ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Gamaredon APT targeted a western government entity in UkraineSecurity Affairs·Feb 4, 11:50 UTC · Feb 4, 2022Vulnerability55
How LiteLLM Turned Developer Machines Into Credential Vaults for AttackersThe Hacker News·Apr 8, 10:59 UTC · Apr 8, 2026Vulnerability155
Unit 42 Cloud Threat Report Update: Cloud Security Weakens as More Organizations Fail to Secure IAMPalo Alto Unit 42·Jun 6, 12:17 UTC · Jun 6, 2024Vulnerability55
Commvault Confirms Hackers Exploited CVE-2025-3928 as ZeroThe Hacker News·May 1, 10:52 UTC · May 1, 2025Vulnerability in the wildCVE-2025-392860
SharePoint vulnerability with 9.8 severity rating under exploit across globeArs Technica · Security·Jul 21, 19:30 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation DetectedThe Hacker News·Jan 29, 06:05 UTC · Jan 29, 2026Vulnerability in the wildCVE-2026-2485860
Anetac Human Link Pro secures both human and non-human identitiesHelp Net Security·Apr 28, 00:00 UTC · Apr 28, 2025Vulnerability55
New Research Highlights Vulnerabilities in MLOps PlatformsInfosecurity Magazine·Jan 7, 17:15 UTC · Jan 7, 2025Vulnerability55
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal CredentialsThe Hacker News·Apr 2, 19:30 UTC · Apr 2, 2026VulnerabilityCVE-2025-5518260
29,000 Servers Remain Unpatched Against Microsoft Exchange FlawInfosecurity Magazine·Aug 12, 16:00 UTC · Aug 12, 2025Vulnerability in the wildCVE-2025-5378660
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from JanuaryRecorded Future·Mar 13, 00:00 UTC · Mar 13, 2026Vulnerability in the wildCVE-2025-15556CVE-2026-21513CVE-2026-21533+4 CVEs160
Unpatched Travis CI API Bug Exposes Thousands of Secret User Access TokensThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2022Vulnerability155
Behind the Scenes: The Art of Safeguarding NonThe Hacker News·Mar 28, 16:57 UTC · Mar 28, 2024Vulnerability55
Day Zero Readiness: The Operational Gaps That Break Incident ResponseThe Hacker News·May 7, 10:54 UTC · May 7, 2026Vulnerability55
Improper cloud IAM leaving organizations at riskHelp Net Security·Apr 20, 09:56 UTC · Apr 20, 2026Vulnerability55
Why CISA is Warning CISOs About a Breach at SisenseKrebs on Security·Apr 11, 21:08 UTC · Apr 11, 2024Vulnerability55
Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber AttacksThe Hacker News·Jul 22, 07:16 UTC · Jul 22, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Exposed BMCs hand out password hashes before loginHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2026VulnerabilityCVE-2013-478660
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)Help Net Security·Jul 22, 00:00 UTC · Jul 22, 2026Vulnerability in the wildCVE-2026-50522CVE-2026-56164CVE-2026-58644160
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AICisco Talos·Aug 4, 10:00 UTC · Aug 4, 2026Vulnerability55
Uptycs helps users strengthen security posture with CIEM capabilitiesHelp Net Security·May 5, 00:00 UTC · May 5, 2022Vulnerability55
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
Notepad++ patches flaw used to hijack update systemSecurity Affairs·Feb 18, 19:28 UTC · Feb 18, 2026VulnerabilityCVE-2026-25926160
Critical Zero-Click Flaw in n8n Allows Full Server CompromiseInfosecurity Magazine·Mar 12, 15:28 UTC · Mar 12, 2026VulnerabilityCVE-2026-27493CVE-2026-2757760
FamousSparrow targets Azerbaijani energy sector in multiSecurity Affairs·May 14, 08:17 UTC · May 14, 2026Vulnerability55
How Google’s 90-day TLS certificate validity proposal will affect enterprisesHelp Net Security·Apr 11, 00:00 UTC · Apr 11, 2024Vulnerability55
Unit 42 Cloud Security Trends and TipsPalo Alto Unit 42·Jan 28, 20:53 UTC · Jan 28, 2022Vulnerability55
99.9% of fixable AI vulnerabilities remain unpatchedHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2026Vulnerability55
The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change ThatThe Hacker News·May 12, 11:00 UTC · May 12, 2025Vulnerability55
SecuriThings and Axis join forces to improve customers' end-to-end visibility and controlHelp Net Security·Nov 18, 00:00 UTC · Nov 18, 2022Vulnerability55
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of DisclosureThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
February 2026 Patch Tuesday forecast: Lots of OOB love this monthHelp Net Security·Feb 16, 10:29 UTC · Feb 16, 2026VulnerabilityCVE-2026-21509CVE-2025-8088160
Organizations still don't know how to handle non-human identitiesHelp Net Security·Sep 16, 07:28 UTC · Sep 16, 2024Vulnerability55
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)Help Net Security·Jul 30, 00:00 UTC · Jul 30, 2026Vulnerability in the wildCVE-2026-20316CVE-2026-20079CVE-2026-20131160
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE FlawsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2025-54518CVE-2026-41096CVE-2026-42826+14 CVEs160
The impact of the Log4j vulnerability on OT networksHelp Net Security·Dec 16, 00:00 UTC · Dec 16, 2021Vulnerability in the wildCVE-2021-4422860
6 Considerations For 2025 Cybersecurity Investment DecisionsHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2025Vulnerability55
Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent InstabilityThe Hacker News·Feb 18, 11:58 UTC · Feb 18, 2026Vulnerability55