CISA warns about actively exploited Broadcom, Commvault vulnerabilitiesHelp Net Security·May 23, 14:23 UTC · May 23, 2025Vulnerability in the wildCVE-2025-3928CVE-2025-42599CVE-2025-197660
Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation ConfirmedThe Hacker News·May 10, 06:43 UTC · May 10, 2025Exploit / PoC in the wildCVE-2025-34028CVE-2025-392860
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud MisconfigsThe Hacker News·May 23, 05:16 UTC · May 23, 2025Advisory in the wildCVE-2025-392860
Commvault measures cyber recovery readiness with AI attack simulationsHelp Net Security·Jul 7, 00:00 UTC · Jul 7, 2026Vulnerability in the wild60
Commvault Confirms Hackers Exploited CVE-2025-3928 as ZeroThe Hacker News·May 1, 10:52 UTC · May 1, 2025Vulnerability in the wildCVE-2025-392860
Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028)Help Net Security·May 5, 07:42 UTC · May 5, 2025Exploit / PoC in the wildCVE-2025-3402860
U.S. CISA adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 1, 20:46 UTC · May 1, 2025Exploit / PoC in the wildCVE-2025-1976CVE-2025-42599CVE-2025-392860
CISA Adds Actively Exploited Broadcom and Commvault Flaws to KEV DatabaseThe Hacker News·May 1, 07:46 UTC · May 1, 2025Exploit / PoC in the wildCVE-2025-1976CVE-2025-392860
Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution AttacksThe Hacker News·Aug 21, 16:38 UTC · Aug 21, 2025Vulnerability in the wildCVE-2025-57788CVE-2025-57789CVE-2025-57790+2 CVEs160
U.S. CISA adds Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 3, 10:11 UTC · May 3, 2025Exploit / PoC in the wildCVE-2025-34028CVE-2024-58136CVE-2025-32432260
Critical Commvault Command Center Flaw Enables Attackers to Execute Code RemotelyThe Hacker News·Apr 24, 10:00 UTC · Apr 24, 2025Data breach in the wildCVE-2025-3402860
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-dayHelp Net Security·Aug 24, 00:00 UTC · Aug 24, 2025Exploit / PoC in the wildCVE-2025-43300CVE-2018-0171CVE-2025-31324+1 CVEs60
CrowdStrike warns of uptick in Silk Typhoon attacks this summerCyberScoop·Aug 22, 16:39 UTC · Aug 22, 2025Exploit / PoC in the wildCVE-2023-3519CVE-2025-392860
Week in review: Critical SAP NetWeaver flaw exploited, RSAC 2025 ConferenceHelp Net Security·May 4, 00:00 UTC · May 4, 2025Ransomware in the wildCVE-2025-31324CVE-2025-3928CVE-2025-42599+1 CVEs60
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
Top 25 Most Dangerous Software Weaknesses of 2025 RevealedInfosecurity Magazine·Dec 15, 10:45 UTC · Dec 15, 2025Data breach in the wild60
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 BugsThe Hacker News·Sep 11, 08:56 UTC · Sep 11, 2025Vulnerability in the wildCVE-2025-53791CVE-2025-55234CVE-2025-54914+9 CVEs60
⚡ Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-theThe Hacker News·Aug 27, 05:11 UTC · Aug 27, 2025Ransomware in the wildCVE-2018-0171CVE-2025-43300CVE-2025-7353+5 CVEs60
Security Affairs newsletter Round 525 by Pierluigi PaganiniSecurity Affairs·May 31, 21:54 UTC · May 31, 2025Ransomware in the wild60
U.S. CISA adds GoVision device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 8, 08:04 UTC · May 8, 2025Exploit / PoC in the wildCVE-2024-6047CVE-2024-1112060
U.S. CISA adds SonicWall SMA100 and Apache HTTP Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 2, 07:50 UTC · May 2, 2025Exploit / PoC in the wildCVE-2024-38475CVE-2023-4422160
Week in review: AWS S3 data encrypted without ransomware, data of 15k Fortinet firewalls leakedHelp Net Security·Jan 19, 00:00 UTC · Jan 19, 2025Ransomware in the wildCVE-2024-55591CVE-2025-0282CVE-2024-734460
Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security toolsHelp Net Security·Oct 13, 00:00 UTC · Oct 13, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-9680+5 CVEs160
Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widensHelp Net Security·Dec 3, 00:00 UTC · Dec 3, 2023Exploit / PoC in the wildCVE-2023-46214CVE-2023-49103CVE-2023-41998+5 CVEs260
Week in review: 7 cybersecurity audiobooks to read, Patch Tuesday forecastHelp Net Security·Oct 9, 00:00 UTC · Oct 9, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2022-3525660
Week in review: Revolut data breach, ManageEngine RCE flaw, free Linux security training coursesHelp Net Security·Sep 25, 00:00 UTC · Sep 25, 2022Data breach in the wildCVE-2007-4559CVE-2022-35405CVE-2022-31671+4 CVEs60