'Smart' doorbells for sale on Amazon, eBay came stocked with security vulnerabilitiesCyberScoop·Nov 24, 14:41 UTC · Nov 24, 2020Vulnerability in the wild60
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCEThe Hacker News·Mar 17, 16:39 UTC · Mar 17, 2026Vulnerability in the wildCVE-2026-25750CVE-2026-3059CVE-2026-3060+1 CVEs60
Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leakedHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2024Vulnerability in the wildCVE-2024-43451CVE-2024-49039CVE-2024-9463+1 CVEs160
251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and ElasticsearchThe Hacker News·May 28, 09:23 UTC · May 28, 2025Vulnerability in the wildCVE-2018-15961CVE-2017-5638CVE-2022-26134+2 CVEs60
Amazon's Hotpatch for Log4j Flaw Found Vulnerable to Privilege Escalation BugThe Hacker News·Apr 23, 05:41 UTC · Apr 23, 2022Vulnerability in the wildCVE-2021-3100CVE-2021-3101CVE-2022-0070+1 CVEs60
Cisco’s latest vulnerability spree has a more troubling pattern underneathCyberScoop·Mar 18, 21:31 UTC · Mar 18, 2026Vulnerability in the wildCVE-2026-20127CVE-2022-20775CVE-2026-20122+6 CVEs60
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell VulnerabilityThe Hacker News·Dec 5, 16:12 UTC · Dec 5, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-31324CVE-2025-133860
Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM CredentialsThe Hacker News·Sep 25, 17:16 UTC · Sep 25, 2025Vulnerability in the wildCVE-2025-51591CVE-2021-2131160
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security·May 17, 00:00 UTC · May 17, 2026Vulnerability in the wildCVE-2026-44413CVE-2026-41940CVE-2026-46300+2 CVEs160
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-27681CVE-2026-34621CVE-2026-34619+7 CVEs60
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-65046CVE-2026-0628CVE-2026-20805+5 CVEs160
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat ActorsRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-5518260
Microsoft Patches 67 Vulnerabilities Including WEBDAV ZeroThe Hacker News·Jun 12, 15:47 UTC · Jun 12, 2025Vulnerability in the wildCVE-2025-33053CVE-2025-47966CVE-2025-32713+3 CVEs160
Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps ServerThe Hacker News·May 15, 00:00 UTC · May 15, 2025Vulnerability in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+10 CVEs160
Microsoft Patches 125 Flaws Including Actively Exploited Windows CLFS VulnerabilityThe Hacker News·Apr 10, 06:48 UTC · Apr 10, 2025Vulnerability in the wildCVE-2025-29824CVE-2022-24521CVE-2022-37969+15 CVEs60
URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited ZeroThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Vulnerability in the wildCVE-2025-26643CVE-2025-24983CVE-2025-24984+5 CVEs160
Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active ExploitationThe Hacker News·Feb 12, 10:28 UTC · Feb 12, 2025Vulnerability in the wildCVE-2025-21391CVE-2025-21418CVE-2024-38193+4 CVEs60
Microsoft's July Update Patches 143 Flaws, Including Two Actively ExploitedThe Hacker News·Jul 11, 09:02 UTC · Jul 11, 2024Vulnerability in the wildCVE-2024-38080CVE-2024-38112CVE-2024-37985+3 CVEs60
Week in review: 18 free Microsoft Azure cybersecurity resources, K8 vulnerability allows RCEHelp Net Security·Sep 24, 00:00 UTC · Sep 24, 2023Vulnerability in the wildCVE-2023-41179CVE-2023-41992CVE-2023-41991+6 CVEs60
Week in review: Exchange Servers under attack, disinformation economics, Patch Tuesday forecastHelp Net Security·Mar 7, 00:00 UTC · Mar 7, 2021Vulnerability in the wildCVE-2021-22681CVE-2021-2670860
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)Help Net Security·Jul 30, 00:00 UTC · Jul 30, 2026Vulnerability in the wildCVE-2026-20316CVE-2026-20079CVE-2026-20131160
UK weakens proposed telecoms defenses against Chinese hackers after industry pushbackThe Record·Jun 10, 06:46 UTC · Jun 10, 2026Vulnerability in the wild60
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2026Vulnerability in the wildCVE-2026-0257CVE-2026-41089CVE-2025-48595+1 CVEs60
Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)Help Net Security·May 11, 11:22 UTC · May 11, 2026Vulnerability in the wildCVE-2026-3143160
Dirty Frag: Unpatched Linux vulnerability delivers root accessHelp Net Security·May 11, 09:48 UTC · May 11, 2026Vulnerability in the wildCVE-2026-43284CVE-2026-43500CVE-2026-3143160
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilitiesCyberScoop·Apr 7, 19:35 UTC · Apr 7, 2026Vulnerability in the wild60
CodeBuild Flaw Put AWS Console Supply Chain At RiskInfosecurity Magazine·Jan 15, 15:00 UTC · Jan 15, 2026Vulnerability in the wild160
React2Shell Vulnerability Actively Exploited to Deploy Linux BackdoorsThe Hacker News·Dec 17, 07:26 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-29927CVE-2025-6647860
Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across TenantsThe Hacker News·Sep 24, 10:50 UTC · Sep 24, 2025Vulnerability in the wildCVE-2025-55241CVE-2025-53786160
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 BugsThe Hacker News·Sep 11, 08:56 UTC · Sep 11, 2025Vulnerability in the wildCVE-2025-53791CVE-2025-55234CVE-2025-54914+9 CVEs60
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHubThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Vulnerability in the wildCVE-2018-15133CVE-2024-5555660
Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL ServerThe Hacker News·Jul 10, 07:02 UTC · Jul 10, 2025Vulnerability in the wildCVE-2025-49719CVE-2025-47981CVE-2025-49735+9 CVEs60
Meta Warns of FreeType Vulnerability (CVE-2025The Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Vulnerability in the wildCVE-2025-2736360
Multiple vulnerabilities found in ICONICS industrial SCADA softwareCyberScoop·Mar 10, 20:13 UTC · Mar 10, 2025Vulnerability in the wildCVE-2024-7587CVE-2024-118260
Swap EOL Zyxel routers, upgrade Netgear ones!Help Net Security·Feb 5, 00:00 UTC · Feb 5, 2025Vulnerability in the wildCVE-2024-40891CVE-2024-40890CVE-2025-089060
Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS VulnerabilityThe Hacker News·Dec 11, 15:01 UTC · Dec 11, 2024Vulnerability in the wildCVE-2024-49138CVE-2022-24521CVE-2022-37969+6 CVEs60
Microsoft Issues Patches for 79 Flaws, Including 3 Actively Exploited Windows FlawsThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2024Vulnerability in the wildCVE-2024-38014CVE-2024-38217CVE-2024-38226+3 CVEs60
Microsoft Issues Patches for 90 Flaws, Including 10 Critical ZeroThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2024Vulnerability in the wildCVE-2024-38189CVE-2024-38178CVE-2024-38193+13 CVEs160