Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft's Disclosure ProcessSecurity Affairs·Jun 4, 09:13 UTC · Jun 4, 2026Exploit / PoC in the wild160
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
Experts published unpatched Windows zero-day BlueHammerSecurity Affairs·Apr 7, 08:10 UTC · Apr 7, 2026Exploit / PoC160
Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026Help Net Security·Feb 11, 00:00 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21513CVE-2026-21514CVE-2026-21510+3 CVEs160
Finding Azurescape – Cross-Account Container Takeover in Azure Container InstancesPalo Alto Unit 42·Jun 6, 01:32 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2019-5736CVE-2018-1002102160
ChaosDB, a Critical Cosmos DB flaw affected thousands of Microsoft Azure CustomersSecurity Affairs·Aug 27, 17:36 UTC · Aug 27, 2021Exploit / PoC60
Microsoft Confirms RoguePlanet ZeroSecurity Affairs·Jun 18, 09:21 UTC · Jun 18, 2026Exploit / PoCCVE-2026-50656CVE-2026-33825CVE-2026-45498+1 CVEs60
Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656)Help Net Security·Jun 17, 00:00 UTC · Jun 17, 2026Exploit / PoCCVE-2026-50656160
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of ResearchSecurity Affairs·Jun 11, 10:58 UTC · Jun 11, 2026Exploit / PoCCVE-2026-33825CVE-2026-45498CVE-2026-41091160
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsThe Hacker News·Jun 10, 17:30 UTC · Jun 10, 2026Exploit / PoC in the wildCVE-2026-33825CVE-2026-45498CVE-2026-41091160
Microsoft says it will not pursue security researchers after zeroThe Record·Jun 1, 12:14 UTC · Jun 1, 2026Exploit / PoC60
Russia-linked APT28 exploited MSHTML zero-day CVE-2026Security Affairs·Mar 2, 14:46 UTC · Mar 2, 2026Exploit / PoCCVE-2026-2151360
Microsoft reveals actively exploited Office zero-day, provides emergency fix (CVE-2026-21509)Help Net Security·Feb 3, 18:36 UTC · Feb 3, 2026Exploit / PoC in the wildCVE-2026-2150960
Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active ExploitationThe Hacker News·Jan 27, 10:37 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2026-21509160
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs160
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
New Chrome zero-day actively exploited, patch quickly! (CVE-2024-7971)Help Net Security·Sep 19, 11:32 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-796560
North Korea-linked APT Citrine Sleet exploit Chrome zero-day to deliver FudModule rootkitSecurity Affairs·Aug 31, 18:22 UTC · Aug 31, 2024Exploit / PoCCVE-2024-7971CVE-2024-3810660
Google addressed the ninth actively exploited Chrome zeroSecurity Affairs·Aug 26, 22:50 UTC · Aug 26, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-0519CVE-2024-2887+6 CVEs60
Google Fixes High-Severity Chrome Flaw Actively Exploited in the WildThe Hacker News·Aug 23, 10:01 UTC · Aug 23, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-4947CVE-2024-5274+6 CVEs160
Microsoft launched its new Microsoft Defender Bounty ProgramSecurity Affairs·Nov 24, 19:49 UTC · Nov 24, 2023Exploit / PoC160
Microsoft Releases Fix for Zero-Day Flaw in July 2022 Security Patch RolloutThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2022Exploit / PoC in the wildCVE-2022-22047CVE-2022-22026CVE-2022-22049+14 CVEs60
A flaw in Microsoft Azure App Service exposes customer source codeSecurity Affairs·Dec 23, 05:36 UTC · Dec 23, 2021Exploit / PoC in the wild160
February 2021 Patch Tuesday: Microsoft and Adobe fix exploited zero-daysHelp Net Security·Jun 8, 18:29 UTC · Jun 8, 2021Exploit / PoC in the wildCVE-2021-21017CVE-2021-1732CVE-2021-24074+6 CVEs60
Microsoft: Solorigate attackers grabbed Azure, Intune, Exchange component source codeHelp Net Security·Feb 24, 10:30 UTC · Feb 24, 2021Exploit / PoC60
SandboxEscaper released PoC code for a new Windows zeroSecurity Affairs·Dec 31, 15:16 UTC · Dec 31, 2018Exploit / PoC60