Researchers Uncover ECScape Flaw in Amazon ECS Enabling CrossThe Hacker News·Aug 7, 05:26 UTC · Aug 7, 2025VulnerabilityCVE-2025-156847
My Little FormBookCisco Talos·Jun 20, 15:00 UTC · Jun 20, 2018VulnerabilityCVE-2017-0199CVE-2017-1188235
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesThe Hacker News·Jul 23, 13:27 UTC · Jul 23, 2026VulnerabilityCVE-2026-4633135
ToddyCat: Keep calm and check logsKaspersky Securelist·Oct 12, 10:41 UTC · Oct 12, 2023Vulnerability42
Rublevka Team: Anatomy of a Russian Crypto Drainer OperationRecorded Future·Feb 4, 00:00 UTC · Feb 4, 2026Vulnerability30
Containers on fire: from container escapes to supply chain attacksKaspersky Securelist·Jun 1, 10:00 UTC · Jun 1, 2026Vulnerability in the wildCVE-2019-5736CVE-2022-0492CVE-2024-21626160
Container security: The seven biggest mistakes companies are makingHelp Net Security·Aug 2, 13:04 UTC · Aug 2, 2017Vulnerability42
Google Patches Quick Share Vulnerability Enabling Silent File Transfers Without ConsentThe Hacker News·Apr 3, 12:16 UTC · Apr 3, 2025VulnerabilityCVE-2024-10668CVE-2024-38271CVE-2024-3827235
AI-Generated Malicious npm Package Drains Solana Funds from 1,500+ Before TakedownThe Hacker News·Aug 1, 12:48 UTC · Aug 1, 2025Vulnerability42
IoC Scanner shows if Citrix appliances have been compromised via CVE-2019-19781Help Net Security·Jan 23, 00:00 UTC · Jan 23, 2020VulnerabilityCVE-2019-1978135
Automotive companies are warming up to vulnerability disclosure programsCyberScoop·Jul 25, 15:15 UTC · Jul 25, 2018Vulnerability55
DirtyClone: A Linux Privilege Escalation That Leaves No Trace on DiskSecurity Affairs·Jun 27, 09:12 UTC · Jun 27, 2026VulnerabilityCVE-2026-43503CVE-2026-31431CVE-2026-43284+2 CVEs35
Unpatched Wordpress Flaw Could Allow Hackers To Reset Admin PasswordThe Hacker News·May 4, 18:50 UTC · May 4, 2017VulnerabilityCVE-2017-829560
Amazon Aurora Serverless v2 removes the complexity of managing database capacityHelp Net Security·Apr 20, 08:42 UTC · Apr 20, 2026Vulnerability30
Server-side attacks, C&C in public clouds and other MDR cases we observedKaspersky Securelist·Nov 2, 08:00 UTC · Nov 2, 2022Vulnerability30
Meet Fractal, an OS made for microarchitecture reverse engineeringHelp Net Security·May 22, 00:00 UTC · May 22, 2026Vulnerability130
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned PacketsThe Hacker News·Jun 26, 13:40 UTC · Jun 26, 2026VulnerabilityCVE-2026-43503CVE-2026-31431CVE-2026-43284+2 CVEs35
VMware Patches Severe Security Flaws in Workstation and Fusion ProductsThe Hacker News·May 15, 00:00 UTC · May 15, 2024VulnerabilityCVE-2024-22267CVE-2024-22268CVE-2024-22269+3 CVEs60
Week in review: Security Onion 2.4 released, WinRAR vulnerable to RCEHelp Net Security·Aug 27, 00:00 UTC · Aug 27, 2023VulnerabilityCVE-2022-47966CVE-2023-40477CVE-2023-36844+5 CVEs160
VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixesHelp Net Security·Apr 21, 00:00 UTC · Apr 21, 2026Vulnerability30
Microsoft warns of attacks exploiting recently patched Windows MSHTML CVE-2021Security Affairs·Nov 25, 12:13 UTC · Nov 25, 2021Vulnerability in the wildCVE-2021-40444260
Using virtualization to isolate risky applications and other endpoint threatsHelp Net Security·Jun 14, 11:08 UTC · Jun 14, 2022Vulnerability42
Crooks bypass a Microsoft Office patch for CVE-2021Security Affairs·Dec 23, 14:49 UTC · Dec 23, 2021VulnerabilityCVE-2021-40444147
CVE-2021-40444 exploitation: Researchers find connections to previous attacksHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2021VulnerabilityCVE-2021-4044460
ServiceNow Patches Critical AI Platform Flaw Allowing Unauthenticated User ImpersonationThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-1242060
Bad Certificate Management in Google Play StorePalo Alto Unit 42·Nov 1, 09:35 UTC · Nov 1, 2018Vulnerability55
Friday Squid Blogging: Flying SquidSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Vulnerability130
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary CodeThe Hacker News·Jun 9, 05:51 UTC · Jun 9, 2026Vulnerability155
Lessons from a 40-year-long automotive OEM leaderHelp Net Security·Aug 16, 14:00 UTC · Aug 16, 2023Vulnerability55
Apple paid a $50K bounty to two bug bounty hunters for hacking its hostsSecurity Affairs·Jan 18, 16:59 UTC · Jan 18, 2021Vulnerability55
Zoom Bug Could Have Let Uninvited People Join Private MeetingsThe Hacker News·Jan 28, 16:08 UTC · Jan 28, 2020Vulnerability30
Inception Attackers Target Europe with YearPalo Alto Unit 42·Mar 19, 16:47 UTC · Mar 19, 2019VulnerabilityCVE-2017-11882CVE-2012-185647
Malicious Tor Browser spreads through YouTubeKaspersky Securelist·Oct 4, 10:00 UTC · Oct 4, 2022Vulnerability30
Threat Source newsletter for Sept. 10, 2020Cisco Talos·Sep 10, 18:00 UTC · Sep 10, 2020VulnerabilityCVE-2020-0922160
New HawkEye Reborn Variant Emerges Following Ownership ChangeCisco Talos·Apr 15, 16:37 UTC · Apr 15, 2019VulnerabilityCVE-2017-1188235
Russia-Nexus UAC-0113 Emulating Telecommunication Providers in UkraineRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Vulnerability42
Critical cPanel Authentication Vulnerability Identified — Update Your Server ImmediatelyThe Hacker News·May 4, 16:03 UTC · May 4, 2026Vulnerability in the wildCVE-2026-4194060
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS AttacksThe Hacker News·Jun 21, 09:10 UTC · Jun 21, 2025Vulnerability in the wildCVE-2025-324860
AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege EscalationPalo Alto Unit 42·Jun 5, 22:41 UTC · Jun 5, 2024VulnerabilityCVE-2021-3100CVE-2021-3101CVE-2022-0070+2 CVEs47
Federal agencies must patch cPanel bug by Sunday, CISA saysThe Record·May 1, 16:25 UTC · May 1, 2026VulnerabilityCVE-2026-4194060