sep 30, 07:56 UTC · Sep 30, 2016Exploit / PoC60
Microsoft warns of new IE zeroThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Exploit / PoCCVE-2021-40444CVE-2021-14044460
New 0-Day Attack Targeting Windows Users With Microsoft Office DocumentsThe Hacker News·Sep 8, 04:55 UTC · Sep 8, 2021Exploit / PoC in the wildCVE-2021-4044460
The New Disclosure Debate and the Evil Mr. MooreCisco Talos·Mar 16, 17:36 UTC · Mar 16, 2010Exploit / PoC57
Russian ‘Dukes’ of Hackers Pounce on Trump WinKrebs on Security·Nov 15, 00:00 UTC · Nov 15, 2016Exploit / PoC60
Microsoft Uncovers Austrian Company Exploiting Windows and Adobe ZeroThe Hacker News·Jul 29, 02:58 UTC · Jul 29, 2022Exploit / PoCCVE-2022-22047CVE-2021-31199CVE-2021-31201+2 CVEs160
Experts published unpatched Windows zero-day BlueHammerSecurity Affairs·Apr 7, 08:10 UTC · Apr 7, 2026Exploit / PoC160
ProjectZero disclose details for three OS X 0days on AppleSecurity Affairs·Jan 23, 10:13 UTC · Jan 23, 2015Exploit / PoC60
Microsoft Releases Windows Update (Dec 2020) to Fix 58 Security FlawsThe Hacker News·Dec 9, 04:58 UTC · Dec 9, 2020Exploit / PoC in the wildCVE-2020-17132CVE-2020-17118CVE-2020-17121+4 CVEs60
Power grid cyber deal between utility and National Guard hailed as modelCyberScoop·Jul 12, 14:42 UTC · Jul 12, 2016Exploit / PoC in the wild60
Matt's Guide to Vendor ResponseCisco Talos·Dec 30, 17:56 UTC · Dec 30, 2009Exploit / PoC in the wild60
Unpatched Windows Zero-Day Flaw Exploited by 11 StateThe Hacker News·Mar 19, 03:46 UTC · Mar 19, 2025Exploit / PoC60
Multiple government hacking groups stay busy targeting Ukraine and the region, Google researchers sayCyberScoop·May 3, 16:00 UTC · May 3, 2022Exploit / PoC in the wild60
Microsoft fixes actively exploited Windows Hyper-V zero-day flawsHelp Net Security·Jan 14, 00:00 UTC · Jan 14, 2025Exploit / PoC in the wildCVE-2025-21333CVE-2025-21334CVE-2025-21335+6 CVEs60
Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation MethodologiesPalo Alto Unit 42·Jun 5, 13:30 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2022-21882CVE-2021-1732CVE-2022-1732160
Adobe Fix for CVE-2011Kaspersky Securelist·Mar 22, 17:07 UTC · Mar 22, 2011Exploit / PoCCVE-2011-060960
Macro Intruders: Sneaking Past Office DefensesCisco Talos·Aug 2, 13:42 UTC · Aug 2, 2016Exploit / PoC in the wild60
NATO tests its hand defending against blended cyberCyberScoop·Apr 19, 18:55 UTC · Apr 19, 2021Exploit / PoC in the wild60
ONCD releases report on the adoption of memoryCyberScoop·Feb 26, 19:43 UTC · Feb 26, 2024Exploit / PoC in the wild60