⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & MoreThe Hacker News·Dec 6, 11:14 UTC · Dec 6, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-38352CVE-2025-48543+25 CVEs160
Spam report: June 2010Kaspersky Securelist·Jul 21, 17:08 UTC · Jul 21, 2010Vulnerability in the wild60
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager BackdoorThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-41940160
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-orThe Hacker News·May 7, 17:59 UTC · May 7, 2026VulnerabilityCVE-2026-7411CVE-2026-7412CVE-2026-467060
CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instancesSecurity Affairs·Mar 1, 10:01 UTC · Mar 1, 2026Vulnerability in the wildCVE-2025-6432860
Edge systems take the brunt of internet-wide exploitation attemptsHelp Net Security·Feb 25, 00:00 UTC · Feb 25, 2026Vulnerability in the wildCVE-2020-2034CVE-2025-5518260
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full ControlThe Hacker News·Jan 8, 09:26 UTC · Jan 8, 2026VulnerabilityCVE-2026-21858CVE-2025-68613CVE-2025-68668+1 CVEs60
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & MoreThe Hacker News·Dec 27, 07:49 UTC · Dec 27, 2025VulnerabilityCVE-2025-20393CVE-2025-40602CVE-2025-23006+22 CVEs160
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of InstancesThe Hacker News·Dec 24, 06:21 UTC · Dec 24, 2025VulnerabilityCVE-2025-6861360
CISA Adds Actively Exploited XSS Bug CVE-2021The Hacker News·Dec 4, 04:57 UTC · Dec 4, 2025Vulnerability in the wildCVE-2021-26829CVE-2021-26828160
Scanning Activity on Palo Alto Networks Portals Jump 500% in One DayThe Hacker News·Oct 10, 14:03 UTC · Oct 10, 2025VulnerabilityCVE-2025-20333CVE-2025-2036260
Week in review: Several companies affected by the Salesloft Drift breach, Sitecore 0-day vulnerabilityHelp Net Security·Sep 7, 00:00 UTC · Sep 7, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-24204CVE-2025-48543+2 CVEs60
Erlang/OTP SSH Vulnerability Sees Spike in Exploitation AttemptsInfosecurity Magazine·Aug 13, 16:45 UTC · Aug 13, 2025Vulnerability in the wildCVE-2025-3243360
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT FirewallsThe Hacker News·Aug 11, 15:08 UTC · Aug 11, 2025Vulnerability in the wildCVE-2025-3243360
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch MiraiThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2025VulnerabilityCVE-2025-24016CVE-2023-1389CVE-2017-17215+3 CVEs160
Ballista Botnet Exploits Unpatched TP-Link Vulnerability, Targets Over 6,000 DevicesThe Hacker News·Mar 12, 03:46 UTC · Mar 12, 2025Vulnerability in the wildCVE-2023-138960
Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF InjectionThe Hacker News·Jan 9, 10:29 UTC · Jan 9, 2025Vulnerability in the wildCVE-2024-5287560
Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access ToolsThe Hacker News·Dec 20, 06:30 UTC · Dec 20, 2024VulnerabilityCVE-2023-4878860
Cloudflare Thwarts Largest-Ever 3.8 Tbps DDoS Attack Targeting Global SectorsThe Hacker News·Oct 5, 04:36 UTC · Oct 5, 2024VulnerabilityCVE-2024-3080CVE-2024-4717660
Cloudflare mitigated new recordSecurity Affairs·Oct 3, 13:01 UTC · Oct 3, 2024VulnerabilityCVE-2024-308060
GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet MalwareThe Hacker News·Sep 8, 07:56 UTC · Sep 8, 2024Vulnerability in the wildCVE-2024-36401CVE-2021-20123CVE-2021-2012460
PHP Vulnerability Exploited to Spread Malware and Launch DDoS AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024VulnerabilityCVE-2024-457760
Critical Fortinet FortiOS bug CVE-2024-21762 potentially impact 150,000 internetSecurity Affairs·Mar 12, 14:56 UTC · Mar 12, 2024Vulnerability in the wildCVE-2024-2176260
~40,000 Attacks in 3 Days: Critical Confluence RCE Under Active ExploitationThe Hacker News·Jan 23, 10:00 UTC · Jan 23, 2024Vulnerability in the wildCVE-2023-2252760
U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM VulnerabilityThe Hacker News·Jan 20, 04:42 UTC · Jan 20, 2024Vulnerability in the wildCVE-2023-35082CVE-2023-35078CVE-2023-35081+2 CVEs60
Cacti Servers Under Attack as Majority Fail to Patch Critical VulnerabilityThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2023Vulnerability in the wildCVE-2022-46169CVE-2023-2295260
Unpatched GPS Tracker Bugs Could Let Attackers Disrupt Vehicles RemotelyThe Hacker News·Jul 20, 09:44 UTC · Jul 20, 2022VulnerabilityCVE-2022-2107CVE-2022-2141CVE-2022-2199+2 CVEs60
New Local Attack Vector Expands the Attack Surface of Log4j VulnerabilityThe Hacker News·Dec 20, 05:03 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-44228+1 CVEs60
CVE-2021-44228 vulnerability in Apache Log4j libraryKaspersky Securelist·Dec 13, 14:10 UTC · Dec 13, 2021Vulnerability in the wildCVE-2021-44228CVE-2021-4504660
Over 300,000 MikroTik Devices Found Vulnerable to Remote Hacking BugsThe Hacker News·Dec 10, 11:53 UTC · Dec 10, 2021VulnerabilityCVE-2018-14847CVE-2019-3977CVE-2019-3978+3 CVEs60
Espionage group targeted hotels, governments, seized on Microsoft Exchange vulnerabilityCyberScoop·Sep 23, 09:30 UTC · Sep 23, 2021Vulnerability in the wild60
NSA Discovers New Vulnerabilities Affecting Microsoft Exchange ServersThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2021Vulnerability in the wildCVE-2021-28310CVE-2021-1732CVE-2021-28480+6 CVEs60
Over 199,500 Websites Are Still Vulnerable to Heartbleed OpenSSL BugThe Hacker News·Jan 23, 10:35 UTC · Jan 23, 2017VulnerabilityCVE-2014-016060