Disappearing bytes: Reverse engineering the MS Office RTF parserKaspersky Securelist·Feb 21, 14:00 UTC · Feb 21, 2018Exploit / PoC145
3 New Code Execution Flaws Discovered in Atlantis Word ProcessorThe Hacker News·Nov 20, 16:30 UTC · Nov 20, 2018Exploit / PoCCVE-2018-4038CVE-2018-4039CVE-2018-404060
Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian GovernmentPalo Alto Unit 42·Jan 18, 20:49 UTC · Jan 18, 2019Exploit / PoCCVE-2012-0158CVE-2014-1761150
Not Just Criminals, But Governments Were Also Using MS Word 0The Hacker News·Apr 15, 00:00 UTC · Apr 15, 2017Exploit / PoC in the wildCVE-2017-019960
Macro Intruders: Sneaking Past Office DefensesCisco Talos·Aug 2, 13:42 UTC · Aug 2, 2016Exploit / PoC in the wild60
Friday Squid Blogging: Zaqistan FlagSchneier on Security·Jul 28, 21:01 UTC · Jul 28, 2023Exploit / PoC60
North Korea exploits 0day in South's principal Word processorSecurity Affairs·Sep 16, 19:46 UTC · Sep 16, 2017Exploit / PoCCVE-2015-658560
Microsoft Copilot for Word Can Copy Hidden Prompts Into New DocumentsThe Hacker News·Jul 30, 11:54 UTC · Jul 30, 2026Exploit / PoC145
Expert released PoC code for critical Microsoft Word RCE flawSecurity Affairs·Mar 7, 15:04 UTC · Mar 7, 2023Exploit / PoCCVE-2023-21716260
New Microsoft Word zero-day used to spread 'lawful intercept' malware, analysts sayCyberScoop·Sep 12, 20:38 UTC · Sep 12, 2017Exploit / PoC in the wildCVE-2017-875960
Iran-linked hackers used Microsoft Word flaw against Israeli targets, security firm saysCyberScoop·Apr 27, 20:24 UTC · Apr 27, 2017Exploit / PoC in the wildCVE-2017-019960
The King is dead. Long live the King!Kaspersky Securelist·May 9, 06:00 UTC · May 9, 2018Exploit / PoCCVE-2016-0189CVE-2018-8174CVE-2017-0199+3 CVEs60
Under tough surveillance, China's cybercriminals find creative ways to chatCyberScoop·May 4, 13:56 UTC · May 4, 2017Exploit / PoC in the wild60
Week in review: Public MS Word RCE PoC, API exploitation, Patch Tuesday forecastHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2023Exploit / PoCCVE-2023-27532CVE-2023-25610CVE-2023-21716160
PoC exploit for recently patched Microsoft Word RCE is public (CVE-2023-21716)Help Net Security·Mar 6, 00:00 UTC · Mar 6, 2023Exploit / PoCCVE-2023-21716160
Web-based Threats-2018 Q2: U.S. Remains #1 in Malicious Web Addresses, China Falls from #2 to #7Palo Alto Unit 42·Nov 6, 12:34 UTC · Nov 6, 2018Exploit / PoCCVE-2018-8174CVE-2009-0075CVE-2008-4844+3 CVEs60
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug FlagThe Hacker News·Jun 3, 14:56 UTC · Jun 3, 2026Exploit / PoCCVE-2026-41100CVE-2026-41101CVE-2026-41102+1 CVEs150
Attack on French Diplomat Linked to Operation Lotus BlossomPalo Alto Unit 42·Nov 1, 09:57 UTC · Nov 1, 2018Exploit / PoCCVE-2014-633260
AKBuilder: A builder for exploit-laden Word documentsHelp Net Security·Jun 26, 21:24 UTC · Jun 26, 2018Exploit / PoCCVE-2012-0158CVE-2014-1761CVE-2015-164160
Google's solution to hacker name confusion? Yet another naming systemCyberScoop·Jul 27, 17:17 UTC · Jul 27, 2026Exploit / PoC60
Zero-day bug exploited by attackers via macro-less Office documents (CVE-2022-30190)Help Net Security·May 31, 00:00 UTC · May 31, 2022Exploit / PoC in the wildCVE-2022-30190CVE-2021-4044460
I know what you did last summer, MuddyWater blending in the crowdKaspersky Securelist·Apr 29, 08:00 UTC · Apr 29, 2019Exploit / PoC57
IT threat evolution Q2 2018Kaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2018Exploit / PoCCVE-2018-817460
Researchers warn of a Windows ZeroSecurity Affairs·Apr 11, 10:36 UTC · Apr 11, 2017Exploit / PoC in the wild60
MS Office zero-day exploited in attacks - no enabling of macros required!Help Net Security·Apr 10, 00:00 UTC · Apr 10, 2017Exploit / PoC60
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
Microsoft shared workarounds for the Microsoft Office Follina 0daySecurity Affairs·May 31, 11:19 UTC · May 31, 2022Exploit / PoCCVE-2022-30190160
Watch Out! Researchers Spot New Microsoft Office ZeroThe Hacker News·May 30, 15:44 UTC · May 30, 2022Exploit / PoCCVE-2021-40444160
First APT attack on Android targeted Tibetan & Uyghur activistsSecurity Affairs·May 7, 12:43 UTC · May 7, 2018Exploit / PoC60
Russia-linked hackers impersonate NATO in attempt to hack Romanian governmentCyberScoop·May 11, 14:16 UTC · May 11, 2017Exploit / PoC in the wild60
Cisco Coverage for CVE-2017Cisco Talos·Apr 14, 18:54 UTC · Apr 14, 2017Exploit / PoC in the wildCVE-2017-019960
Nvidia chips become the first GPUs to fall to Rowhammer bitArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2025Exploit / PoC45
Melting Down Grids and Warping Minds: Cyberwarfare in PracticeRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC60
Friday Squid Blogging: 2023 Squid Oil Global Market ReportSchneier on Security·Aug 4, 21:07 UTC · Aug 4, 2023Exploit / PoC45
Racial slurs discovered in leaked Yandex source codeCyberScoop·Jan 27, 19:55 UTC · Jan 27, 2023Exploit / PoC in the wild60
Microsoft published exploit code for macOS App sandbox escapeSecurity Affairs·Jul 14, 09:24 UTC · Jul 14, 2022Exploit / PoCCVE-2022-2670650
China-linked TA413 group actively exploits Microsoft Follina ZeroSecurity Affairs·Jun 1, 10:25 UTC · Jun 1, 2022Exploit / PoCCVE-2022-3019060
Chinese Hackers Begin Exploiting Latest Microsoft Office ZeroThe Hacker News·Jun 1, 10:00 UTC · Jun 1, 2022Exploit / PoC in the wildCVE-2022-30190160
Microsoft Office versions impacted by an actively exploited zeroSecurity Affairs·May 30, 12:06 UTC · May 30, 2022Exploit / PoC in the wild60