GOFFEE’s recent attacks: new tools and techniquesKaspersky Securelist·Apr 10, 10:00 UTC · Apr 10, 2025Vulnerability130
ToddyCat: Keep calm and check logsKaspersky Securelist·Oct 12, 10:41 UTC · Oct 12, 2023Vulnerability42
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Cloud Atlas group acquires PowerCloud, ReverseSocks, SSHKaspersky Securelist·May 22, 09:12 UTC · May 22, 2026VulnerabilityCVE-2018-080247
Scarcity signals: Are rare activities red flags?Cisco Talos·May 23, 10:00 UTC · May 23, 2025Vulnerability30
This Windows PowerShell Phish Has Scary PotentialKrebs on Security·Sep 19, 20:18 UTC · Sep 19, 2024Vulnerability55
Kazakhstan-associated YoroTrooper disguises origin of attacks as AzerbaijanCisco Talos·Oct 25, 12:01 UTC · Oct 25, 2023Vulnerability30
Microsoft urges Azure users to update PowerShell to fix RCE flawSecurity Affairs·Jul 2, 17:43 UTC · Jul 2, 2021VulnerabilityCVE-2021-2670147
CVE-2019-0803 Windows flaw exploited to deliver PowerShell BackdoorSecurity Affairs·Apr 16, 07:03 UTC · Apr 16, 2019VulnerabilityCVE-2019-0803CVE-2019-0859160
eScan Antivirus Update Servers Compromised to Deliver MultiThe Hacker News·Feb 2, 05:47 UTC · Feb 2, 2026Vulnerability42
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
New Cyber Operation Targets Italy: Digging Into the Netwire Attack ChainSecurity Affairs·Jun 5, 18:26 UTC · Jun 5, 2020Vulnerability30
Microsoft Urges Azure Users to Update PowerShell to Patch RCE FlawThe Hacker News·Jul 5, 06:42 UTC · Jul 5, 2021VulnerabilityCVE-2021-2670160
IT threat evolution Q2 2019Kaspersky Securelist·Aug 19, 10:00 UTC · Aug 19, 2019VulnerabilityCVE-2018-812047
Iranian Hackers Exploit Log4j Vulnerability to Deploy PowerShell BackdoorThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2022VulnerabilityCVE-2021-4422860
CVE-2019-2725 Oracle WebLogic flaw exploited in cryptojacking campaignSecurity Affairs·Jun 11, 05:53 UTC · Jun 11, 2019Vulnerability in the wildCVE-2019-272560
Russian Hackers Exploit CVE-2025-26633 via MSC EvilTwin to Deploy SilentPrism and DarkWispThe Hacker News·Apr 1, 05:36 UTC · Apr 1, 2025Vulnerability in the wildCVE-2025-2663360
Russia takes unusual route to hack StarlinkArs Technica · Security·Dec 11, 23:18 UTC · Dec 11, 2024Vulnerability42
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
Server-side attacks, C&C in public clouds and other MDR cases we observedKaspersky Securelist·Nov 2, 08:00 UTC · Nov 2, 2022Vulnerability30
Microsoft Issues Improved Mitigations for Unpatched Exchange Server VulnerabilitiesThe Hacker News·Oct 10, 03:51 UTC · Oct 10, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-41082160
The BlueNoroff cryptocurrency hunt is still onKaspersky Securelist·Jan 13, 09:00 UTC · Jan 13, 2022VulnerabilityCVE-2017-019947
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange ServersThe Hacker News·Nov 1, 13:31 UTC · Nov 1, 2025Vulnerability in the wildCVE-2025-59287260
Russian Group EncryptHub Exploits MSC EvilTwin Vulnerability to Deploy Fickle Stealer MalwareThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025VulnerabilityCVE-2025-2663347
UAT-6382 exploits Cityworks zeroCisco Talos·May 22, 10:00 UTC · May 22, 2025Vulnerability in the wildCVE-2025-0994CVE-2025-094460
Attackers exploiting a FortiClient EMS vulnerability in the wildKaspersky Securelist·Dec 19, 12:00 UTC · Dec 19, 2024VulnerabilityCVE-2023-4878835
Threat Brief: CVE-2022-30190Palo Alto Unit 42·Jun 5, 20:40 UTC · Jun 5, 2024VulnerabilityCVE-2022-3019060
CVE-2022-41040 and CVE-2022-41082 – zeroKaspersky Securelist·Dec 19, 16:07 UTC · Dec 19, 2022VulnerabilityCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
Iran-linked TunnelVision APT is actively exploiting the Log4j vulnerabilitySecurity Affairs·Feb 18, 15:21 UTC · Feb 18, 2022VulnerabilityCVE-2018-1337947
Analysis of CVE-2018-8174 VBScript 0day and APT actor related to Office targeted attackSecurity Affairs·May 10, 05:31 UTC · May 10, 2018VulnerabilityCVE-2018-8174CVE-2017-019947
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs60
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian NetworksThe Hacker News·Apr 27, 14:07 UTC · Apr 27, 2026Vulnerability42
SolarWinds Web Help Desk Exploited for RCE in MultiThe Hacker News·Mar 7, 07:03 UTC · Mar 7, 2026Vulnerability in the wildCVE-2025-40551CVE-2025-40536CVE-2025-26399+1 CVEs60
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active ExploitationThe Hacker News·Oct 31, 08:31 UTC · Oct 31, 2025Vulnerability in the wildCVE-2025-5928760
Paper Werewolf Deploys PowerModul Implant in Targeted Cyberattacks on Russian SectorsThe Hacker News·Apr 12, 05:17 UTC · Apr 12, 2025Vulnerability42
ClearFake Infects 9,300 Sites, Uses Fake reCAPTCHA and Turnstile to Spread InfoThe Hacker News·Mar 19, 10:59 UTC · Mar 19, 2025VulnerabilityCVE-2017-019947
Cleo File Transfer Vulnerability Under ExploitationThe Hacker News·Dec 18, 04:09 UTC · Dec 18, 2024Vulnerability in the wildCVE-2024-50623CVE-2024-5595660