H1 2025 Malware and Vulnerability TrendsRecorded Future·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability in the wild60
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway VulnerabilityThe Hacker News·Sep 24, 06:24 UTC · Sep 24, 2025Vulnerability in the wildCVE-2025-5968960
Iranian state-sponsored hackers exploiting printer vulnerabilityThe Record·May 8, 20:30 UTC · May 8, 2023Vulnerability in the wildCVE-2023-2735060
State-sponsored attackers actively exploiting RCE in Citrix devices, patch ASAP! (CVE-2022-27518)Help Net Security·Apr 24, 13:36 UTC · Apr 24, 2023Vulnerability in the wildCVE-2022-2751860
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from JanuaryRecorded Future·Mar 13, 00:00 UTC · Mar 13, 2026Vulnerability in the wildCVE-2025-15556CVE-2026-21513CVE-2026-21533+4 CVEs160
Week in review: Notepad++ supply chain attack details and targets, Patch Tuesday forecastHelp Net Security·Feb 8, 00:00 UTC · Feb 8, 2026Vulnerability in the wildCVE-2026-21509CVE-2025-22225CVE-2026-2442360
Windows Shortcut Flaw Exploited by 11 StateInfosecurity Magazine·Mar 19, 16:30 UTC · Mar 19, 2025Vulnerability in the wild60
Published Vulnerabilities Surge by 43%Infosecurity Magazine·Aug 30, 14:00 UTC · Aug 30, 2024Vulnerability in the wild60
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025Security Affairs·Mar 19, 14:48 UTC · Mar 19, 2026Vulnerability in the wildCVE-2025-6637660
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
CISA orders federal agencies to patch exploited SolarWinds, Apple, Microsoft bugs within weeksThe Record·Feb 13, 14:58 UTC · Feb 13, 2026Vulnerability in the wildCVE-2025-40536CVE-2026-20700CVE-2025-14174+5 CVEs160
Notepad++ Update Hijacking Linked to Hosting Provider CompromiseInfosecurity Magazine·Feb 2, 15:15 UTC · Feb 2, 2026Vulnerability in the wild57
WinRAR vulnerability still a go-to tool for hackers, Mandiant warnsHelp Net Security·Jan 28, 00:00 UTC · Jan 28, 2026Vulnerability in the wildCVE-2025-808860
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat ActorsRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-5518260
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & MoreThe Hacker News·Dec 6, 11:14 UTC · Dec 6, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-38352CVE-2025-48543+25 CVEs160
CISA, VMware warn of new vulnerabilities being exploited by hackersThe Record·Mar 4, 21:25 UTC · Mar 4, 2025Vulnerability in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
CISA: Cisco and CrushFTP vulnerabilities are being actively exploitedThe Record·Apr 24, 19:07 UTC · Apr 24, 2024Vulnerability in the wildCVE-2024-20353CVE-2024-20359CVE-2024-404060
Week in review: Apache Struts vulnerability exploit attempt, EOL Sophos firewalls get hotfixHelp Net Security·Dec 17, 00:00 UTC · Dec 17, 2023Vulnerability in the wildCVE-2022-3236CVE-2023-50164CVE-2021-44228+1 CVEs60
Week in review: KeePass vulnerability, Apple fixes exploited WebKit 0-daysHelp Net Security·May 21, 00:00 UTC · May 21, 2023Vulnerability in the wildCVE-2023-28204CVE-2023-32373CVE-2023-32409+1 CVEs60
Hackers exploiting vulnerability affecting Zoho ManageEngine products: Rapid7The Record·Feb 3, 00:00 UTC · Feb 3, 2023Vulnerability in the wildCVE-2022-47966CVE-2021-4053960
RCE on Log4j Among Top CVEs Exploited By ChineseInfosecurity Magazine·Oct 7, 17:02 UTC · Oct 7, 2022Vulnerability in the wild60
Threat Source newsletter for Oct. 1, 2020Cisco Talos·Oct 1, 18:00 UTC · Oct 1, 2020Vulnerability in the wildCVE-2020-1472CVE-2020-3421CVE-2020-348060
Cyber Command’s bug bounty program uncovers more than 30 vulnerabilitiesCyberScoop·Oct 15, 02:13 UTC · Oct 15, 2019Vulnerability in the wild60
Senators draft bill to turn government's vulnerabilities equities process into lawCyberScoop·Mar 23, 00:01 UTC · Mar 23, 2017Vulnerability in the wild60
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)Help Net Security·Aug 6, 06:54 UTC · Aug 6, 2026Vulnerability in the wildCVE-2026-6307760
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OSThe Hacker News·Jul 8, 14:38 UTC · Jul 8, 2026Vulnerability in the wildCVE-2026-50746CVE-2026-50747CVE-2026-50748+7 CVEs60
Langflow Vulnerability CVE-2026The Hacker News·Jun 12, 04:10 UTC · Jun 12, 2026Vulnerability in the wildCVE-2026-5027CVE-2026-0770CVE-2026-33017+2 CVEs60
Google Patches Actively Exploited Android Flaw Affecting Millions of DevicesSecurity Affairs·Jun 3, 09:44 UTC · Jun 3, 2026Vulnerability in the wildCVE-2025-4859560
PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News·May 7, 17:58 UTC · May 7, 2026Vulnerability in the wildCVE-2026-030060
Root-level RCE vulnerability in Palo Alto firewalls exploited (CVE-2026-0300)Help Net Security·May 6, 00:00 UTC · May 6, 2026Vulnerability in the wildCVE-2026-030060
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
US, UK agencies warn hackers were hiding on Cisco firewalls long after patches were appliedCyberScoop·Apr 23, 20:25 UTC · Apr 23, 2026Vulnerability in the wildCVE-2025-20333CVE-2025-2036260
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621260
Software vulnerabilities push credential abuse aside in cloud intrusionsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2026Vulnerability in the wild60
Patch, track, repeat: The 2025 CVE retrospectiveCisco Talos·Mar 5, 19:00 UTC · Mar 5, 2026Vulnerability in the wildCVE-2026-2138560
Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacksCyberScoop·Feb 25, 13:30 UTC · Feb 25, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60