Hardcoded SSH Key in Cisco Policy Suite Lets Remote Hackers Gain Root AccessThe Hacker News·Nov 5, 06:15 UTC · Nov 5, 2021VulnerabilityCVE-2021-40119CVE-2021-34795CVE-2021-40113+3 CVEs60
Hackers patch Citrix servers to deploy their own backdoorSecurity Affairs·Jan 19, 09:32 UTC · Jan 19, 2020Vulnerability in the wildCVE-2019-1978160
New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60
‘Critical’ vulnerability found in Siemens industrial tool, allowing theft of cryptographic keysThe Record·Dec 16, 00:00 UTC · Dec 16, 2022VulnerabilityCVE-2022-3846560
WAGO Industrial Switches affected by multiple flawsSecurity Affairs·Jun 13, 21:42 UTC · Jun 13, 2019VulnerabilityCVE-2017-16544CVE-2015-0235CVE-2019-1255060
Patch now: TP-Link Archer NX routers vulnerable to firmware takeoverSecurity Affairs·Mar 25, 14:44 UTC · Mar 25, 2026Vulnerability in the wildCVE-2025-15517CVE-2025-15605CVE-2025-9377+1 CVEs60
Critical SimpleHelp vulnerabilities fixed, update your server instances!Help Net Security·May 28, 10:03 UTC · May 28, 2025VulnerabilityCVE-2024-57727CVE-2024-57728CVE-2024-5772660
First patches for the Citrix ADC, Gateway RCE flaw releasedHelp Net Security·Jan 23, 13:30 UTC · Jan 23, 2024Vulnerability in the wildCVE-2019-1978160
Cisco fixes small business routers, kills eavesdropping vulnerability in conferencing devicesHelp Net Security·Nov 10, 10:47 UTC · Nov 10, 2019Vulnerability in the wild60
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-orThe Hacker News·May 7, 17:59 UTC · May 7, 2026VulnerabilityCVE-2026-7411CVE-2026-7412CVE-2026-467060
Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE VulnerabilityThe Hacker News·Apr 21, 14:48 UTC · Apr 21, 2025Vulnerability in the wildCVE-2025-3040660
Patch this critical Safeguard for Privileged Passwords auth bypass flaw (CVE-2024-45488)Help Net Security·Sep 19, 00:00 UTC · Sep 19, 2024VulnerabilityCVE-2024-4548860
PayU Plugin Flaw Allows Account Takeover on 5000 WordPress SitesInfosecurity Magazine·Jun 9, 16:45 UTC · Jun 9, 2025VulnerabilityCVE-2025-3102260
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Power struggle: Government-funded researchers investigate vulnerabilities in EV charging stationsCyberScoop·Feb 25, 16:36 UTC · Feb 25, 2019Vulnerability in the wild60
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from OctoberRecorded Future·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability in the wildCVE-2025-64446CVE-2025-58034CVE-2025-21042+1 CVEs60
miniOrange’s WordPress Social Login and Register plugin affected by a critical auth bypassSecurity Affairs·Jun 30, 04:03 UTC · Jun 30, 2023VulnerabilityCVE-2023-298260
Cisco warns of hard-coded credentials and default SSH key issues in some productsSecurity Affairs·Nov 4, 20:19 UTC · Nov 4, 2021VulnerabilityCVE-2021-34795CVE-2021-4011960
Expert found multiple critical issues in MoFi routersSecurity Affairs·Sep 8, 15:13 UTC · Sep 8, 2020VulnerabilityCVE-2020-15835CVE-2020-1583660
MDhex vulnerabilities open GE Healthcare patient monitoring devices to attackersHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2020VulnerabilityCVE-2020-6961CVE-2020-6962CVE-2020-6963+3 CVEs60
Auto-Color Backdoor Malware Exploits SAP VulnerabilityInfosecurity Magazine·Jul 29, 15:10 UTC · Jul 29, 2025VulnerabilityCVE-2025-3132460
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a PasswordSecurity Affairs·Jun 1, 11:36 UTC · Jun 1, 2026Vulnerability in the wildCVE-2026-873260
RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)Help Net Security·Apr 14, 16:25 UTC · Apr 14, 2025Vulnerability in the wildCVE-2025-30406CVE-2025-3116160
Exposed training apps are showing up in active cloud attacksHelp Net Security·Jan 22, 00:00 UTC · Jan 22, 2026Vulnerability in the wild60
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistantKaspersky Securelist·May 29, 07:00 UTC · May 29, 2026VulnerabilityCVE-2025-55182CVE-2023-4911CVE-2021-4034+3 CVEs60