Russia’s GRU hackers targeting misconfigured network edge devices in attacks on energy sector, Amazon saysThe Record·Dec 16, 21:50 UTC · Dec 16, 2025Exploit / PoCCVE-2022-26318CVE-2021-26084CVE-2023-22518+1 CVEs60
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain AttacksThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wild60
Automated Magecart spree hit thousands of sites via misconfigured cloud servers, RiskIQ saysCyberScoop·Jul 11, 10:00 UTC · Jul 11, 2019Exploit / PoC in the wild60
Top secret Army, NSA data found on public internet due to misconfigured AWS serverCyberScoop·Nov 28, 19:34 UTC · Nov 28, 2017Exploit / PoC in the wild60
Hundreds of thousands of voter records exposed on misconfigured server, researcher saysCyberScoop·Jul 19, 13:41 UTC · Jul 19, 2018Exploit / PoC in the wild60
Stop Your Legacy Infrastructure from Hijacking Your AI AgentsThe Hacker News·Jul 20, 06:32 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2025-2481360
Researcher Finds Five Zero-Days and 20 Misconfigurations in SalesforceInfosecurity Magazine·Jun 11, 11:30 UTC · Jun 11, 2025Exploit / PoCCVE-2025-4399CVE-2025-43700CVE-2025-43701+2 CVEs60
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
Sophos notifies data leak after a misconfiguration ......Security Affairs·Nov 26, 13:22 UTC · Nov 26, 2020Exploit / PoC in the wild60
Misconfigured server exposed half of all Brazilian taxpayer ID numbers, report saysCyberScoop·Dec 11, 20:50 UTC · Dec 11, 2018Exploit / PoC in the wild60
Top 5 Attack Surface Risks of 2022Recorded Future·Aug 25, 00:00 UTC · Aug 25, 2025Exploit / PoC in the wildCVE-2022-30190CVE-2022-3786CVE-2022-360260
⚡ THN Weekly Recap: Alerts on Zero-Day Exploits, AI Breaches, and Crypto HeistsThe Hacker News·May 6, 07:05 UTC · May 6, 2025Exploit / PoCCVE-2024-53104CVE-2024-53197CVE-2024-50302+25 CVEs60
What We Can Learn from the Capital One HackKrebs on Security·Aug 5, 17:20 UTC · Aug 5, 2019Exploit / PoC60
19.6 Billion Files Are Sitting Open on the Internet. No Password RequiredSecurity Affairs·May 28, 07:48 UTC · May 28, 2026Exploit / PoC60
Imperva introduces Serverless Protection to secure serverless computing functionsHelp Net Security·Apr 20, 08:49 UTC · Apr 20, 2026Exploit / PoC60
10 Critical Network Pentest Findings IT Teams OverlookThe Hacker News·Mar 21, 11:01 UTC · Mar 21, 2025Exploit / PoCCVE-2019-070860
Researchers Find Exploit Allowing NTLMv1 Despite Active Directory RestrictionsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Exploit / PoC in the wild60
Attackers are hijacking Jupyter notebooks to host illegal Champions League streamsCyberScoop·Nov 19, 14:00 UTC · Nov 19, 2024Exploit / PoC in the wild160
Best practices for implementing threat exposure management, reducing cyber risk exposureHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2024Exploit / PoC in the wild60
Palo Alto Networks PAN-OS 11.0 Nova protects organizations against zero-day threatsHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2022Exploit / PoC60
Mobile Devices See 466% Annual Increase in ZeroInfosecurity Magazine·Mar 15, 10:30 UTC · Mar 15, 2022Exploit / PoC60
5 Popular Web Hosting Services Found Vulnerable to Multiple FlawsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2019Exploit / PoC60
Autonomous AI-driven worm can reason its way through corporate networksHelp Net Security·Jun 3, 00:00 UTC · Jun 3, 2026Exploit / PoC in the wild60
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AIThe Hacker News·May 26, 12:07 UTC · May 26, 2026Exploit / PoC in the wild60
CISA credential leak raises alarms, and Capitol Hill demands answersCyberScoop·May 20, 14:43 UTC · May 20, 2026Exploit / PoC in the wild60
Identity discovery: The overlooked lever in strategic risk reductionHelp Net Security·Apr 29, 00:00 UTC · Apr 29, 2026Exploit / PoC60
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Hackers exploit unsecured MongoDB instances to wipe data and demand ransomSecurity Affairs·Feb 2, 15:13 UTC · Feb 2, 2026Exploit / PoC60
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
China-linked APT UAT-8837 targets North American critical infrastructureSecurity Affairs·Jan 17, 15:50 UTC · Jan 17, 2026Exploit / PoCCVE-2025-5369060
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
Wiz Uncovers Critical Access Bypass Flaw in AIThe Hacker News·Jul 30, 07:43 UTC · Jul 30, 2025Exploit / PoC in the wild60
Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry CloudThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoCCVE-2025-43697CVE-2025-43698CVE-2025-43699+3 CVEs60
ChatGPT SSRF bug quickly becomes a favorite attack vectorSecurity Affairs·Mar 18, 15:17 UTC · Mar 18, 2025Exploit / PoCCVE-2024-2756460
89% of AI-powered APIs rely on insecure authentication mechanismsHelp Net Security·Jan 30, 00:00 UTC · Jan 30, 2025Exploit / PoC60
Cybercriminals capitalize on poorly configured cloud environmentsHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2024Exploit / PoC60
Blueprint for Success: Implementing a CTEM OperationThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild60
How a $10B Enterprise Customer Drastically Increased their SaaS Security Posture with 201% ROI by Using SSPMThe Hacker News·Feb 20, 10:22 UTC · Feb 20, 2024Exploit / PoC60
API Security Flaw Found in Booking.com Allowed Full Account TakeoverInfosecurity Magazine·Mar 2, 17:30 UTC · Mar 2, 2023Exploit / PoC in the wild60
What Is Your Security Team Profile? Prevention, Detection, or Risk ManagementThe Hacker News·Sep 6, 12:03 UTC · Sep 6, 2022Exploit / PoC60