New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026The Hacker News·May 31, 12:13 UTC · May 31, 2026Vulnerability in the wildCVE-2026-3998760
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
H1 2025 Malware and Vulnerability TrendsRecorded Future·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability in the wild60
Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to TargetsThe Hacker News·Jul 11, 04:04 UTC · Jul 11, 2025Vulnerability55
New Cyberattack Targets Chinese-Speaking Businesses with Cobalt Strike PayloadsThe Hacker News·Aug 30, 06:17 UTC · Aug 30, 2024Vulnerability55
Hackers Deploy IceApple Exploitation Framework on Hacked MS Exchange ServersThe Hacker News·May 12, 05:36 UTC · May 12, 2022Vulnerability55
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
2021 Vulnerability LandscapeRecorded Future·Jul 28, 00:00 UTC · Jul 28, 2025Vulnerability in the wildCVE-2021-4422860
Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN CredentialsThe Hacker News·Nov 18, 03:52 UTC · Nov 18, 2024Vulnerability55
Fortinet Warns of Critical Vulnerability in FortiManager Under Active ExploitationThe Hacker News·Nov 15, 04:35 UTC · Nov 15, 2024Vulnerability in the wildCVE-2024-4757560
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN VulnerabilitiesThe Hacker News·Feb 2, 04:53 UTC · Feb 2, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Critical vulnerability in Atlassian Confluence server is under “mass exploitation”Ars Technica · Security·Nov 6, 23:40 UTC · Nov 6, 2023Vulnerability in the wildCVE-2023-2251860
Hackers target Chinese-speaking Microsoft users with ‘RedDriver’ browser hijackerThe Record·Jul 11, 19:55 UTC · Jul 11, 2023Vulnerability55
Critical RCE impacts popular postSecurity Affairs·Oct 18, 12:27 UTC · Oct 18, 2022VulnerabilityCVE-2022-42948CVE-2022-3919760
New Toddycat APT Targets MS Exchange Servers in Europe and AsiaInfosecurity Magazine·Jun 21, 17:30 UTC · Jun 21, 2022Vulnerability55
CISA Warns of Actively Exploited Critical Zoho ManageEngine ServiceDesk VulnerabilityThe Hacker News·Dec 3, 13:34 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-4053960
A look at modern adversary behavior and the usage of open source tools in the enterpriseHelp Net Security·Jul 17, 00:00 UTC · Jul 17, 2020Vulnerability55
New GhostHook Attack Bypasses Windows 10 PatchGuard ProtectionsThe Hacker News·Jun 23, 05:49 UTC · Jun 23, 2017Vulnerability55
Toolkit Hidden Inside Oracle Database Evades Endpoint ToolsInfosecurity Magazine·Aug 6, 15:30 UTC · Aug 6, 2026Vulnerability55
Chinese Threat Actors Weaponize New Vulnerabilities in Under a DayInfosecurity Magazine·Aug 3, 15:00 UTC · Aug 3, 2026Vulnerability in the wild60
JSP webshells being dropped on unpatched PTC Windchill instancesHelp Net Security·Jul 27, 12:30 UTC · Jul 27, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-468160
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesThe Hacker News·Jul 8, 05:07 UTC · Jul 8, 2026VulnerabilityCVE-2024-42009CVE-2025-4911360
Why patch directives only go so farCyberScoop·Jun 25, 09:00 UTC · Jun 25, 2026Vulnerability in the wildCVE-2026-5075160
Hackers probe, exploit newly patched BeyondTrust RCE flaw (CVE-2026-1731)Help Net Security·Jun 24, 10:29 UTC · Jun 24, 2026VulnerabilityCVE-2026-1731CVE-2024-1235660
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in AprilCyberScoop·Jun 18, 14:32 UTC · Jun 18, 2026Vulnerability in the wildCVE-2026-39808CVE-2026-39813CVE-2026-2508960
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code ExecutionThe Hacker News·Jun 12, 09:50 UTC · Jun 12, 2026VulnerabilityCVE-2025-67644CVE-2026-28277CVE-2026-2702260
Attackers actively exploiting flaw(s) in Cleo file transfer software (CVE-2024-50623)Help Net Security·Jun 8, 10:32 UTC · Jun 8, 2026Vulnerability in the wildCVE-2024-5062360
Containers on fire: from container escapes to supply chain attacksKaspersky Securelist·Jun 1, 10:00 UTC · Jun 1, 2026Vulnerability in the wildCVE-2019-5736CVE-2022-0492CVE-2024-21626160
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-0300160
Three Microsoft Defender Zero-Days Actively Exploited; Two Still UnpatchedThe Hacker News·May 14, 09:15 UTC · May 14, 2026Vulnerability in the wildCVE-2026-3382560
Rushed Patches Follow Broken Embargo on Linux Kernel VulnerabilitiesInfosecurity Magazine·May 11, 14:30 UTC · May 11, 2026Vulnerability in the wildCVE-2026-31431CVE-2026-43284CVE-2026-43500160
PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News·May 7, 17:58 UTC · May 7, 2026Vulnerability in the wildCVE-2026-030060
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of DisclosureThe Hacker News·Apr 24, 05:28 UTC · Apr 24, 2026Vulnerability in the wildCVE-2026-3998760
CVE-2026-39987: Marimo RCE exploited in hours after disclosureSecurity Affairs·Apr 11, 09:44 UTC · Apr 11, 2026Vulnerability in the wildCVE-2026-39987CVE-2026-3301760