Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoSThe Hacker News·Jun 10, 05:08 UTC · Jun 10, 2026VulnerabilityCVE-2026-44289CVE-2026-44290CVE-2026-44291+3 CVEs47
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
Git vulnerability leading to RCE is being exploited by attackers (CVE-2025-48384)Help Net Security·Aug 26, 00:00 UTC · Aug 26, 2025Vulnerability in the wildCVE-2025-4838460
Shell No! Adversary Web Shell Trends and Mitigations (Part 1)Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Over 70 Malicious npm and VS Code Packages Found Stealing Data and CryptoThe Hacker News·May 26, 15:12 UTC · May 26, 2025Vulnerability55
NCSC Urges Users to Patch Next.js Flaw ImmediatelyInfosecurity Magazine·Mar 31, 10:15 UTC · Mar 31, 2025VulnerabilityCVE-2025-2992760
Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization ChecksThe Hacker News·Mar 25, 03:16 UTC · Mar 25, 2025VulnerabilityCVE-2025-2992760
Chinese APT Weaver Ant infiltrated a telco for over four yearsSecurity Affairs·Mar 24, 20:36 UTC · Mar 24, 2025Vulnerability55
Wireshark 4.4.2: Security updates, bug fixes, updated protocol supportHelp Net Security·Jan 9, 08:56 UTC · Jan 9, 2025Vulnerability30
Cybersecurity jobs available right now: October 9, 2024Help Net Security·Dec 5, 12:13 UTC · Dec 5, 2024Vulnerability55
Chinese Actor SecShow Conducts Massive DNS Probing on Global ScaleThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2024VulnerabilityCVE-2023-2571735
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by FirefoxThe Hacker News·May 21, 10:22 UTC · May 21, 2024VulnerabilityCVE-2024-34359CVE-2024-4367160
New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 ProtectionsThe Hacker News·Jan 3, 06:35 UTC · Jan 3, 2024Vulnerability55
DIY attack surface management: Simple, cost-effective and actionable perimeter insightsHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2023Vulnerability42
Collide+Power, Downfall, and Inception: New SideThe Hacker News·Aug 10, 08:33 UTC · Aug 10, 2023VulnerabilityCVE-2023-20583CVE-2022-40982CVE-2023-20569+3 CVEs60
A key post-quantum algorithm may be vulnerable to sideThe Record·Mar 27, 00:00 UTC · Mar 27, 2023Vulnerability30
Experts Discover Flaw in U.S. Govt's Chosen QuantumThe Hacker News·Mar 10, 13:28 UTC · Mar 10, 2023Vulnerability30
EU wants to build its own DNS infrastructure with builtThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Vulnerability30
Unpatched Microsoft Exchange ZeroSecurity Affairs·Sep 30, 07:25 UTC · Sep 30, 2022Vulnerability in the wild60
A 15-Year-Old Unpatched Python bug potentially impacts +350K projectsSecurity Affairs·Sep 22, 13:28 UTC · Sep 22, 2022VulnerabilityCVE-2007-4559CVE-2001-1267160
Halo Security launches attack surface management platform to protect data from external attackersHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2022Vulnerability30
CISA Urges Organizations to Patch Actively Exploited F5 BIGThe Hacker News·May 12, 13:47 UTC · May 12, 2022Vulnerability in the wildCVE-2022-138860
CVE-2021-44731 Linux privilege escalation bug affects Canonical's Snap Package ManagerSecurity Affairs·Feb 18, 09:54 UTC · Feb 18, 2022VulnerabilityCVE-2021-44731CVE-2021-44730CVE-2021-3996+4 CVEs135
New Linux Privilege Escalation Flaw Uncovered in Snap Package ManagerThe Hacker News·Feb 18, 08:37 UTC · Feb 18, 2022VulnerabilityCVE-2021-44731CVE-2021-3995CVE-2021-3996+4 CVEs60
CVE-2021-44228 vulnerability in Apache Log4j libraryKaspersky Securelist·Dec 13, 14:10 UTC · Dec 13, 2021Vulnerability in the wildCVE-2021-44228CVE-2021-4504660
ReversingLabs announces REVERSING2021 software supply chain virtual roadshowHelp Net Security·May 17, 00:00 UTC · May 17, 2021Vulnerability55
TsuNAME flaw exposes DNS servers to DDoS AttacksSecurity Affairs·May 9, 07:58 UTC · May 9, 2021Vulnerability30
A Set of Severe Flaws Affect Popular DNSMasq DNS ForwarderThe Hacker News·Apr 13, 11:28 UTC · Apr 13, 2021VulnerabilityCVE-2020-25684CVE-2020-25685CVE-2020-2568660
Vulnerability Spotlight: Internet Systems Consortium BIND server DoSCisco Talos·Aug 20, 19:18 UTC · Aug 20, 2020Vulnerability in the wildCVE-2020-862060
On the path to Zero Trust security: Time to get startedHelp Net Security·May 20, 00:00 UTC · May 20, 2019Vulnerability30
Vulnerability Spotlight: Multiple Vulnerabilities in CUJO Smart Firewall, Das UCisco Talos·Mar 19, 15:00 UTC · Mar 19, 2019VulnerabilityCVE-2018-3963CVE-2018-396847
36-Year-Old SCP Clients' Implementation Flaws DiscoveredThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2019VulnerabilityCVE-2018-20685CVE-2019-6111CVE-2019-6109+1 CVEs35
MikroTik routers with default credentials can be easily compromisedHelp Net Security·Oct 8, 00:00 UTC · Oct 8, 2018VulnerabilityCVE-2018-1156CVE-2018-1157CVE-2018-1158+2 CVEs47
New tactics subvert traditional security measures and strike organizations of all sizesHelp Net Security·Sep 26, 00:00 UTC · Sep 26, 2018Vulnerability55
Dyn DDoS attack post-mortem: Users inadvertently helpedHelp Net Security·Jun 26, 21:25 UTC · Jun 26, 2018Vulnerability42
CVE-2018-11235 flaw in Git can lead to arbitrary code executionSecurity Affairs·May 30, 12:31 UTC · May 30, 2018VulnerabilityCVE-2018-11235CVE-2018-11233147