CVE-2024-3400 exploited: Unit 42, Volexity share more details about the attacksHelp Net Security·Apr 17, 09:48 UTC · Apr 17, 2024VulnerabilityCVE-2024-340060
A new Insomnia iOS exploit used to spy on China's Uyghur minoritySecurity Affairs·Apr 22, 09:48 UTC · Apr 22, 2020Vulnerability42
Experts warn of mass exploitation of an RCE flaw in Zimbra Collaboration SuiteSecurity Affairs·Aug 12, 08:00 UTC · Aug 12, 2022Vulnerability in the wildCVE-2022-27925CVE-2022-37042CVE-2022-2792460
CISA orders civilian agencies to patch Zimbra bug after mass exploitationThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-37042CVE-2022-27925CVE-2022-2792460
Ivanti spots ‘sharp increase’ in targeting of VPN as analysts find 1,700 devices exploitedThe Record·Jan 16, 19:11 UTC · Jan 16, 2024VulnerabilityCVE-2023-46805CVE-2024-2188735
Ivanti Connect Secure zero-days exploited by attackers (CVE-2023-46805, CVE-2024-21887)Help Net Security·Jan 16, 16:05 UTC · Jan 16, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-2188760
Zimbra RCE Vulnerability Exploited Without Admin PrivilegesInfosecurity Magazine·Aug 11, 17:30 UTC · Aug 11, 2022Vulnerability in the wildCVE-2022-27925CVE-2022-3704260
Chinese Hackers Using New iPhone Hack to Spy On Uyghur MuslimsThe Hacker News·Apr 23, 09:43 UTC · Apr 23, 2020Vulnerability30
Attackers phish OAuth codes, take over Microsoft 365 accountsHelp Net Security·Apr 23, 00:00 UTC · Apr 23, 2025Vulnerability130
Chinese hackers compromised an ISP to deliver malicious software updatesHelp Net Security·Aug 5, 00:00 UTC · Aug 5, 2024Vulnerability42
Ivanti customers urged to patch vulnerabilities allegedly exploited by Chinese state hackersThe Record·Jan 10, 21:02 UTC · Jan 10, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-2188760
Chinese APT groups targeting India, Pakistan and more with Sophos firewall vulnerabilityThe Record·Jan 13, 00:00 UTC · Jan 13, 2023VulnerabilityCVE-2022-104060
Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN CredentialsThe Hacker News·Nov 18, 03:52 UTC · Nov 18, 2024Vulnerability55
Unpatched critical Atlassian Confluence ZeroSecurity Affairs·Jun 3, 10:13 UTC · Jun 3, 2022Vulnerability in the wildCVE-2022-26134CVE-2021-2608460
Palo Alto Networks firewalls under attack, hotfixes incoming! (CVE-2024-3400)Help Net Security·Apr 30, 13:30 UTC · Apr 30, 2024VulnerabilityCVE-2024-340035
CISA issues emergency directive for federal agencies to patch Ivanti VPN vulnerabilitiesCyberScoop·Jan 19, 22:13 UTC · Jan 19, 2024Vulnerability in the wild60
Patch released for exploited Atlassian zeroThe Record·Jan 13, 00:00 UTC · Jan 13, 2023Vulnerability in the wildCVE-2022-2613460
Why think tanks are such juicy targets for cyberspiesThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability42
Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE VulnerabilityThe Hacker News·Aug 12, 06:14 UTC · Aug 12, 2022Vulnerability in the wildCVE-2022-27925CVE-2022-37042CVE-2022-2792460
Hackers Exploiting Unpatched Critical Atlassian Confluence ZeroThe Hacker News·Jun 3, 09:27 UTC · Jun 3, 2022Vulnerability in the wildCVE-2022-26134CVE-2021-2608460
How the SolarWinds Hackers Bypassed Duo's Multi-Factor AuthenticationSchneier on Security·Dec 15, 00:00 UTC · Dec 15, 2020Vulnerability30
Mass exploitation of Ivanti VPNs is infecting networks around the globeArs Technica · Security·Jan 24, 01:36 UTC · Jan 24, 2024Vulnerability in the wild60
U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM VulnerabilityThe Hacker News·Jan 20, 04:42 UTC · Jan 20, 2024Vulnerability in the wildCVE-2023-35082CVE-2023-35078CVE-2023-35081+2 CVEs60
Ivanti vulnerabilities are being exploited widely, CISA says in emergency directiveThe Record·Jan 19, 19:54 UTC · Jan 19, 2024VulnerabilityCVE-2023-46805CVE-2024-2188735
Friday Squid Blogging: More Squid Camouflage ResearchSchneier on Security·Apr 28, 21:07 UTC · Apr 28, 2023Vulnerability42
Atlassian Releases Patch for Confluence ZeroThe Hacker News·Jun 4, 08:57 UTC · Jun 4, 2022Vulnerability in the wildCVE-2022-26134CVE-2021-2608460
CISA adds recently disclosed Zimbra bug to its Exploited Vulnerabilities CatalogThe Hacker News·Mar 1, 04:37 UTC · Mar 1, 2022Vulnerability in the wildCVE-2022-24682CVE-2017-8570CVE-2017-0222+1 CVEs60
Hackers Exploited 0-Day Vulnerability in Zimbra Email Platform to Spy on UsersThe Hacker News·Feb 4, 13:18 UTC · Feb 4, 2022Vulnerability55
VMware Flaw a Vector in SolarWinds Breach?Krebs on Security·Dec 20, 02:19 UTC · Dec 20, 2020VulnerabilityCVE-2020-400647
Hackers Exploiting Drupal Vulnerability to Inject Cryptocurrency MinersThe Hacker News·Apr 18, 09:50 UTC · Apr 18, 2018Vulnerability in the wildCVE-2018-7600CVE-2017-1027160
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
China-Linked Hackers Target Asian Governments, NATO State, Journalists, and ActivistsThe Hacker News·May 2, 06:30 UTC · May 2, 2026VulnerabilityCVE-2025-5518260
Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global RegionsThe Hacker News·Jun 2, 10:08 UTC · Jun 2, 2025VulnerabilityCVE-2017-1188235
Chinese spies targeting new Ivanti vulnerability, Mandiant saysThe Record·Jan 9, 20:38 UTC · Jan 9, 2025Vulnerability in the wildCVE-2025-0282CVE-2023-46805CVE-2024-21887160
Week in review: Tips for starting your cybersecurity career, Patch Tuesday forecastHelp Net Security·Aug 11, 00:00 UTC · Aug 11, 2024VulnerabilityCVE-2024-42219CVE-2024-42218CVE-2024-38856+2 CVEs160
Five Eyes Warn of Ivanti Vulnerabilities ExploitationInfosecurity Magazine·Mar 1, 12:00 UTC · Mar 1, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Ivanti publishes urgent warning about new vulnerabilityThe Record·Feb 8, 22:05 UTC · Feb 8, 2024Vulnerability in the wildCVE-2024-2202460
Agencies using vulnerable Ivanti products have until Saturday to disconnect themArs Technica · Security·Feb 1, 23:45 UTC · Feb 1, 2024Vulnerability in the wildCVE-2024-21888CVE-2024-2189360
Adobe, Microsoft and Citrix vulnerabilities draw warnings from CISAThe Record·Jul 18, 19:46 UTC · Jul 18, 2023Vulnerability in the wildCVE-2023-29298CVE-2023-38203CVE-2023-36884+1 CVEs60