ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More StoriesThe Hacker News·Aug 6, 15:24 UTC · Aug 6, 2026VulnerabilityCVE-2025-21079CVE-2025-58486247
AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes beginHelp Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability55
Scripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object modelCisco Talos·Jun 18, 10:00 UTC · Jun 18, 2026Vulnerability130
Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PANSecurity Affairs·Jun 15, 11:11 UTC · Jun 15, 2026Vulnerability in the wildCVE-2026-025760
Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025Security Affairs·Jun 10, 13:37 UTC · Jun 10, 2026VulnerabilityCVE-2025-8088CVE-2018-2025047
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 BugsThe Hacker News·Jun 6, 07:28 UTC · Jun 6, 2026VulnerabilityCVE-2026-39210CVE-2026-39218CVE-2026-1088160
CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple CustomersSecurity Affairs·May 31, 17:53 UTC · May 31, 2026Vulnerability in the wildCVE-2026-025760
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heapCisco Talos·May 28, 10:00 UTC · May 28, 2026Vulnerability55
Cloud Atlas group acquires PowerCloud, ReverseSocks, SSHKaspersky Securelist·May 22, 09:12 UTC · May 22, 2026VulnerabilityCVE-2018-080247
Meet Fractal, an OS made for microarchitecture reverse engineeringHelp Net Security·May 22, 00:00 UTC · May 22, 2026Vulnerability130
Dangerous vulnerability can be exploited to carry out massive DDoS attacks (CVE-2023-44487)Help Net Security·Apr 23, 13:42 UTC · Apr 23, 2026VulnerabilityCVE-2023-4448760
Popular fintech apps expose valuable, exploitable secretsHelp Net Security·Apr 23, 13:38 UTC · Apr 23, 2026Vulnerability55
German political party store hacked before electionSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability30
Unpublished security flaws (0days) massively exploitedSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Cardbleed: 3% of Magento install base hackedSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Found defunct.dat on your site? You've got a problem.Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Magento wish list exploit bypasses WAF protectionSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026VulnerabilityCVE-2022-2408660
SVG Onload Tag Hides Magecart Skimmer on 99 StoresSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wild57
Vendors defeat Magento security patch (+ simple check)Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2022-24086CVE-2022-24087CVE-2026-7565060
China-Linked TA416 Targets European Governments with PlugX and OAuthThe Hacker News·Apr 3, 17:34 UTC · Apr 3, 2026VulnerabilityCVE-2025-31324CVE-2025-099460
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux ServersThe Hacker News·Apr 3, 15:32 UTC · Apr 3, 2026Vulnerability142
Mass PolyShell attack wave hits 471 stores in one hourSansec (Magento / e-commerce security)·Mar 31, 07:45 UTC · Mar 31, 2026Vulnerability in the wildCVE-2026-7565060
How to Protect Your SaaS from Bot Attacks with SafeLine WAFThe Hacker News·Mar 9, 14:16 UTC · Mar 9, 2026Vulnerability55
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKENThe Hacker News·Feb 28, 17:02 UTC · Feb 28, 2026Vulnerability142
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIPThe Hacker News·Feb 23, 17:21 UTC · Feb 23, 2026Vulnerability42
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 ScoreThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2026-24423CVE-2026-23760CVE-2026-2506760
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bugSecurity Affairs·Jan 16, 10:17 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-2039360
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full ControlThe Hacker News·Jan 8, 09:26 UTC · Jan 8, 2026VulnerabilityCVE-2026-21858CVE-2025-68613CVE-2025-68668+1 CVEs60
Cisco Warns of Active Attacks Exploiting Unpatched 0The Hacker News·Dec 20, 12:11 UTC · Dec 20, 2025Vulnerability in the wildCVE-2025-2039360
A vehicle's head unit hacked via its modemKaspersky Securelist·Dec 16, 10:00 UTC · Dec 16, 2025VulnerabilityCVE-2024-39432CVE-2024-3943160
Week in review: 40 open-source tools securing the stack, invisible IT to be the next workplace priorityHelp Net Security·Dec 14, 00:00 UTC · Dec 14, 2025Vulnerability130
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Upwind adds real-time AI security and posture management to its CNAPPHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2025Vulnerability55
New Mirai variant ShadowV2 tests IoT exploits amid AWS disruptionSecurity Affairs·Nov 28, 08:20 UTC · Nov 28, 2025VulnerabilityCVE-2009-2765CVE-2020-25506CVE-2022-37055+5 CVEs35
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential TheftThe Hacker News·Nov 25, 03:51 UTC · Nov 25, 2025Vulnerability55
Attackers deliver ShadowPad via newly patched WSUS RCE bugSecurity Affairs·Nov 24, 12:35 UTC · Nov 24, 2025Vulnerability in the wildCVE-2025-5928760
AI-Enhanced Tuoni Framework Targets Major US Real Estate FirmInfosecurity Magazine·Nov 18, 14:45 UTC · Nov 18, 2025Vulnerability30
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
China-Linked Hackers Exploit Windows Shortcut Flaw to Target European DiplomatsThe Hacker News·Nov 8, 05:26 UTC · Nov 8, 2025VulnerabilityCVE-2025-949135
Microsoft releases urgent fix for actively exploited WSUS vulnerability (CVE-2025-59287)Help Net Security·Nov 3, 09:36 UTC · Nov 3, 2025Vulnerability in the wildCVE-2025-5928760