VS Code extensions with 125M+ installs expose users to cyberattacksSecurity Affairs·Feb 18, 15:14 UTC · Feb 18, 2026VulnerabilityCVE-2025-65715CVE-2025-65716CVE-2025-65717160
Flaws in Popular IDE Extensions Allow Data ExfiltrationInfosecurity Magazine·Feb 19, 10:45 UTC · Feb 19, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-6571560
Critical Flaws Found in Four VS Code Extensions with Over 125 Million InstallsThe Hacker News·Feb 18, 13:16 UTC · Feb 18, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-65715160
Patch Tuesday, February 2026 EditionKrebs on Security·Feb 11, 03:47 UTC · Feb 11, 2026VulnerabilityCVE-2026-21510CVE-2026-21513CVE-2026-21514+7 CVEs160
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security·Feb 15, 00:00 UTC · Feb 15, 2026Vulnerability in the wildCVE-2026-1731CVE-2024-12356CVE-2026-1281+2 CVEs60
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs160
Microsoft Patches Record 622 Flaws, Including Two ZeroThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2026-56164CVE-2026-56155CVE-2026-50661+6 CVEs60
CodeBuild Flaw Put AWS Console Supply Chain At RiskInfosecurity Magazine·Jan 15, 15:00 UTC · Jan 15, 2026Vulnerability in the wild160
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
Unpatched SolarWinds WHD instances under active attackHelp Net Security·Mar 9, 17:22 UTC · Mar 9, 2026Vulnerability in the wildCVE-2025-26399160
An XSS flaw in GitLab allows attackers to take over accountsSecurity Affairs·May 24, 20:39 UTC · May 24, 2024Vulnerability in the wildCVE-2024-4835CVE-2023-7028160
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Why Patch Management Isn’t Enough: SharePoint, Webshells & the Modern Threat LandscapeRecorded Future·Aug 11, 00:00 UTC · Aug 11, 2025VulnerabilityCVE-2023-4724660
Resolving Availability vs. Security, a Constant Conflict in ITThe Hacker News·Aug 5, 10:39 UTC · Aug 5, 2022Vulnerability in the wildCVE-2022-3162660
CUPS flaws allow remote code execution on Linux systems under certain conditionsSecurity Affairs·Sep 27, 14:00 UTC · Sep 27, 2024VulnerabilityCVE-2024-47076CVE-2024-47175CVE-2024-47176+1 CVEs60
Microsoft Patch Tuesday, May 2020 EditionKrebs on Security·May 12, 21:45 UTC · May 12, 2020VulnerabilityCVE-2020-1117CVE-2020-1126CVE-2020-1054+2 CVEs60
Synology & QNAP warn of critical Netatalk flaws in some of their productsSecurity Affairs·May 1, 14:29 UTC · May 1, 2022VulnerabilityCVE-2022-23125CVE-2022-23122CVE-2022-019460
vBulletin fixes critical vulnerability, patch immediately!Help Net Security·May 28, 10:04 UTC · May 28, 2020VulnerabilityCVE-2020-1272060
Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024The Hacker News·Feb 6, 03:49 UTC · Feb 6, 2025Vulnerability in the wildCVE-2024-53104CVE-2024-4556960
QNAP fixes OS command injection flaws affecting its NAS devices (CVE-2023-47218, CVE-2023-50358)Help Net Security·Feb 14, 00:00 UTC · Feb 14, 2024VulnerabilityCVE-2023-47218CVE-2023-50358CVE-2023-4756560
Patch Responsibility Remains Up for Grabs as AI Unearth Flaws At ScaleInfosecurity Magazine·Jun 3, 09:00 UTC · Jun 3, 2026Vulnerability in the wild60
Discovering Exchange Servers: Leveling the Field Using Attack Surface IntelligenceRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2021-2685560
Hackers are exploiting the CVE-2018-0101 CISCO ASA flaw in attacks in the wildSecurity Affairs·Feb 11, 09:57 UTC · Feb 11, 2018VulnerabilityCVE-2018-010160
QNAP Releases Firmware Patches for 9 New Flaws Affecting NAS DevicesThe Hacker News·May 9, 02:52 UTC · May 9, 2022VulnerabilityCVE-2022-27588CVE-2021-38693CVE-2021-44051+6 CVEs60
Threat and Vulnerability Management in 2026Recorded Future·Jan 14, 00:00 UTC · Jan 14, 2026Vulnerability in the wild60
China vs. U.S.: The Race in Vulnerability ReportingRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2016-5195CVE-2017-563860
Vulnerability landscape analysis for Q4 2024Kaspersky Securelist·Feb 26, 10:12 UTC · Feb 26, 2025Vulnerability in the wildCVE-2018-0802CVE-2017-11882CVE-2017-0199+8 CVEs60
New P2PInfect Worm Targeting Redis Servers on Linux and Windows SystemsThe Hacker News·Jul 31, 13:28 UTC · Jul 31, 2023VulnerabilityCVE-2022-054360
Google to remove app from Pixel devices following claims that it made phones vulnerableThe Record·Aug 15, 20:11 UTC · Aug 15, 2024Vulnerability in the wild60
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer AttacksThe Hacker News·Sep 24, 11:03 UTC · Sep 24, 2025Vulnerability in the wild60
China's Influence on National Network Vulnerability PublicationsRecorded Future·Oct 21, 00:00 UTC · Oct 21, 2025VulnerabilityCVE-2017-0199160