⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignThe Hacker News·Jul 21, 07:41 UTC · Jul 21, 2026MalwareCVE-2025-33053CVE-2026-21513CVE-2025-24054135
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes TokensThe Hacker News·Jul 17, 17:12 UTC · Jul 17, 2026MalwareCVE-2026-39987CVE-2026-41176CVE-2022-22947+1 CVEs47
Gafgyt botnet is targeting EoL Zyxel routersSecurity Affairs·Aug 11, 08:16 UTC · Aug 11, 2023Malware in the wildCVE-2017-18368CVE-2017-1836360
Zyxel firewalls under attack by Mirai-like botnetHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2023Malware in the wildCVE-2023-28771CVE-2023-33009CVE-2023-3301060
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data ExfiltrationThe Hacker News·May 5, 14:09 UTC · May 5, 2026Malware in the wildCVE-2026-1731CVE-2024-1235660
Analyzing evolution of the PipeMagic malwareSecurity Affairs·Aug 19, 08:02 UTC · Aug 19, 2025Malware in the wildCVE-2025-29824CVE-2017-014460
Multiple malware families delivered exploiting GeoServer GeoTools flaw CVE-2024Security Affairs·Sep 9, 06:41 UTC · Sep 9, 2024Malware in the wildCVE-2024-3640160
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+23 CVEs160
Hackers Deploy Python Backdoor in Palo Alto ZeroThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2024Malware in the wildCVE-2024-3400160
Attackers are exploiting JetBrains TeamCity flaw to deliver a variety of malwareHelp Net Security·Mar 21, 00:00 UTC · Mar 21, 2024Malware in the wildCVE-2024-27198CVE-2024-2719960
CISA warns of malware deployed through Ivanti EPMM flawsSecurity Affairs·Sep 20, 14:07 UTC · Sep 20, 2025Malware in the wildCVE-2025-4427CVE-2025-4428160
BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic TrojanThe Hacker News·May 15, 00:00 UTC · May 15, 2025Malware in the wildCVE-2025-31324CVE-2025-29824CVE-2025-42999160
CISA and FBI Raise Alerts on Exploited Flaws and Expanding HiatusRAT CampaignThe Hacker News·Dec 17, 06:34 UTC · Dec 17, 2024Malware in the wildCVE-2024-20767CVE-2024-35250CVE-2017-7921+6 CVEs60
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360
Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE MalwareThe Hacker News·Apr 7, 06:39 UTC · Apr 7, 2025Malware in the wildCVE-2025-22457CVE-2024-38657CVE-2025-22467+2 CVEs60
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect SecureSecurity Affairs·Apr 25, 17:56 UTC · Apr 25, 2025Malware in the wildCVE-2025-028260
News Flodrix botnet targets vulnerable Langflow serversSecurity Affairs·Jun 18, 10:43 UTC · Jun 18, 2025Malware in the wildCVE-2025-324860
Active Mirai Botnet Variant Exploiting Zyxel Devices for DDoS AttacksThe Hacker News·Jun 2, 03:30 UTC · Jun 2, 2023Malware in the wildCVE-2023-2877160
Mirai Botnet targeting OFBiz Servers Vulnerable to Directory TraversalThe Hacker News·Aug 2, 17:14 UTC · Aug 2, 2024Malware in the wildCVE-2024-3221360
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023Help Net Security·Mar 1, 00:00 UTC · Mar 1, 2026Malware in the wildCVE-2026-25108CVE-2026-20127160
Week in review: Backdoor found in XZ utilities, weaponized iMessages, Exchange servers at riskHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2024Malware in the wildCVE-2024-3094CVE-2023-48022CVE-2023-2495560