Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
Week in review: Notepad++ supply chain attack details and targets, Patch Tuesday forecastHelp Net Security·Feb 8, 00:00 UTC · Feb 8, 2026Vulnerability in the wildCVE-2026-21509CVE-2025-22225CVE-2026-2442360
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecomSecurity Affairs·Oct 24, 08:37 UTC · Oct 24, 2025Vulnerability in the wildCVE-2025-53770CVE-2021-3694260
September 2020 Patch Tuesday: Microsoft fixes over 110 CVEs againHelp Net Security·Sep 8, 00:00 UTC · Sep 8, 2020Vulnerability in the wildCVE-2020-16875CVE-2020-0688CVE-2020-0951+5 CVEs160
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4681760
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)Help Net Security·Jun 8, 00:00 UTC · Jun 8, 2026Vulnerability in the wildCVE-2026-28318CVE-2021-35211CVE-2021-35247+1 CVEs60
CVE-2026-1731 fuels ongoing attacks on BeyondTrust remote access productsSecurity Affairs·Feb 23, 12:09 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-173160
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
Federal agencies now only have one more day to patch React2Shell bugThe Record·Dec 11, 19:54 UTC · Dec 11, 2025Vulnerability in the wildCVE-2025-5518260
SAP S/4HANA Users Urged to Patch Critical Exploited BugInfosecurity Magazine·Sep 8, 09:20 UTC · Sep 8, 2025Vulnerability in the wildCVE-2025-4295760
ToolShell: a story of five vulnerabilities in Microsoft SharePointKaspersky Securelist·Jul 25, 07:00 UTC · Jul 25, 2025Vulnerability in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs160
Week in review: Sudo local privilege escalation flaws fixed, Google patches actively exploited ChromeHelp Net Security·Jul 6, 00:00 UTC · Jul 6, 2025Vulnerability in the wildCVE-2025-32462CVE-2025-32463CVE-2025-6554+4 CVEs60
Exploited: Cisco, SharePoint, Chrome vulnerabilitiesHelp Net Security·Nov 4, 10:40 UTC · Nov 4, 2024Vulnerability in the wildCVE-2024-20481CVE-2024-38094CVE-2024-4947+3 CVEs60
80% of Manufacturing Firms Have Critical VulnerabilitiesInfosecurity Magazine·Oct 2, 14:00 UTC · Oct 2, 2024Vulnerability in the wild60
Thousands of internet-facing devices vulnerable to Check Point VPN zeroThe Record·May 31, 21:08 UTC · May 31, 2024Vulnerability in the wildCVE-2024-2491960
What is cybersecurity mesh architecture (CSMA)?Help Net Security·May 11, 05:15 UTC · May 11, 2024Vulnerability in the wild57
Lazarus Group exploited ManageEngine vulnerability to target critical infrastructureHelp Net Security·Aug 25, 00:00 UTC · Aug 25, 2023Vulnerability in the wildCVE-2022-4796660
Critical Security Flaws Uncovered in Honeywell Experion DCS and QuickBlox ServicesThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Vulnerability in the wildCVE-2023-31184CVE-2023-31185CVE-2023-36664+2 CVEs60
It's time to patch your MOVEit Transfer solution again!Help Net Security·Jun 12, 00:00 UTC · Jun 12, 2023Vulnerability in the wildCVE-2023-3436260
Week in review: Kali Linux gets Purple, Microsoft zero-days get patchedHelp Net Security·Mar 19, 00:00 UTC · Mar 19, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880160
Week in review: F5 BIG-IP RCE exploitation, URL spoofing flaws in Zoom, Google DocsHelp Net Security·May 15, 00:00 UTC · May 15, 2022Vulnerability in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs60
CISA warns 'most serious' Log4j vulnerability likely to affect hundreds of millions of devicesCyberScoop·Dec 14, 15:17 UTC · Dec 14, 2021Vulnerability in the wild60
CISA Warns of Actively Exploited Critical Zoho ManageEngine ServiceDesk VulnerabilityThe Hacker News·Dec 3, 13:34 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-4053960
Determined APT is exploiting ManageEngine ServiceDesk Plus vulnerability (CVE-2021-44077)Help Net Security·Dec 3, 00:00 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-33617160
NSA Discovers New Vulnerabilities Affecting Microsoft Exchange ServersThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2021Vulnerability in the wildCVE-2021-28310CVE-2021-1732CVE-2021-28480+6 CVEs60
White House releases maritime cybersecurity updateCyberScoop·Jan 5, 18:41 UTC · Jan 5, 2021Vulnerability in the wild60
Chinese hackers hit Citrix, Cisco vulnerabilities in sweeping campaignCyberScoop·Mar 25, 15:16 UTC · Mar 25, 2020Vulnerability in the wildCVE-2019-1978160
CVE-2014-1761, Oh did you mean CVE-2012Cisco Talos·Apr 8, 13:26 UTC · Apr 8, 2014Vulnerability in the wildCVE-2014-1761CVE-2012-0158CVE-2012-253960
Crimeware: A new round of confrontation begins…Kaspersky Securelist·Apr 29, 14:13 UTC · Apr 29, 2010Vulnerability in the wild57