Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025Security Affairs·Mar 19, 14:48 UTC · Mar 19, 2026Vulnerability in the wildCVE-2025-6637660
Further analysis of Denmark attacks leads to warning about unpatched network gearThe Record·Jan 11, 17:25 UTC · Jan 11, 2024Vulnerability in the wild60
Netgear releases patches for two highThe Record·Aug 30, 18:12 UTC · Aug 30, 2023Vulnerability in the wildCVE-2023-41183CVE-2023-4118260
Microsoft Patches Two Zero Days This MonthInfosecurity Magazine·Mar 15, 09:30 UTC · Mar 15, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880CVE-2023-2170860
March 2022 Patch Tuesday forecast: Pressure mounts to resolve vulnerabilitiesHelp Net Security·Mar 10, 05:56 UTC · Mar 10, 2022Vulnerability in the wild60
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security·Jun 21, 00:00 UTC · Jun 21, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-48558CVE-2026-39813+3 CVEs160
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Microsoft Releases Patches for 74 New Vulnerabilities in August UpdateThe Hacker News·Aug 10, 03:31 UTC · Aug 10, 2023Vulnerability in the wildCVE-2023-20569CVE-2023-36884CVE-2023-35388+8 CVEs60
Cacti Servers Under Attack as Majority Fail to Patch Critical VulnerabilityThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2023Vulnerability in the wildCVE-2022-46169CVE-2023-2295260
How the French fiber optic cable attacks accentuate critical infrastructure vulnerabilitiesCyberScoop·Apr 28, 14:00 UTC · Apr 28, 2022Vulnerability in the wild60
Week in review: Spring4Shell vulnerability, attackers exploiting patched RCE in Sophos FirewallHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2022Vulnerability in the wildCVE-2022-104060
FBI warns of growing risks of RussiaSecurity Affairs·Mar 23, 15:20 UTC · Mar 23, 2022Vulnerability in the wild60
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133)Help Net Security·Apr 21, 00:00 UTC · Apr 21, 2026Vulnerability in the wildCVE-2026-20133CVE-2026-20128CVE-2026-20122+5 CVEs160
Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword ExploitThe Hacker News·Apr 4, 07:24 UTC · Apr 4, 2026Vulnerability in the wild160
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File DownloadThe Hacker News·Apr 19, 08:34 UTC · Apr 19, 2025Vulnerability in the wildCVE-2025-24054CVE-2024-43451160
Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF InjectionThe Hacker News·Jan 9, 10:29 UTC · Jan 9, 2025Vulnerability in the wildCVE-2024-5287560
Vulnerability Exploitation on the Rise as Attackers Ditch PhishingInfosecurity Magazine·Apr 23, 13:01 UTC · Apr 23, 2024Vulnerability in the wildCVE-2023-34362CVE-2022-21587CVE-2023-286860
Roundcube webmail XSS vulnerability exploited by attackers (CVE-2023-43770)Help Net Security·Feb 15, 11:46 UTC · Feb 15, 2024Vulnerability in the wildCVE-2023-43770CVE-2020-35730CVE-2021-4402660
Critical vulnerability in Atlassian Confluence server is under “mass exploitation”Ars Technica · Security·Nov 6, 23:40 UTC · Nov 6, 2023Vulnerability in the wildCVE-2023-2251860
Russian hackers offered phony drone training to exploit WinRAR vulnerabilityCyberScoop·Oct 18, 15:40 UTC · Oct 18, 2023Vulnerability in the wild60
Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation AttacksThe Hacker News·Jul 24, 13:01 UTC · Jul 24, 2023Vulnerability in the wildCVE-2023-26077CVE-2023-26078CVE-2023-2339760
Microsoft Releases Patches for 132 Vulnerabilities, Including 6 Under Active AttackThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Vulnerability in the wildCVE-2023-32046CVE-2023-32049CVE-2023-35311+2 CVEs160
BlackLotus UEFI bootkit disables Windows security mechanismsHelp Net Security·Apr 17, 10:14 UTC · Apr 17, 2023Vulnerability in the wildCVE-2022-2189460
Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active AttackThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880CVE-2022-44698+10 CVEs60
CISA adds Spring4Shell vulnerability, Apple zeroThe Record·Jan 13, 00:00 UTC · Jan 13, 2023Vulnerability in the wildCVE-2022-22965CVE-2022-22675CVE-2022-22674+1 CVEs60
Hackers Exploiting Recently Reported Windows Print Spooler Vulnerability in the WildThe Hacker News·Apr 20, 14:37 UTC · Apr 20, 2022Vulnerability in the wildCVE-2022-22718CVE-2018-6882CVE-2019-356860
Cyber Command’s bug bounty program uncovers more than 30 vulnerabilitiesCyberScoop·Oct 15, 02:13 UTC · Oct 15, 2019Vulnerability in the wild60
CVE-2019-1132 Win 0Day used by Buhtrap Group in government attackSecurity Affairs·Jul 12, 06:32 UTC · Jul 12, 2019Vulnerability in the wildCVE-2019-113260
China hides homegrown hacks from its vulnerability disclosure processCyberScoop·Nov 16, 13:00 UTC · Nov 16, 2017Vulnerability in the wildCVE-2017-0199CVE-2016-10136CVE-2016-1013860