The latest on BlueKeep and DejaBlue vulnerabilities — Using Firepower to defend against encrypted DejaBlueCisco Talos·Nov 4, 15:43 UTC · Nov 4, 2019Vulnerability in the wildCVE-2019-0708CVE-2019-1181CVE-2019-118260
macOS vulnerability allowed Keychain and iOS app decryption without a passwordHelp Net Security·Sep 4, 00:00 UTC · Sep 4, 2025Vulnerability in the wildCVE-2025-2420460
New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHubThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Vulnerability in the wildCVE-2018-15133CVE-2024-5555660
TETRA:BURST — 5 New Vulnerabilities Exposed in Widely Used Radio Communication SystemThe Hacker News·Jul 27, 06:34 UTC · Jul 27, 2023Vulnerability in the wildCVE-2022-24400CVE-2022-24401CVE-2022-24402+2 CVEs60
Vulnerability Spotlight: How an attacker could chain several vulnerabilities in an industrial wireless router to gain root accessCisco Talos·May 12, 12:00 UTC · May 12, 2022Vulnerability in the wild57
Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PANSecurity Affairs·Jun 15, 11:11 UTC · Jun 15, 2026Vulnerability in the wildCVE-2026-025760
CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple CustomersSecurity Affairs·May 31, 17:53 UTC · May 31, 2026Vulnerability in the wildCVE-2026-025760
Patch now: TP-Link Archer NX routers vulnerable to firmware takeoverSecurity Affairs·Mar 25, 14:44 UTC · Mar 25, 2026Vulnerability in the wildCVE-2025-15517CVE-2025-15605CVE-2025-9377+1 CVEs60
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from JanuaryRecorded Future·Mar 13, 00:00 UTC · Mar 13, 2026Vulnerability in the wildCVE-2025-15556CVE-2026-21513CVE-2026-21533+4 CVEs160
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency ServersThe Hacker News·Dec 9, 05:09 UTC · Dec 9, 2023Vulnerability in the wildCVE-2023-2636060
Update Windows 10 Immediately to Patch a Flaw Discovered by the NSAThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2020Vulnerability in the wildCVE-2020-0601CVE-2020-0609CVE-2020-0610+1 CVEs60
Confide, the White House's favorite messaging app, has multiple critical vulnerabilitiesCyberScoop·Mar 8, 15:45 UTC · Mar 8, 2017Vulnerability in the wild60
BENIGNCERTAIN-like flaw affects various Cisco networking devicesHelp Net Security·Sep 19, 00:00 UTC · Sep 19, 2016Vulnerability in the wildCVE-2016-641560
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)Help Net Security·Jun 1, 00:00 UTC · Jun 1, 2026Vulnerability in the wildCVE-2026-025760
Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege EscalationThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-33825CVE-2025-48804160
Microsoft Issues Patches for SharePoint ZeroThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2023-20585CVE-2026-21637CVE-2026-25250+4 CVEs160
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored CredentialsThe Hacker News·Mar 11, 14:51 UTC · Mar 11, 2026Vulnerability in the wildCVE-2026-27577CVE-2026-27493CVE-2026-27495+1 CVEs60
Patch, track, repeat: The 2025 CVE retrospectiveCisco Talos·Mar 5, 19:00 UTC · Mar 5, 2026Vulnerability in the wildCVE-2026-2138560
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
H1 2025 Malware and Vulnerability TrendsRecorded Future·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability in the wild60
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active ExploitationThe Hacker News·Oct 31, 08:31 UTC · Oct 31, 2025Vulnerability in the wildCVE-2025-5928760
Week in review: Several companies affected by the Salesloft Drift breach, Sitecore 0-day vulnerabilityHelp Net Security·Sep 7, 00:00 UTC · Sep 7, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-24204CVE-2025-48543+2 CVEs60
What to know about ToolShell, the SharePoint threat under mass exploitationArs Technica · Security·Jul 23, 20:14 UTC · Jul 23, 2025Vulnerability in the wildCVE-2025-49706CVE-2025-4970460
RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)Help Net Security·Apr 14, 16:25 UTC · Apr 14, 2025Vulnerability in the wildCVE-2025-30406CVE-2025-3116160
New Malware Variant RESURGE Exploits Ivanti VulnerabilityInfosecurity Magazine·Mar 31, 16:45 UTC · Mar 31, 2025Vulnerability in the wildCVE-2025-028260
Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9)The Hacker News·Jan 23, 08:44 UTC · Jan 23, 2025Vulnerability in the wildCVE-2025-20156CVE-2025-20165CVE-2025-20128+4 CVEs160
Cleo File Transfer Vulnerability Under ExploitationThe Hacker News·Dec 18, 04:09 UTC · Dec 18, 2024Vulnerability in the wildCVE-2024-50623CVE-2024-5595660
Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerabilityHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2024Vulnerability in the wildCVE-2024-10443CVE-2024-43093CVE-2024-43047+2 CVEs60
Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining AttacksThe Hacker News·Jul 9, 11:50 UTC · Jul 9, 2024Vulnerability in the wild57
Microsoft's January 2024 Windows Update Patches 48 New VulnerabilitiesThe Hacker News·Jan 10, 10:14 UTC · Jan 10, 2024Vulnerability in the wildCVE-2023-7024CVE-2024-20674CVE-2024-20700+3 CVEs60
Adobe, Apple, Google & Microsoft Patch 0-Day BugsKrebs on Security·Sep 15, 00:00 UTC · Sep 15, 2023Vulnerability in the wildCVE-2023-41064CVE-2023-36761CVE-2023-36802+3 CVEs60
Microsoft, Adobe fix zero-days exploited by attackers (CVE-2023-26369, CVE-2023-36761, CVE-2023-36802)Help Net Security·Sep 12, 00:00 UTC · Sep 12, 2023Vulnerability in the wildCVE-2023-26369CVE-2023-36761CVE-2023-36802+2 CVEs60
Lazarus Group exploited ManageEngine vulnerability to target critical infrastructureHelp Net Security·Aug 25, 00:00 UTC · Aug 25, 2023Vulnerability in the wildCVE-2022-4796660
Vulnerability Spotlight: SNIProxy contains remote code execution vulnerabilityCisco Talos·Mar 30, 14:35 UTC · Mar 30, 2023Vulnerability in the wildCVE-2023-2507660