Password managers' promise that they can't see your vaults isn't always trueArs Technica · Security·Feb 17, 20:43 UTC · Feb 17, 2026Vulnerability30
A Magento breach analysis: part 1Sansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability42
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Critical Apache Guacamole Flaws Put Remote Desktops at Risk of HackingThe Hacker News·Jul 8, 07:01 UTC · Jul 8, 2020VulnerabilityCVE-2020-9497CVE-2020-949860
Review: Action1 – Simple and powerful patch managementHelp Net Security·Aug 2, 04:43 UTC · Aug 2, 2024Vulnerability in the wild60
Microsoft Patch Tuesday, March 2023 EditionKrebs on Security·Mar 15, 00:00 UTC · Mar 15, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-2488060
Patch Tuesday, May 2025 EditionKrebs on Security·May 15, 00:00 UTC · May 15, 2025Vulnerability in the wildCVE-2025-32701CVE-2025-32706CVE-2025-32709+3 CVEs60
CISA Warns of Active Exploitation of Critical Spring4Shell VulnerabilityThe Hacker News·Apr 6, 03:27 UTC · Apr 6, 2022Vulnerability in the wildCVE-2022-22965CVE-2022-22674CVE-2022-22675+1 CVEs60
North Korea-Linked Hackers Target Developers via Malicious VS Code ProjectsThe Hacker News·Feb 26, 10:15 UTC · Feb 26, 2026Vulnerability42
GOFFEE’s recent attacks: new tools and techniquesKaspersky Securelist·Apr 10, 10:00 UTC · Apr 10, 2025Vulnerability130
Hoax Email Blast Abused Poor Coding in FBI WebsiteKrebs on Security·Nov 15, 00:00 UTC · Nov 15, 2021Vulnerability55
A light December 2020 Patch Tuesday for a no-stress end of the yearHelp Net Security·Dec 8, 00:00 UTC · Dec 8, 2020Vulnerability in the wildCVE-2020-17132CVE-2020-16875CVE-2020-17095+2 CVEs60
Tens of thousands of compromised routers abused in WordPress attacksSecurity Affairs·May 3, 11:13 UTC · May 3, 2017VulnerabilityCVE-2014-922260
North Korean hackers target employees of news outlets, software vendors and more through Chrome vulnerabilityThe Record·Jan 17, 00:00 UTC · Jan 17, 2023VulnerabilityCVE-2022-060947
eScan AV users targeted with malicious updatesHelp Net Security·Jan 29, 00:00 UTC · Jan 29, 2026Vulnerability42
Critical RCE Bug Affects Millions of OpenWrtSecurity Affairs·Mar 25, 09:09 UTC · Mar 25, 2020VulnerabilityCVE-2020-798260
AWS Network Firewall: Network protection across all AWS workloadsHelp Net Security·Apr 20, 09:54 UTC · Apr 20, 2026Vulnerability30
Ghidra: NSA's Reverse-Engineering ToolSchneier on Security·Jan 27, 14:39 UTC · Jan 27, 2020Vulnerability42
API Supply Chain Attacks Put Millions of Airline Users at RiskInfosecurity Magazine·Jan 28, 14:00 UTC · Jan 28, 2025Vulnerability42
4 issues in Microsoft Office component allow to weaponize docsSecurity Affairs·Jun 8, 20:45 UTC · Jun 8, 2021VulnerabilityCVE-2021-31179CVE-2021-31174CVE-2021-31178+1 CVEs147
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security·May 17, 00:00 UTC · May 17, 2026Vulnerability in the wildCVE-2026-44413CVE-2026-41940CVE-2026-46300+2 CVEs160
Critical vulnerability in the RADIUS protocol leaves networking equipment open to attackHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2024VulnerabilityCVE-2024-359660
Atlassian Rolls Out Security Patch for Critical Confluence VulnerabilityThe Hacker News·Jul 22, 02:37 UTC · Jul 22, 2022Vulnerability in the wildCVE-2022-26138CVE-2022-26136CVE-2022-2613760
China suspends deal with Alibaba for not sharing Log4j 0The Hacker News·Dec 23, 15:13 UTC · Dec 23, 2021Vulnerability in the wildCVE-2021-4422860
Analyzing the security properties of a ZKTeco biometric terminalKaspersky Securelist·Jun 11, 08:00 UTC · Jun 11, 2024VulnerabilityCVE-2023-3938CVE-2023-3939CVE-2023-3940+3 CVEs35
Goodfellas, the Brazilian carding scene is after youKaspersky Securelist·Mar 15, 10:00 UTC · Mar 15, 2018Vulnerability42
New infostealer reaches enterprise devices through FortiClient EMS vulnerabilityHelp Net Security·May 29, 00:00 UTC · May 29, 2026VulnerabilityCVE-2026-3561660
Microsoft Patch TuesdayCisco Talos·Oct 13, 17:23 UTC · Oct 13, 2015VulnerabilityCVE-2015-2482CVE-2015-6055CVE-2015-6052+16 CVEs60
Duping Cloud Functions: An emerging serverless attack vectorCisco Talos·May 20, 10:00 UTC · May 20, 2025Vulnerability30
Sysdig introduces new capabilities to secure Kubernetes-based applicationsHelp Net Security·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability30
November 2020 Patch Tuesday: Microsoft fixes actively exploited Windows Kernel flawHelp Net Security·Jun 8, 18:29 UTC · Jun 8, 2021Vulnerability in the wildCVE-2020-17087CVE-2020-17051CVE-2020-17040+2 CVEs60
CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File DownloadThe Hacker News·Apr 19, 08:34 UTC · Apr 19, 2025Vulnerability in the wildCVE-2025-24054CVE-2024-4345160
Vulnerability Management Innovator Konvu Wins Cyber Startup AwardInfosecurity Magazine·Jun 3, 13:30 UTC · Jun 3, 2026Vulnerability30
Hackers Hit U.S. Senate GOP CommitteeKrebs on Security·Oct 17, 14:47 UTC · Oct 17, 2016Vulnerability30
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs160
If you haven't yet patched the BlueKeep RDP vulnerability, do so nowHelp Net Security·Jun 7, 11:33 UTC · Jun 7, 2019VulnerabilityCVE-2019-070860
Analyzing the vulnerability landscape in Q1 2024Kaspersky Securelist·May 7, 10:00 UTC · May 7, 2024VulnerabilityCVE-2023-38831CVE-2023-40477CVE-2023-2825260
2020 cybersecurity risks: Insecure security tools, supply chains, abandonwareHelp Net Security·Mar 23, 00:00 UTC · Mar 23, 2020Vulnerability55