Patch, track, repeat: The 2025 CVE retrospectiveCisco Talos·Mar 5, 19:00 UTC · Mar 5, 2026Vulnerability in the wildCVE-2026-2138560
Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public ZeroThe Hacker News·Mar 11, 09:15 UTC · Mar 11, 2026VulnerabilityCVE-2026-26127CVE-2026-21262CVE-2026-21536+3 CVEs60
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply ChainThe Hacker News·Apr 22, 05:41 UTC · Apr 22, 2026VulnerabilityCVE-2025-65720CVE-2026-30623CVE-2026-30624+12 CVEs160
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ DownloadsThe Hacker News·Jul 11, 04:05 UTC · Jul 11, 2025VulnerabilityCVE-2025-6514CVE-2025-49596CVE-2025-53110+1 CVEs60
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post ApprovalThe Hacker News·Aug 5, 13:04 UTC · Aug 5, 2025VulnerabilityCVE-2025-54136160
Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking DataThe Hacker News·Apr 16, 15:50 UTC · Apr 16, 2026VulnerabilityCVE-2025-59145160
Critical Vulnerability in Anthropic's MCP Exposes Developer Machines to Remote ExploitsThe Hacker News·Jul 4, 09:23 UTC · Jul 4, 2025VulnerabilityCVE-2025-4959660
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryThe Hacker News·Jul 29, 15:39 UTC · Jul 29, 2026VulnerabilityCVE-2026-59726160
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2026Vulnerability in the wildCVE-2026-0257CVE-2026-41089CVE-2025-48595+1 CVEs60
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 CrossThe Hacker News·Aug 5, 14:27 UTC · Aug 5, 2026Vulnerability in the wildCVE-2026-58073CVE-2026-58072CVE-2026-58067+10 CVEs160
CVE-2026-33032: severe nginx-ui bug grants unauthenticated server accessSecurity Affairs·Apr 15, 18:17 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-3303260
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances ExposedThe Hacker News·Apr 7, 05:56 UTC · Apr 7, 2026Vulnerability in the wildCVE-2025-59528CVE-2025-8943CVE-2025-2631960
Microsoft Patch Tuesday for March 2026 — Snort rules and prominent vulnerabilitiesCisco Talos·Mar 10, 22:23 UTC · Mar 10, 2026VulnerabilityCVE-2026-26110CVE-2026-26113CVE-2026-26144+14 CVEs60
Untrusted repositories turn Claude code into an attack vectorSecurity Affairs·Feb 25, 21:39 UTC · Feb 25, 2026VulnerabilityCVE-2025-59536CVE-2026-2185260
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHubThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Vulnerability in the wildCVE-2018-15133CVE-2024-5555660
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security·May 17, 00:00 UTC · May 17, 2026Vulnerability in the wildCVE-2026-44413CVE-2026-41940CVE-2026-46300+2 CVEs160
More than half of public vulnerabilities bypass leading WAFsHelp Net Security·Feb 18, 05:11 UTC · Feb 18, 2026VulnerabilityCVE-2025-5518260
Microsoft Patch Tuesday addresses 81 vulnerabilities, none actively exploitedCyberScoop·Sep 9, 21:21 UTC · Sep 9, 2025Vulnerability in the wildCVE-2025-55232CVE-2025-54918CVE-2025-5523460
Wireless vulnerabilities are doubling every few yearsHelp Net Security·Jun 19, 12:05 UTC · Jun 19, 2026VulnerabilityCVE-2025-36911CVE-2025-20631CVE-2025-20753+1 CVEs60
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More StoriesThe Hacker News·Jan 19, 06:25 UTC · Jan 19, 2026VulnerabilityCVE-2025-62507CVE-2025-23304CVE-2026-22584160
Patch it up: Old vulnerabilities are everyone’s problemsCisco Talos·Mar 13, 18:04 UTC · Mar 13, 2025Vulnerability in the wildCVE-2025-22224CVE-2024-457760
The vulnerability landscape in Q1 2026Kaspersky Securelist·May 7, 08:42 UTC · May 7, 2026VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+10 CVEs60
Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare OrganizationPalo Alto Unit 42·Jun 5, 23:27 UTC · Jun 5, 2024VulnerabilityCVE-2019-12255CVE-2019-12264CVE-2016-9355+7 CVEs160
3 flaws in Nagios IT Monitoring Software pose serious risk to orgsSecurity Affairs·May 24, 14:02 UTC · May 24, 2021VulnerabilityCVE-2020-28903CVE-2020-28905CVE-2020-28902+10 CVEs60
A vehicle's head unit hacked via its modemKaspersky Securelist·Dec 16, 10:00 UTC · Dec 16, 2025VulnerabilityCVE-2024-39432CVE-2024-3943160
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
How do I select an API security solution for my business?Help Net Security·Feb 17, 00:00 UTC · Feb 17, 2022Vulnerability in the wild60
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621160
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security·Jul 5, 00:00 UTC · Jul 5, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-48558CVE-2026-4681760
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60