Malicious npm Packages Deliver Sophisticated Reverse ShellsInfosecurity Magazine·Mar 26, 13:30 UTC · Mar 26, 2025Vulnerability42
Weathering the storm: In the midst of a TyphoonCisco Talos·Feb 20, 13:00 UTC · Feb 20, 2025VulnerabilityCVE-2018-0171CVE-2023-20198CVE-2023-20273+1 CVEs47
Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect Secure and Policy SecureThe Hacker News·Jan 11, 06:31 UTC · Jan 11, 2025Vulnerability in the wildCVE-2025-0282CVE-2025-028360
Digging Inside Azure Functions: HyperV Is the Last Line of DefensePalo Alto Unit 42·Jun 5, 17:09 UTC · Jun 5, 2024Vulnerability30
Week in review: New DNS vulnerabilities, benefits of cyber threat intelligence, FBI removes web shellsHelp Net Security·Apr 18, 00:00 UTC · Apr 18, 2021Vulnerability55
Microsoft issues guidance to defend Exchange servers under attackSecurity Affairs·Jun 25, 08:12 UTC · Jun 25, 2020VulnerabilityCVE-2020-068847
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
CISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202)Help Net Security·Apr 29, 00:00 UTC · Apr 29, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513160
React2Shell Vulnerability Actively Exploited to Deploy Linux BackdoorsThe Hacker News·Dec 17, 07:26 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-29927CVE-2025-6647860
UNC6148 Backdoors Fully-Patched SonicWall SMA 100 Series Devices with OVERSTEP RootkitThe Hacker News·Jul 26, 11:34 UTC · Jul 26, 2025VulnerabilityCVE-2021-20035CVE-2021-20038CVE-2021-20039+2 CVEs60
Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy GolangThe Hacker News·May 9, 07:00 UTC · May 9, 2025VulnerabilityCVE-2025-31324160
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
An Ancient Crystal from the Sahara Reveals a Lost World of Martian Water404 Media·Nov 23, 14:00 UTC · Nov 23, 2024Vulnerability55
New Mirai Variant Targets WebSVN Command Injection Vulnerability (CVE-2021Palo Alto Unit 42·Jun 6, 12:14 UTC · Jun 6, 2024VulnerabilityCVE-2021-3230560
Kazakhstan-associated YoroTrooper disguises origin of attacks as AzerbaijanCisco Talos·Oct 25, 12:01 UTC · Oct 25, 2023Vulnerability30
Threat Roundup for September 22 to September 29Cisco Talos·Sep 29, 16:40 UTC · Sep 29, 2023Vulnerability30
Adobe ColdFusion vulnerabilities exploited to deliver web shells (CVE-2023-29298, CVE-2023-38203)Help Net Security·Jul 20, 07:53 UTC · Jul 20, 2023Vulnerability in the wildCVE-2023-29298CVE-2023-38203CVE-2023-29300+2 CVEs60
Active exploitation of the MOVEit Transfer vulnerability — CVE-2023Cisco Talos·Jun 16, 18:17 UTC · Jun 16, 2023Vulnerability in the wildCVE-2023-34362CVE-2023-35036CVE-2023-3570860
CVE-2022-41040 and CVE-2022-41082 – zeroKaspersky Securelist·Dec 19, 16:07 UTC · Dec 19, 2022VulnerabilityCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
WARNING: New Unpatched Microsoft Exchange ZeroThe Hacker News·Oct 3, 08:22 UTC · Oct 3, 2022Vulnerability in the wild60
Hackers exploited Centreon monitoring software to compromise IT providersHelp Net Security·Feb 16, 00:00 UTC · Feb 16, 2021Vulnerability42
CISCO fixed 3 critical issues in Elastic Services Controller and Ultra Services FrameworkSecurity Affairs·Jul 6, 08:22 UTC · Jul 6, 2017VulnerabilityCVE-2017-6713CVE-2017-6712CVE-2017-6711+2 CVEs60
Another Major Vulnerability Bashes SystemsCisco Talos·Sep 25, 08:55 UTC · Sep 25, 2014Vulnerability in the wildCVE-2014-627160
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's ServersThe Hacker News·Jul 24, 11:45 UTC · Jul 24, 2026VulnerabilityCVE-2026-32194CVE-2026-32191CVE-2016-3714160
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager BackdoorThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-41940160
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of DisclosureThe Hacker News·Apr 24, 05:28 UTC · Apr 24, 2026Vulnerability in the wildCVE-2026-3998760
Severe Framelink Figma MCP Vulnerability Lets Hackers Execute Code RemotelyThe Hacker News·Oct 9, 13:35 UTC · Oct 9, 2025VulnerabilityCVE-2025-5396747
UAT-7237 targets Taiwanese web hosting infrastructureCisco Talos·Aug 15, 10:00 UTC · Aug 15, 2025Vulnerability42
Hackers exploit Microsoft Defender SmartScreen bug CVE-2024-21412 to deliver ACR, Lumma, and Meduza StealersSecurity Affairs·Jul 25, 10:20 UTC · Jul 25, 2024VulnerabilityCVE-2024-21412135
Commando Cat Cryptojacking Attacks Target Misconfigured Docker InstancesThe Hacker News·Jun 7, 05:10 UTC · Jun 7, 2024VulnerabilityCVE-2018-20062CVE-2019-9082135
Threat Roundup for November 3 to November 10Cisco Talos·Nov 9, 18:32 UTC · Nov 9, 2023Vulnerability30
Atlassian Confluence bug CVE-2022-26134 exploited in cryptocurrency mining campaignSecurity Affairs·Sep 22, 11:06 UTC · Sep 22, 2022Vulnerability in the wildCVE-2022-2613460
Attackers exploit a flaw in Digium Phone sw to target VoIP serversSecurity Affairs·Jul 16, 13:14 UTC · Jul 16, 2022VulnerabilityCVE-2021-4546147
Hackers Targeting VoIP Servers By Exploiting Digium Phone SoftwareThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2022VulnerabilityCVE-2021-4546147
Experts found 14 new flaws in BusyBoxSecurity Affairs·Nov 10, 11:38 UTC · Nov 10, 2021VulnerabilityCVE-2021-42373CVE-2021-42374CVE-2021-42375+11 CVEs60
Vulnerability Spotlight: A deep dive into WAGO’s cloud connectivity and the vulnerabilities that ariseCisco Talos·Oct 21, 19:30 UTC · Oct 21, 2020VulnerabilityCVE-2019-5161CVE-2019-5155CVE-2019-5157+1 CVEs47
Friday Squid Blogging: "How the Squid Lost Its Shell"Schneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Vulnerability30
FBI issues flash alert on Apache Struts vulnerabilityCyberScoop·Oct 3, 13:15 UTC · Oct 3, 2017Vulnerability in the wildCVE-2017-563860