Windows 11 to Deprecate NTLM, Add AI-Powered App Controls and Security DefensesThe Hacker News·Jun 6, 09:16 UTC · Jun 6, 2024Exploit / PoC60
A flaw could allow recovery of the phone number associated with any Google accountSecurity Affairs·Jun 11, 07:06 UTC · Jun 11, 2025Exploit / PoC45
NIST wants agencies to move away from SMS authenticationCyberScoop·Jul 31, 19:29 UTC · Jul 31, 2016Exploit / PoC in the wild60
New attack sounds death knell for widely used SHA-1 crypto hash functionHelp Net Security·Nov 8, 07:47 UTC · Nov 8, 2019Exploit / PoC45
ROBOT Attack: RSA TLS crypto attack worked against Facebook, PayPal, and tens of 100 top domainsSecurity Affairs·Dec 13, 16:19 UTC · Dec 13, 2017Exploit / PoCCVE-2017-6168CVE-2017-17382CVE-2017-17427+6 CVEs60
Check Point Warns Critical Auth Bypass Bug Exploited in the WildInfosecurity Magazine·Jun 9, 09:30 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-50751CVE-2026-5075260
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
Invisible text that AI chatbots understand and humans can’t? Yep, it’s a thing.Ars Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2024Exploit / PoC145
Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)Help Net Security·Oct 8, 00:00 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-38112+3 CVEs60
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensThe Hacker News·Aug 8, 08:03 UTC · Aug 8, 2026Exploit / PoC45
U.S. CISA adds BerriAI LiteLLM and Check Point Security Gateway flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 9, 08:13 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-42271CVE-2026-5075160
Android 17 Beta Introduces Secure-ByInfosecurity Magazine·Feb 17, 16:00 UTC · Feb 17, 2026Exploit / PoC in the wild60
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
NIST officials detail impact of staff cuts on encryption and other prioritiesCyberScoop·Jan 22, 01:14 UTC · Jan 22, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
Experts uncover critical flaws in Kigen eSIM affecting billionsSecurity Affairs·Jul 14, 11:09 UTC · Jul 14, 2025Exploit / PoC60
Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053)Help Net Security·Jun 16, 13:26 UTC · Jun 16, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-33073CVE-2025-33070+6 CVEs60
Researchers Find Exploit Allowing NTLMv1 Despite Active Directory RestrictionsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Exploit / PoC in the wild60
Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilitiesCisco Talos·Oct 8, 19:04 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+10 CVEs60
Fortra fixed 2 severe issues in FileCatalyst Workflow, including a critical flawSecurity Affairs·Aug 30, 19:47 UTC · Aug 30, 2024Exploit / PoC in the wildCVE-2024-6633CVE-2024-663260
Microsoft fixes 6 zero-days under active attackHelp Net Security·Aug 15, 07:12 UTC · Aug 15, 2024Exploit / PoC in the wildCVE-2024-38178CVE-2024-38106CVE-2024-38107+10 CVEs60
Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation MethodologiesPalo Alto Unit 42·Jun 5, 13:30 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2022-21882CVE-2021-1732CVE-2022-1732160
Hands-on Review: Myrror Security Code-Aware and AttackThe Hacker News·Feb 17, 07:01 UTC · Feb 17, 2024Exploit / PoC60
Critical Zero-Day in Apache OfBiz ERP System Exposes Businesses to AttackThe Hacker News·Jan 9, 06:04 UTC · Jan 9, 2024Exploit / PoC in the wildCVE-2023-51467CVE-2023-4907060
Adobe patches newly exploited Flash zero-dayHelp Net Security·Dec 15, 12:35 UTC · Dec 15, 2023Exploit / PoC in the wildCVE-2018-1598260
Microsoft fixes exploited WordPad, Skype for Business zero-days (CVE-2023-36563, CVE-2023-41763)Help Net Security·Oct 10, 00:00 UTC · Oct 10, 2023Exploit / PoC in the wildCVE-2023-36563CVE-2023-41763CVE-2023-44487+2 CVEs60
Phishers Exploit Salesforce's Email Services ZeroThe Hacker News·Aug 4, 10:16 UTC · Aug 4, 2023Exploit / PoC60
Google: A mysterious hacking group used 11 different zeroThe Record·Jan 24, 00:00 UTC · Jan 24, 2023Exploit / PoCCVE-2020-6418CVE-2020-0938CVE-2020-1020+8 CVEs60
PoC exploit accidentally leaks for dangerous Windows PrintNightmare bugThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Exploit / PoCCVE-2021-1675CVE-2020-133760
Jenkins project discloses security breach following Confluence server hackThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Exploit / PoC in the wildCVE-2021-2608460
Chrome Limits Websites' Direct Access to Private Networks for Security ReasonsThe Hacker News·Jan 18, 04:53 UTC · Jan 18, 2022Exploit / PoC in the wild60
Latest Atlassian Confluence Flaw Exploited to Breach Jenkins Project ServerThe Hacker News·Sep 7, 10:05 UTC · Sep 7, 2021Exploit / PoC in the wildCVE-2021-2608460
Trump fires CISA chief Chris Krebs, who guarded the 2020 election from interference and domestic misinformationCyberScoop·Nov 18, 03:18 UTC · Nov 18, 2020Exploit / PoC in the wild60
CoSoSys announces zero-day support, kextless agent for macOS customersHelp Net Security·Jun 22, 00:00 UTC · Jun 22, 2020Exploit / PoC60
Critical SQLite Flaw Leaves Millions of Apps Vulnerable to HackersThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2018Exploit / PoC in the wild60
The King is dead. Long live the King!Kaspersky Securelist·May 9, 06:00 UTC · May 9, 2018Exploit / PoCCVE-2016-0189CVE-2018-8174CVE-2017-0199+3 CVEs60
SHA-1 crypto algorithm is dead by collision attackCyberScoop·Feb 23, 19:17 UTC · Feb 23, 2017Exploit / PoC in the wild60
Cyber-defenders urged to use counterinsurgency playbookCyberScoop·Feb 1, 16:32 UTC · Feb 1, 2017Exploit / PoC in the wild60