Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat ActorsRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-5518260
Developers scramble as critical React flaw threatens major appsCyberScoop·Dec 3, 19:23 UTC · Dec 3, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-6647860
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
Federal agencies now only have one more day to patch React2Shell bugThe Record·Dec 11, 19:54 UTC · Dec 11, 2025Vulnerability in the wildCVE-2025-5518260
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm PackageThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-11953160
AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.The Hacker News·Jun 2, 11:58 UTC · Jun 2, 2026Vulnerability in the wild60
Vulnerability landscape in Q4 2025Kaspersky Securelist·Mar 6, 10:00 UTC · Mar 6, 2026Vulnerability in the wildCVE-2018-0802CVE-2017-11882CVE-2017-0199+7 CVEs160
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell VulnerabilityThe Hacker News·Dec 5, 16:12 UTC · Dec 5, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-31324CVE-2025-133860
Beyond Vulnerability ManagementThe Hacker News·May 9, 16:51 UTC · May 9, 2025Vulnerability in the wild60
Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacksCyberScoop·Feb 25, 13:30 UTC · Feb 25, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer AttacksThe Hacker News·Sep 24, 11:03 UTC · Sep 24, 2025Vulnerability in the wild60
GreyNoise enhances threat response with real-time blocklists, feeds, and SOAR integrationsHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2025Vulnerability in the wild60
UK and US share more vulnerabilities exploited by Russia's APT29 hackersThe Record·Dec 9, 00:00 UTC · Dec 9, 2022Vulnerability in the wildCVE-2018-13379CVE-2019-1653CVE-2019-2725+9 CVEs60
Kaspersky Lab report: Evaluating the threat level of software vulnerabilitiesKaspersky Securelist·Feb 1, 14:30 UTC · Feb 1, 2013Vulnerability in the wild160
Chinese Threat Actors Weaponize New Vulnerabilities in Under a DayInfosecurity Magazine·Aug 3, 15:00 UTC · Aug 3, 2026Vulnerability in the wild60
At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026Recorded Future·May 21, 00:00 UTC · May 21, 2026Vulnerability in the wildCVE-2025-5518260
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621160
Cloud Attackers Now Prefer Vulnerability Exploits Over CredentialsInfosecurity Magazine·Mar 10, 15:30 UTC · Mar 10, 2026Vulnerability in the wildCVE-2025-5518260
Edge systems take the brunt of internet-wide exploitation attemptsHelp Net Security·Feb 25, 00:00 UTC · Feb 25, 2026Vulnerability in the wildCVE-2020-2034CVE-2025-5518260
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
React2Shell Vulnerability Actively Exploited to Deploy Linux BackdoorsThe Hacker News·Dec 17, 07:26 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-29927CVE-2025-6647860
Integrating Threat Intelligence and Vulnerability Management: A Modern ApproachRecorded Future·Dec 17, 00:00 UTC · Dec 17, 2025Vulnerability in the wild60
AI can help track an ever-growing body of vulnerabilities, CISA official saysCyberScoop·Sep 4, 17:42 UTC · Sep 4, 2025Vulnerability in the wild60
Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)Help Net Security·Apr 2, 08:44 UTC · Apr 2, 2025Vulnerability in the wildCVE-2025-2992760
87,000+ Fortinet devices still open to attack, are yours among them? (CVE-2024-23113)Help Net Security·Oct 15, 00:00 UTC · Oct 15, 2024Vulnerability in the wildCVE-2024-2311360
Five Eyes Warn of Ivanti Vulnerabilities ExploitationInfosecurity Magazine·Mar 1, 12:00 UTC · Mar 1, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Realtek SDK vulnerability exploitation attempts detected (CVE-2021-35395)Help Net Security·Dec 12, 13:09 UTC · Dec 12, 2023Vulnerability in the wildCVE-2021-35395CVE-2021-35392CVE-2021-35393+1 CVEs60
Microsoft October 2022 Patch Tuesday Fixes 84 Flaws, Including ZeroInfosecurity Magazine·Oct 12, 17:00 UTC · Oct 12, 2022Vulnerability in the wildCVE-2022-4104060
Week in review: ProxyShell and Realtek SDK vulnerabilities exploitation, automated pentestingHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2021Vulnerability in the wildCVE-2021-35395160
Multiple Flaws Affecting Realtek Wi-Fi SDKs Impact Nearly a Million IoT DevicesThe Hacker News·Aug 24, 04:42 UTC · Aug 24, 2021Vulnerability in the wildCVE-2021-35392CVE-2021-35393CVE-2021-35394+1 CVEs60
NSA says it found new critical vulnerabilities in Microsoft Exchange ServerCyberScoop·Apr 13, 19:37 UTC · Apr 13, 2021Vulnerability in the wild60
US racing to address Microsoft vulnerabilities, especially for small businessesCyberScoop·Mar 22, 19:55 UTC · Mar 22, 2021Vulnerability in the wild60
Week in review: Password psychology, SaltStack Salt vulnerabilities exploited, Patch Tuesday forecastHelp Net Security·May 10, 00:00 UTC · May 10, 2020Vulnerability in the wild60
SaltStack Salt vulnerabilities actively exploited by attackers, patch ASAP!Help Net Security·May 4, 00:00 UTC · May 4, 2020Vulnerability in the wildCVE-2020-11651CVE-2020-1165260
Chinese hackers hit Citrix, Cisco vulnerabilities in sweeping campaignCyberScoop·Mar 25, 15:16 UTC · Mar 25, 2020Vulnerability in the wildCVE-2019-1978160
Power struggle: Government-funded researchers investigate vulnerabilities in EV charging stationsCyberScoop·Feb 25, 16:36 UTC · Feb 25, 2019Vulnerability in the wild60
Congress on Juniper patches: What took so long?CyberScoop·Apr 20, 15:27 UTC · Apr 20, 2016Vulnerability in the wild60