September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Cisco fixes critical and high-severity flaws in Data Center Network ManagerSecurity Affairs·Jul 31, 14:51 UTC · Jul 31, 2020Exploit / PoCCVE-2020-3382CVE-2020-3377CVE-2020-3384+4 CVEs60
Hackers get into Dropbox developer accounts on GitHub, access 130 code repositories and moreThe Record·Dec 22, 00:00 UTC · Dec 22, 2022Ransomware160
Firefox Browser vulnerable to Man-in-theThe Hacker News·Sep 19, 10:44 UTC · Sep 19, 2016Vulnerability55
AI agents are still logging in as humansHelp Net Security·Jul 21, 00:00 UTC · Jul 21, 2026Policy & legal155
The latest on BlueKeep and DejaBlue vulnerabilities — Using Firepower to defend against encrypted DejaBlueCisco Talos·Nov 4, 15:43 UTC · Nov 4, 2019Vulnerability in the wildCVE-2019-0708CVE-2019-1181CVE-2019-118260
Defending Microsoft Exchange from encrypted attacks with Cisco Secure IPSCisco Talos·Mar 23, 20:50 UTC · Mar 23, 2021VulnerabilityCVE-2021-26855CVE-2021-2706560
Week in review: Cisco fixes critical UCCX flaws, November 2025 Patch Tuesday forecastHelp Net Security·Nov 9, 00:00 UTC · Nov 9, 2025Vulnerability in the wildCVE-2025-48703CVE-2025-11371CVE-2025-20358+1 CVEs60
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active ExploitationThe Hacker News·Sep 8, 14:09 UTC · Sep 8, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-30406CVE-2025-393560
Mixed-signal circuits can stop side-channel attacks against IoT devicesHelp Net Security·Oct 24, 08:47 UTC · Oct 24, 2025Vulnerability55
Sitecore zero-day vulnerability exploited by attackers (CVE-2025-53690)Help Net Security·Sep 4, 00:00 UTC · Sep 4, 2025Exploit / PoCCVE-2025-5369060
Sitecore zero-day vulnerability springs up from exposed machine keyCyberScoop·Sep 4, 17:34 UTC · Sep 4, 2025Exploit / PoC in the wildCVE-2025-5369060
Identity Is Now the Top Source of Cloud RiskInfosecurity Magazine·Nov 4, 13:00 UTC · Nov 4, 2025Vulnerability55
CMS Provider Sitecore Patches Exploited Critical Zero DayInfosecurity Magazine·Sep 4, 13:30 UTC · Sep 4, 2025VulnerabilityCVE-2025-5369060
How LiteLLM Turned Developer Machines Into Credential Vaults for AttackersThe Hacker News·Apr 8, 10:59 UTC · Apr 8, 2026Vulnerability155
Zero trust physical security needs trust decisions at the edgeHelp Net Security·Jun 2, 00:00 UTC · Jun 2, 2026Exploit / PoC60
Cloud-audit: Fast, open-source AWS security scannerHelp Net Security·Apr 20, 06:36 UTC · Apr 20, 2026Tools55
Cisco Data Center Network Manager flaws fixed, Cisco ASA appliances under attackHelp Net Security·Jan 16, 09:36 UTC · Jan 16, 2020Exploit / PoC in the wildCVE-2019-15975CVE-2019-15976CVE-2019-15977+2 CVEs60
ToolShell Exploit: Critical SharePoint ZeroRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs160
Cisco fixes small business routers, kills eavesdropping vulnerability in conferencing devicesHelp Net Security·Nov 10, 10:47 UTC · Nov 10, 2019Vulnerability in the wild60
Instagram hacked! Hacker compromised the entire platformSecurity Affairs·Dec 19, 10:27 UTC · Dec 19, 2015Vulnerability55
The Persistence Problem: Why Exposed Credentials Remain Unfixed—and How to Change ThatThe Hacker News·May 12, 11:00 UTC · May 12, 2025Vulnerability55
Concentric AI unveils deep-learning driven detection capabilitiesHelp Net Security·May 18, 00:00 UTC · May 18, 2023Data breach60
Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to TargetsThe Hacker News·Jul 11, 04:04 UTC · Jul 11, 2025Vulnerability55
The Rise of S3 Ransomware: How to Identify and Combat ItThe Hacker News·Oct 25, 11:36 UTC · Oct 25, 2023Ransomware60
Security Affairs newsletter Round 362 by Pierluigi PaganiniSecurity Affairs·Apr 24, 08:55 UTC · Apr 24, 2022Ransomware in the wildCVE-2022-2068560
Organizations are creating the perfect storm by not implementing security basicsHelp Net Security·Jun 10, 00:00 UTC · Jun 10, 2020Data breach60
Why machine identities matter (and how to use them)Help Net Security·Mar 21, 00:00 UTC · Mar 21, 2022Ransomware60
Double Robotics Telepresence Robot can be hackedHelp Net Security·Jul 18, 20:19 UTC · Jul 18, 2018Vulnerability55
Black Kingdom ransomwareKaspersky Securelist·Jun 17, 09:42 UTC · Jun 17, 2021RansomwareCVE-2021-27065CVE-2019-11510CVE-2021-26855+2 CVEs60
Yubico's latest authentication keys get the jump on a 'passwordless' futureCyberScoop·Sep 24, 20:29 UTC · Sep 24, 2018Exploit / PoC in the wild60
Tricking attackers through the art of deceptionHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2019Vulnerability55
Top must-visit companies at RSAC 2026Help Net Security·Mar 23, 00:00 UTC · Mar 23, 2026Vulnerability55
Top companies to visit at Black Hat USA 2026Help Net Security·Jul 30, 00:00 UTC · Jul 30, 2026Vulnerability55
The Future of Serverless Security in 2025: From Logs to Runtime ProtectionThe Hacker News·Nov 28, 11:30 UTC · Nov 28, 2024Vulnerability in the wild60
Aruba Central NetConductor enables IT teams to automate network configurationHelp Net Security·Mar 30, 00:00 UTC · Mar 30, 2022Industry55