Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Why Patch Management Isn’t Enough: SharePoint, Webshells & the Modern Threat LandscapeRecorded Future·Aug 11, 00:00 UTC · Aug 11, 2025VulnerabilityCVE-2023-4724660
BadCandy Webshell threatens unpatched Cisco IOS XE devices, warns Australian governmentSecurity Affairs·Nov 1, 17:41 UTC · Nov 1, 2025VulnerabilityCVE-2023-2019835
(Re)check your patched NetScaler ADC and Gateway appliances for signs of compromiseHelp Net Security·Aug 16, 00:00 UTC · Aug 16, 2023VulnerabilityCVE-2023-351960
JSP webshells being dropped on unpatched PTC Windchill instancesHelp Net Security·Jul 27, 12:30 UTC · Jul 27, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-468160
Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)Help Net Security·Jun 26, 09:26 UTC · Jun 26, 2026Vulnerability in the wildCVE-2026-20230CVE-2026-2004560
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324)Help Net Security·Aug 20, 08:46 UTC · Aug 20, 2025Vulnerability in the wildCVE-2025-3132460
China-linked group Fire Ant exploits VMware and F5 flaws since early 2025Security Affairs·Jul 28, 08:28 UTC · Jul 28, 2025VulnerabilityCVE-2023-34048CVE-2023-20867CVE-2022-138860
Ongoing exploitation of CVE-2022-41352 (Zimbra 0Kaspersky Securelist·Oct 13, 08:00 UTC · Oct 13, 2022VulnerabilityCVE-2022-41352CVE-2015-119747
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
Attackers Conducting Cryptojacking Operation Against U.S. Education OrganizationsPalo Alto Unit 42·Jun 6, 13:25 UTC · Jun 6, 2024Vulnerability42
Threat Advisory: Microsoft warns of actively exploited vulnerabilities in Exchange ServerCisco Talos·Sep 30, 21:16 UTC · Sep 30, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-4108260
Unpatched Microsoft Exchange ZeroSecurity Affairs·Sep 30, 07:25 UTC · Sep 30, 2022Vulnerability in the wild60
Mass PolyShell attack wave hits 471 stores in one hourSansec (Magento / e-commerce security)·Mar 31, 07:45 UTC · Mar 31, 2026Vulnerability in the wildCVE-2026-7565060
Exploit for critical SAP Netweaver flaws released (CVE-2025-31324, CVE-2025-42999)Help Net Security·Aug 20, 00:00 UTC · Aug 20, 2025Vulnerability in the wildCVE-2025-31324CVE-2025-42999CVE-2025-30012+4 CVEs60
SharePoint vulnerability with 9.8 severity rating under exploit across globeArs Technica · Security·Jul 21, 19:30 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Turning Criminal Forum Exploit Chatter Into Vulnerability Risk AnalysisRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2016-3081CVE-2015-2419CVE-2015-4852+1 CVEs47
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Unpatched critical Atlassian Confluence ZeroSecurity Affairs·Jun 3, 10:13 UTC · Jun 3, 2022Vulnerability in the wildCVE-2022-26134CVE-2021-2608460
Suspected Chinese Threat Group Targets UniversitiesInfosecurity Magazine·Jul 7, 15:40 UTC · Jul 7, 2026VulnerabilityCVE-2024-42009CVE-2025-4911347
Unauthenticated remote code execution in JTL ShopSansec (Magento / e-commerce security)·Jun 18, 19:31 UTC · Jun 18, 2026Vulnerability in the wildCVE-2026-5439060
Over 200 PrestaShop stores expose installer, allowing full takeoverSansec (Magento / e-commerce security)·Apr 14, 13:40 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521)Help Net Security·Mar 30, 10:17 UTC · Mar 30, 2026Vulnerability in the wildCVE-2025-5352160
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security·Feb 15, 00:00 UTC · Feb 15, 2026Vulnerability in the wildCVE-2026-1731CVE-2024-12356CVE-2026-1281+2 CVEs60
Commvault plugs holes in backup suite that allow remote code executionHelp Net Security·Aug 20, 00:00 UTC · Aug 20, 2025VulnerabilityCVE-2025-57788CVE-2025-57789CVE-2025-57791+2 CVEs47
What to know about ToolShell, the SharePoint threat under mass exploitationArs Technica · Security·Jul 23, 20:14 UTC · Jul 23, 2025Vulnerability in the wildCVE-2025-49706CVE-2025-4970460
Chained Vulnerabilities Exploited in Ivanti Cloud Service AppliancesInfosecurity Magazine·Jan 23, 16:30 UTC · Jan 23, 2025VulnerabilityCVE-2024-8963CVE-2024-9379CVE-2024-8190+1 CVEs160
Attackers are trying to exploit Apache Struts vulnerability (CVE-2023-50164)Help Net Security·Dec 18, 09:23 UTC · Dec 18, 2023Vulnerability in the wildCVE-2023-5016460
CISA, experts warn of Citrix vulnerabilities being exploited by hackersThe Record·Aug 16, 21:19 UTC · Aug 16, 2023VulnerabilityCVE-2023-24489CVE-2023-351947
Critical Microsoft Azure RCE flaw impacted multiple servicesSecurity Affairs·Jan 19, 16:02 UTC · Jan 19, 2023Vulnerability55
CISA orders civilian agencies to patch Zimbra bug after mass exploitationThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-37042CVE-2022-27925CVE-2022-2792460
Two Microsoft Exchange zero-days exploited by attackers (CVE-2022-41040, CVE-2022-41082)Help Net Security·Oct 3, 10:39 UTC · Oct 3, 2022VulnerabilityCVE-2022-41040CVE-2022-4108260
Threat actors are actively exploiting CVE-2022-1388 RCE in F5 BIGSecurity Affairs·May 10, 06:42 UTC · May 10, 2022VulnerabilityCVE-2022-138860
Tens of AccessPress WordPress themes compromised as part of a supply chain attackSecurity Affairs·Jan 24, 20:33 UTC · Jan 24, 2022VulnerabilityCVE-2021-2486747
Determined APT is exploiting ManageEngine ServiceDesk Plus vulnerability (CVE-2021-44077)Help Net Security·Dec 3, 00:00 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-33617160