Toolkit Hidden Inside Oracle Database Evades Endpoint ToolsInfosecurity Magazine·Aug 6, 15:30 UTC · Aug 6, 2026Vulnerability55
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesThe Hacker News·Aug 6, 15:24 UTC · Aug 6, 2026VulnerabilityCVE-2025-21079CVE-2025-58486247
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM AccessThe Hacker News·Aug 6, 09:19 UTC · Aug 6, 2026Vulnerability130
Chinese Threat Actors Weaponize New Vulnerabilities in Under a DayInfosecurity Magazine·Aug 3, 15:00 UTC · Aug 3, 2026Vulnerability in the wild60
JSP webshells being dropped on unpatched PTC Windchill instancesHelp Net Security·Jul 27, 12:30 UTC · Jul 27, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-468160
New Project CAV3RN .NET Native AOT communication moduleKaspersky Securelist·Jul 22, 15:43 UTC · Jul 22, 2026Vulnerability30
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesThe Hacker News·Jul 8, 05:07 UTC · Jul 8, 2026VulnerabilityCVE-2024-42009CVE-2025-4911360
How to improve your organization's security based on compromise assessment findingsKaspersky Securelist·Jul 2, 09:00 UTC · Jul 2, 2026Vulnerability142
Why patch directives only go so farCyberScoop·Jun 25, 09:00 UTC · Jun 25, 2026Vulnerability in the wildCVE-2026-5075160
Hackers probe, exploit newly patched BeyondTrust RCE flaw (CVE-2026-1731)Help Net Security·Jun 24, 10:29 UTC · Jun 24, 2026VulnerabilityCVE-2026-1731CVE-2024-1235660
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in AprilCyberScoop·Jun 18, 14:32 UTC · Jun 18, 2026Vulnerability in the wildCVE-2026-39808CVE-2026-39813CVE-2026-2508960
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code ExecutionThe Hacker News·Jun 12, 09:50 UTC · Jun 12, 2026VulnerabilityCVE-2025-67644CVE-2026-28277CVE-2026-2702260
Attackers actively exploiting flaw(s) in Cleo file transfer software (CVE-2024-50623)Help Net Security·Jun 8, 10:32 UTC · Jun 8, 2026Vulnerability in the wildCVE-2024-5062360
Containers on fire: from container escapes to supply chain attacksKaspersky Securelist·Jun 1, 10:00 UTC · Jun 1, 2026Vulnerability in the wildCVE-2019-5736CVE-2022-0492CVE-2024-21626160
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-0300160
Three Microsoft Defender Zero-Days Actively Exploited; Two Still UnpatchedThe Hacker News·May 14, 09:15 UTC · May 14, 2026Vulnerability in the wildCVE-2026-3382560
Rushed Patches Follow Broken Embargo on Linux Kernel VulnerabilitiesInfosecurity Magazine·May 11, 14:30 UTC · May 11, 2026Vulnerability in the wildCVE-2026-31431CVE-2026-43284CVE-2026-43500160
PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News·May 7, 17:58 UTC · May 7, 2026Vulnerability in the wildCVE-2026-030060
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian NetworksThe Hacker News·Apr 27, 14:07 UTC · Apr 27, 2026Vulnerability42
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of DisclosureThe Hacker News·Apr 24, 05:28 UTC · Apr 24, 2026Vulnerability in the wildCVE-2026-3998760
CVE-2026-39987: Marimo RCE exploited in hours after disclosureSecurity Affairs·Apr 11, 09:44 UTC · Apr 11, 2026Vulnerability in the wildCVE-2026-39987CVE-2026-3301760
CISA Orders US Government to Patch Maximum Severity Cisco FlawInfosecurity Magazine·Mar 23, 10:30 UTC · Mar 23, 2026Vulnerability in the wildCVE-2026-2013160
Critical Unpatched Telnetd Flaw (CVE-2026The Hacker News·Mar 20, 15:41 UTC · Mar 20, 2026Vulnerability in the wildCVE-2026-32746CVE-2026-24061CVE-2005-046960
Critical Zero-Click Flaw in n8n Allows Full Server CompromiseInfosecurity Magazine·Mar 12, 15:28 UTC · Mar 12, 2026VulnerabilityCVE-2026-27493CVE-2026-2757760
SolarWinds Web Help Desk Exploited for RCE in MultiThe Hacker News·Mar 7, 07:03 UTC · Mar 7, 2026Vulnerability in the wildCVE-2025-40551CVE-2025-40536CVE-2025-26399+1 CVEs60
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code ExecutionThe Hacker News·Feb 18, 16:35 UTC · Feb 18, 2026VulnerabilityCVE-2026-232960
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
China-linked Amaranth-Dragon hackers target Southeast Asian governments in 2025Security Affairs·Feb 5, 10:09 UTC · Feb 5, 2026VulnerabilityCVE-2025-808847
Cybersecurity jobs available right now: May 20, 2025Help Net Security·Jan 30, 10:23 UTC · Jan 30, 2026Vulnerability30
Cybersecurity jobs available right now: June 10, 2025Help Net Security·Jan 30, 10:20 UTC · Jan 30, 2026Vulnerability55
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ StoriesThe Hacker News·Jan 24, 08:04 UTC · Jan 24, 2026Vulnerability55
React2Shell Vulnerability Actively Exploited to Deploy Linux BackdoorsThe Hacker News·Dec 17, 07:26 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-29927CVE-2025-6647860
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from OctoberRecorded Future·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability in the wildCVE-2025-64446CVE-2025-58034CVE-2025-21042+1 CVEs60
AI-Enhanced Tuoni Framework Targets Major US Real Estate FirmInfosecurity Magazine·Nov 18, 14:45 UTC · Nov 18, 2025Vulnerability30
Attackers exploited another Gladinet Triofox vulnerability (CVE-2025-12480)Help Net Security·Nov 11, 00:00 UTC · Nov 11, 2025VulnerabilityCVE-2025-12480CVE-2025-30406CVE-2025-31161+1 CVEs60
sqlmap: Open-source SQL injection and database takeover toolHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2025Vulnerability30
Two Windows vulnerabilities, one a 0Ars Technica · Security·Oct 31, 21:03 UTC · Oct 31, 2025Vulnerability in the wildCVE-2025-949160
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active ExploitationThe Hacker News·Sep 8, 14:09 UTC · Sep 8, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-30406CVE-2025-393560
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched ServersThe Hacker News·Sep 2, 04:43 UTC · Sep 2, 2025Vulnerability in the wildCVE-2025-54309CVE-2025-31161CVE-2024-404060