Why React Didn't Kill XSS: The New JavaScript Injection PlaybookThe Hacker News·Jul 29, 10:00 UTC · Jul 29, 2025Vulnerability55
Adobe released out-of-band updates for After Effects and Media EncoderSecurity Affairs·Feb 20, 15:36 UTC · Feb 20, 2020VulnerabilityCVE-2020-3765CVE-2020-376460
Out-of-band security update fixes Adobe Media Encoder issueSecurity Affairs·Sep 15, 21:14 UTC · Sep 15, 2020VulnerabilityCVE-2020-9739CVE-2020-9744CVE-2020-974560
Adobe fixes over a dozen flaws in Media Encoder, Download ManagerSecurity Affairs·Jul 14, 17:59 UTC · Jul 14, 2020VulnerabilityCVE-2020-9688CVE-2020-9669CVE-2020-9671+3 CVEs60
Adobe Patches Critical Bugs Affecting Media Encoder and After EffectsThe Hacker News·Feb 20, 10:09 UTC · Feb 20, 2020Vulnerability in the wildCVE-2020-3765CVE-2020-376460
Adobe Releases Critical Patches for Flash, Acrobat Reader, and Media EncoderThe Hacker News·May 15, 00:00 UTC · May 15, 2019Vulnerability in the wildCVE-2019-7837CVE-2019-784260
Moodle vulnerability exposed users to account takeoverSecurity Affairs·Apr 8, 20:22 UTC · Apr 8, 2021Vulnerability55
Adobe Patch Tuesday patches fix over 80 flaws in Flash, Acrobat Reader, and Media EncoderSecurity Affairs·May 15, 06:14 UTC · May 15, 2019VulnerabilityCVE-2019-7837CVE-2019-784260
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Equation Group: from Houston with loveKaspersky Securelist·Feb 19, 09:00 UTC · Feb 19, 2015Vulnerability55
CERT/CC Warns binary-parser Bug Allows Node.js PrivilegeThe Hacker News·Jan 27, 14:10 UTC · Jan 27, 2026VulnerabilityCVE-2026-1245160
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
UPS: Observations on CVE-2015-3113, Prior ZeroPalo Alto Unit 42·Nov 1, 09:48 UTC · Nov 1, 2018VulnerabilityCVE-2015-3113CVE-2014-1776CVE-2014-633260
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AICisco Talos·Aug 4, 10:00 UTC · Aug 4, 2026Vulnerability55
CISA Adds Exploited Magento RCE Flaw CVE-2026The Hacker News·Jun 4, 11:53 UTC · Jun 4, 2026Vulnerability in the wildCVE-2026-4524760
Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical InfrastructureThe Hacker News·Mar 9, 18:22 UTC · Mar 9, 2026Vulnerability55
5 Threats That Reshaped Web Security This Year [2025]The Hacker News·Dec 4, 11:30 UTC · Dec 4, 2025VulnerabilityCVE-2025-54135CVE-2025-53109CVE-2025-5528460
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer AttacksThe Hacker News·Sep 24, 11:03 UTC · Sep 24, 2025Vulnerability in the wild60
Kaspersky found multiple memory corruptions in Suricata and FreeRDPKaspersky Securelist·Aug 22, 12:50 UTC · Aug 22, 2024VulnerabilityCVE-2024-32041CVE-2024-32039CVE-2024-32040+4 CVEs60
Critical Jenkins Vulnerability Exposes Servers to RCE AttacksThe Hacker News·Jan 29, 03:45 UTC · Jan 29, 2024VulnerabilityCVE-2024-23897CVE-2023-27898CVE-2023-2790560
July 2020 Patch Tuesday: Microsoft plugs wormable Windows DNS Server RCE flawHelp Net Security·Nov 14, 09:19 UTC · Nov 14, 2023Vulnerability in the wildCVE-2020-1350CVE-2020-1147CVE-2020-1349+2 CVEs60
VMware addressed an information disclosure flaw in VMware Tanzu Application Service for VMs and Isolation SegmentSecurity Affairs·Jul 25, 18:26 UTC · Jul 25, 2023VulnerabilityCVE-2023-20891CVE-2023-2086460
Critical Bug in Mozilla’s NSS Crypto Library Potentially Affects Several Other SoftwareThe Hacker News·Dec 3, 03:40 UTC · Dec 3, 2021VulnerabilityCVE-2021-4352760
Adobe Issues July 2020 Critical Security Patches for Multiple SoftwareThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2020Vulnerability in the wildCVE-2020-9682CVE-2020-9650CVE-2020-9646+1 CVEs60
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersThe Hacker News·Jul 10, 11:47 UTC · Jul 10, 2026Vulnerability in the wildCVE-2026-4253060
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code ExecutionThe Hacker News·Jun 22, 05:37 UTC · Jun 22, 2026Vulnerability in the wildCVE-2026-42530CVE-2026-42055CVE-2026-4294560
F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code ExecutionSecurity Affairs·Jun 18, 14:07 UTC · Jun 18, 2026VulnerabilityCVE-2026-42530CVE-2026-42055CVE-2026-11311+1 CVEs60
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)Help Net Security·Jun 8, 00:00 UTC · Jun 8, 2026Vulnerability in the wildCVE-2026-28318CVE-2021-35211CVE-2021-35247+1 CVEs60
Magento and the Log4j vulnerabilitySansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability55
Magento wish list exploit bypasses WAF protectionSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026VulnerabilityCVE-2022-2408660
PolyShell flaw exposes Magento and Adobe Commerce to file upload attacksSecurity Affairs·Mar 21, 10:09 UTC · Mar 21, 2026Vulnerability in the wild60
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCEThe Hacker News·Mar 17, 16:39 UTC · Mar 17, 2026Vulnerability in the wildCVE-2026-25750CVE-2026-3059CVE-2026-3060+1 CVEs60
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from OctoberRecorded Future·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability in the wildCVE-2025-64446CVE-2025-58034CVE-2025-21042+1 CVEs60
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential TheftThe Hacker News·Nov 25, 03:51 UTC · Nov 25, 2025Vulnerability55
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange ServersThe Hacker News·Nov 1, 13:31 UTC · Nov 1, 2025Vulnerability in the wildCVE-2025-59287260
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active ExploitationThe Hacker News·Oct 31, 08:31 UTC · Oct 31, 2025Vulnerability in the wildCVE-2025-59287160
How Juventus protects fans, revenue, and reputation during matchdaysHelp Net Security·Sep 22, 00:00 UTC · Sep 22, 2025Vulnerability55
Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid SetupsThe Hacker News·Aug 8, 04:02 UTC · Aug 8, 2025VulnerabilityCVE-2025-5378660