Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attackArs Technica · Security·Dec 6, 15:02 UTC · Dec 6, 2023Exploit / PoC60
ESET detailed a flaw that could allow a bypass of the Secure Boot in UEFI systemsSecurity Affairs·Jan 17, 11:15 UTC · Jan 17, 2025Exploit / PoCCVE-2024-7344CVE-2022-3430250
ESET researchers analyze first UEFI bootkit for Linux systemsHelp Net Security·Nov 27, 00:00 UTC · Nov 27, 2024Exploit / PoC57
Rare case of UEFI hacking hit targets interested in North Korea, Kaspersky saysCyberScoop·Oct 6, 14:47 UTC · Oct 6, 2020Exploit / PoC in the wild60
BootKitty Linux UEFI bootkit spotted exploiting LogoFAIL flawsSecurity Affairs·Dec 3, 08:11 UTC · Dec 3, 2024Exploit / PoCCVE-2023-4023850
Three flaws allow attackers to bypass UEFI Secure Boot featureSecurity Affairs·Aug 13, 09:39 UTC · Aug 13, 2022Exploit / PoCCVE-2022-34301CVE-2022-34302CVE-2022-3430360
Found on VirusTotal: The world’s first UEFI bootkit for LinuxArs Technica · Security·Nov 27, 19:21 UTC · Nov 27, 2024Exploit / PoC145
New Bootkit “Bootkitty” Targets Linux Systems via UEFIInfosecurity Magazine·Nov 27, 16:30 UTC · Nov 27, 2024Exploit / PoC60
ReFirm Labs releases updates to its Centrifuge PlatformHelp Net Security·Apr 26, 00:00 UTC · Apr 26, 2019Exploit / PoC60
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
Microsoft Fixes Another Two Actively Exploited ZeroInfosecurity Magazine·Feb 12, 09:45 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2025-21391CVE-2025-21418CVE-2025-21194+1 CVEs60
IT threat evolution Q3 2021Kaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021Exploit / PoCCVE-2021-4044460
WikiLeaks publishes MacBook, iPhone hacking toolkit supposedly used by CIACyberScoop·Mar 24, 13:24 UTC · Mar 24, 2017Exploit / PoC in the wild60
Microsoft Releases RecordSecurity Affairs·Jun 9, 22:56 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-41091CVE-2026-45657CVE-2026-47291+5 CVEs160
Three ZeroInfosecurity Magazine·Jan 14, 10:45 UTC · Jan 14, 2026Exploit / PoC in the wildCVE-2026-20805CVE-2026-21265CVE-2023-3109660
Chrome Zero-Day Exploited to Deliver Italian Memento Labs' LeetAgent SpywareThe Hacker News·Nov 3, 17:57 UTC · Nov 3, 2025Exploit / PoC in the wildCVE-2025-2783160
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, DThe Hacker News·Jun 27, 05:06 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2024-54085CVE-2024-0769CVE-2019-669360
Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053)Help Net Security·Jun 16, 13:26 UTC · Jun 16, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-33073CVE-2025-33070+6 CVEs60
Sophos mounted counter-offensive operation to foil Chinese attackersHelp Net Security·Oct 31, 00:00 UTC · Oct 31, 2024Exploit / PoC in the wildCVE-2022-104060
Microsoft patches two actively exploited zero-days (CVE-2024-29988, CVE-2024-26234)Help Net Security·Apr 9, 00:00 UTC · Apr 9, 2024Exploit / PoC in the wildCVE-2024-29988CVE-2024-26234CVE-2024-21412+9 CVEs60
KeePass Flaw Exposes Master PasswordsInfosecurity Magazine·May 19, 17:00 UTC · May 19, 2023Exploit / PoCCVE-2023-3278450
How an NSA researcher plans to allow everyone to guard against firmware attacksCyberScoop·Aug 23, 21:17 UTC · Aug 23, 2019Exploit / PoC in the wild60
IT threat evolution Q1 2019Kaspersky Securelist·May 23, 10:00 UTC · May 23, 2019Exploit / PoCCVE-2019-0797CVE-2018-858960