iOS zero-click attacks used to deliver Graphite spyware (CVE-2025-43200)Help Net Security·Jun 16, 19:19 UTC · Jun 16, 2025Vulnerability in the wildCVE-2025-43200CVE-2025-2420060
CISA: Patch Samsung flaw exploited to deliver spyware (CVE-2025-21042)Help Net Security·Nov 11, 00:00 UTC · Nov 11, 2025Vulnerability in the wildCVE-2025-21042CVE-2025-2104360
Donot Team targets a Togo prominent activist with IndianSecurity Affairs·Jun 3, 10:23 UTC · Jun 3, 2025VulnerabilityCVE-2017-019947
Candiru: Another Cyberweapons Arms ManufacturerSchneier on Security·Aug 14, 19:52 UTC · Aug 14, 2021VulnerabilityCVE-2021-31979CVE-2021-3377135
Apple issues emergency patch to address alleged spyware vulnerabilityCyberScoop·Jun 21, 20:55 UTC · Jun 21, 2023Vulnerability in the wildCVE-2023-32434CVE-2023-3243560
June 2023 Security Update for Android fixed Arm Mali GPU bug used by spywareSecurity Affairs·Jun 7, 13:09 UTC · Jun 7, 2023Vulnerability in the wildCVE-2022-22706CVE-2023-21127CVE-2023-21108+1 CVEs60
Serbian civilians targeted with Pegasus on eve of national electionsThe Record·Nov 22, 17:58 UTC · Nov 22, 2023Vulnerability55
3 iOS 0-days, a cellular network compromise, and HTTP used to infect an iPhoneArs Technica · Security·Sep 23, 00:23 UTC · Sep 23, 2023VulnerabilityCVE-2023-41993CVE-2023-41991CVE-2023-41992+1 CVEs60
Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware AttackThe Hacker News·Mar 10, 05:52 UTC · Mar 10, 2026Vulnerability in the wildCVE-2025-43300CVE-2025-55177CVE-2025-31255+13 CVEs60
Ireland Proposes Giving Police New Digital Surveillance PowersSchneier on Security·Jan 26, 12:04 UTC · Jan 26, 2026Vulnerability30
Jury orders NSO Group to pay $168 million to WhatsApp for facilitating Pegasus hacks of its usersThe Record·May 7, 00:21 UTC · May 7, 2025Vulnerability55
Judge unlikely to allow expert testimony for NSO as jury decides damages in WhatsApp caseThe Record·Apr 11, 19:24 UTC · Apr 11, 2025Vulnerability30
More on NSO Group and Cytrox: Two Cyberweapons Arms ManufacturersSchneier on Security·Dec 20, 15:17 UTC · Dec 20, 2021Vulnerability30
Burner phones are an eavesdropping risk for international travelersHelp Net Security·Jan 7, 00:00 UTC · Jan 7, 2020Vulnerability55
WhatsApp flaw CVE-2019-11931 could be exploited to install spywareSecurity Affairs·Nov 16, 14:02 UTC · Nov 16, 2019VulnerabilityCVE-2019-11931CVE-2019-356860
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from OctoberRecorded Future·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability in the wildCVE-2025-64446CVE-2025-58034CVE-2025-21042+1 CVEs60
ICE Reinstates Contract with ParagonInfosecurity Magazine·Sep 2, 17:10 UTC · Sep 2, 2025VulnerabilityCVE-2025-4320060
WhatsApp fixed a spoofing flaw that could enable Remote Code ExecutionSecurity Affairs·Apr 8, 14:25 UTC · Apr 8, 2025VulnerabilityCVE-2025-3040160
Apple Patches Two ZeroInfosecurity Magazine·Sep 8, 09:30 UTC · Sep 8, 2023Vulnerability in the wildCVE-2023-41064CVE-2023-4106160
Apple patches against alleged NSO Group zeroCyberScoop·Sep 13, 20:17 UTC · Sep 13, 2021Vulnerability in the wild60
A cyber-espionage effort against Tibetan leaders leveraged known Android, iOS vulnerabilitiesCyberScoop·Sep 24, 13:57 UTC · Sep 24, 2019Vulnerability in the wild60
CVE-2017-0199 Zero Day exploit used to deliver FINSPY spywareSecurity Affairs·Oct 16, 22:06 UTC · Oct 16, 2017VulnerabilityCVE-2017-019960
Immediately Patch Windows 0-Day Flaw That's Being Used to Spread SpywareThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2017Vulnerability in the wildCVE-2017-8759CVE-2017-8746CVE-2017-8723+1 CVEs60
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
You’d be surprised to know what devices are still using Windows CECisco Talos·Nov 2, 18:00 UTC · Nov 2, 2023Vulnerability in the wildCVE-2023-496660
Google Patches Chrome ZeroInfosecurity Magazine·Sep 28, 10:00 UTC · Sep 28, 2023Vulnerability in the wildCVE-2023-5217CVE-2023-5186CVE-2023-518760
Google TAG argues that Italian surveillance firm RCS Labs was helped by ISPs to infect mobile usersSecurity Affairs·Jun 25, 09:28 UTC · Jun 25, 2022Vulnerability in the wildCVE-2018-4344CVE-2019-8605CVE-2020-3837+3 CVEs60
The six most common threats against the device that knows you bestHelp Net Security·Nov 18, 00:00 UTC · Nov 18, 2021Vulnerability30
Why it's such a bad idea for Trump to use an off-theCyberScoop·Jan 18, 21:08 UTC · Jan 18, 2017Vulnerability30
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
Apple doubles maximum bug bounty to $2M for zeroSecurity Affairs·Oct 10, 23:38 UTC · Oct 10, 2025Vulnerability42
NSO appeals WhatsApp decision, says it can’t pay $168 million in ‘unlawful’ damagesThe Record·Jun 2, 18:08 UTC · Jun 2, 2025Vulnerability30
Apple Rolls Out Security Patches for Actively Exploited iOS ZeroThe Hacker News·Oct 11, 03:55 UTC · Oct 11, 2023Vulnerability in the wildCVE-2023-42824CVE-2023-5217CVE-2023-41991+2 CVEs60
US Government Ordered to Urgently Patch Apple ZeroInfosecurity Magazine·Sep 12, 10:00 UTC · Sep 12, 2023Vulnerability in the wildCVE-2023-41064CVE-2023-4106160
Facebook Bans 7 'Cyber Mercenary' Companies for Spying on 50,000 UsersThe Hacker News·May 20, 09:06 UTC · May 20, 2022Vulnerability30
Three's a crowd: Popular bug bounty companies are growing at an insane rateCyberScoop·Jul 28, 06:11 UTC · Jul 28, 2017Vulnerability55