CISA sunsets 10 emergency directives thanks to evolution of exploited vulnerabilities catalogThe Record·Jan 8, 22:02 UTC · Jan 8, 2026Vulnerability in the wildCVE-2020-0601CVE-2020-1350CVE-2020-1472+3 CVEs60
CISA directive orders agencies to prioritize vulnerability patching in a new wayCyberScoop·Jun 10, 18:10 UTC · Jun 10, 2026Vulnerability in the wild60
Containers on fire: from container escapes to supply chain attacksKaspersky Securelist·Jun 1, 10:00 UTC · Jun 1, 2026Vulnerability in the wildCVE-2019-5736CVE-2022-0492CVE-2024-21626160
CISA directive orders federal civilian agencies to regularly report software vulnerabilitiesCyberScoop·Oct 3, 22:43 UTC · Oct 3, 2022Vulnerability in the wild60
Why patch directives only go so farCyberScoop·Jun 25, 09:00 UTC · Jun 25, 2026Vulnerability in the wildCVE-2026-5075160
CISA issues emergency directive for federal agencies to patch Ivanti VPN vulnerabilitiesCyberScoop·Jan 19, 22:13 UTC · Jan 19, 2024Vulnerability in the wild60
CISA Orders Agencies to Patch by Risk, Not SeverityInfosecurity Magazine·Jun 11, 15:00 UTC · Jun 11, 2026Vulnerability in the wild60
CISA to require federal agencies to patch some cyber vulnerabilities within 3 daysThe Record·Jun 10, 19:56 UTC · Jun 10, 2026Vulnerability in the wild60
US CISA shares a catalog of 306 actively exploited vulnerabilitiesSecurity Affairs·Nov 4, 11:37 UTC · Nov 4, 2021Vulnerability in the wildCVE-2010-532660
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sectorCyberScoop·Jun 9, 16:27 UTC · Jun 9, 2026Vulnerability in the wild60
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Actively exploited critical flaw in Modular DS WordPress plugin enables admin takeoverSecurity Affairs·Jan 16, 08:26 UTC · Jan 16, 2026Vulnerability in the wildCVE-2026-2355060
February 2025 Patch Tuesday forecast: New directions for AI developmentHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2025Vulnerability in the wildCVE-2025-21418CVE-2025-21391CVE-2025-2408560
Patch Tuesday for August 2022 fixed actively exploited zeroSecurity Affairs·Aug 9, 21:25 UTC · Aug 9, 2022Vulnerability in the wildCVE-2022-34713CVE-2022-30133CVE-2022-35744+46 CVEs160
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code ExecutionThe Hacker News·Jun 22, 05:37 UTC · Jun 22, 2026Vulnerability in the wildCVE-2026-42530CVE-2026-42055CVE-2026-4294560
CISA to transform how it assesses cyber vulnerabilities and risks, Andersen saysThe Record·Jun 9, 18:59 UTC · Jun 9, 2026Vulnerability in the wild60
CISA Orders Federal Agencies to Patch FlawsInfosecurity Magazine·Nov 3, 17:20 UTC · Nov 3, 2021Vulnerability in the wild60
New DHS order pushes agencies to quickly patch vulnerabilitiesCyberScoop·Apr 30, 15:33 UTC · Apr 30, 2019Vulnerability in the wild60
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security·May 17, 00:00 UTC · May 17, 2026Vulnerability in the wildCVE-2026-44413CVE-2026-41940CVE-2026-46300+2 CVEs160
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
Kernel shellcode persistence technique in APT attacks and SAS CTF challengeKaspersky Securelist·Oct 17, 14:20 UTC · Oct 17, 2024Vulnerability in the wildCVE-2010-4398160
Experts found hundreds of devices within federal networks having internetSecurity Affairs·Jun 27, 14:07 UTC · Jun 27, 2023Vulnerability in the wild60
CISA orders agencies to quickly patch critical Netlogon bugCyberScoop·Sep 21, 21:50 UTC · Sep 21, 2020Vulnerability in the wild60
200 new CVEs a day and no realistic way to patch them allHelp Net Security·Aug 4, 11:25 UTC · Aug 4, 2026Vulnerability in the wildCVE-2026-25089160
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621160
32% Of Top-Exploited Vulnerabilities Are Over A Decade OldHelp Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Vulnerability in the wild157
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025Security Affairs·Mar 19, 14:48 UTC · Mar 19, 2026Vulnerability in the wildCVE-2025-6637660
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
Week in review: Notepad++ supply chain attack details and targets, Patch Tuesday forecastHelp Net Security·Feb 8, 00:00 UTC · Feb 8, 2026Vulnerability in the wildCVE-2026-21509CVE-2025-22225CVE-2026-2442360
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation WaveInfosecurity Magazine·Jan 16, 09:15 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-37164CVE-2025-5518260
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
Integrating Threat Intelligence and Vulnerability Management: A Modern ApproachRecorded Future·Dec 17, 00:00 UTC · Dec 17, 2025Vulnerability in the wild60
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
H1 2025 Malware and Vulnerability TrendsRecorded Future·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability in the wild60
Patch the vulnerability: Confirm Sean Plankey as CISA directorCyberScoop·Aug 13, 13:24 UTC · Aug 13, 2025Vulnerability in the wild160
CISA, Microsoft warn organizations of high-severity Microsoft Exchange vulnerabilityCyberScoop·Aug 7, 15:36 UTC · Aug 7, 2025Vulnerability in the wildCVE-2025-53786160
BreachLock Attack Surface Analytics strengthens enterprise CTEM capabilitiesHelp Net Security·Oct 8, 00:00 UTC · Oct 8, 2024Vulnerability in the wild60
Void Banshee exploits CVE-2024-38112 zeroSecurity Affairs·Jul 17, 14:16 UTC · Jul 17, 2024Vulnerability in the wildCVE-2024-38112CVE-2021-4044460