Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breachHelp Net Security·Apr 26, 00:00 UTC · Apr 26, 2026Ransomware in the wildCVE-2026-20133CVE-2026-21876CVE-2026-2895060
Cl0p announces rules for extortion negotiation after MOVEit hackHelp Net Security·Jun 8, 10:36 UTC · Jun 8, 2026Ransomware60
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here's What We Know.Security Affairs·Jul 12, 14:39 UTC · Jul 12, 2026Exploit / PoC in the wildCVE-2023-2448960
PoC for critical Progress Flowmon vulnerability released (CVE-2024-2389)Help Net Security·Apr 24, 00:00 UTC · Apr 24, 2024Exploit / PoCCVE-2024-238960
Leading with Intelligence: Winning Against Credential TheftRecorded Future·Jun 23, 00:00 UTC · Jun 23, 2026Ransomware60
Clop Ransomware Gang Likely Aware of MOVEit Transfer Vulnerability Since 2021The Hacker News·Jun 9, 15:38 UTC · Jun 9, 2023Ransomware in the wildCVE-2023-3436260
Welltok data breach impacted 8.5 million patients in the U.S.Security Affairs·Nov 23, 14:49 UTC · Nov 23, 2023Data breachCVE-2023-3436260
Telerik Report Server Flaw Could Let Attackers Create Rogue Admin AccountsThe Hacker News·Jun 5, 05:26 UTC · Jun 5, 2024Vulnerability in the wildCVE-2024-4358CVE-2024-180060
Sony sent data breach notifications to about 6,800 individualsSecurity Affairs·Oct 5, 06:24 UTC · Oct 5, 2023Data breachCVE-2023-3436260
US cyber officials offer technical details associated with CL0P ransomware attacksCyberScoop·Jun 7, 20:12 UTC · Jun 7, 2023Ransomware in the wildCVE-2023-346260
MOVEit app mass-exploited last month patches new critical vulnerabilityArs Technica · Security·Jul 7, 19:10 UTC · Jul 7, 2023Vulnerability in the wildCVE-2023-3693460
Progress quietly fixes MOVEit auth bypass flaws (CVE-2024-5805, CVE-2024-5806)Help Net Security·Jun 8, 10:33 UTC · Jun 8, 2026Vulnerability in the wildCVE-2024-5805CVE-2024-580660
Hackers seen exploiting bugs in browsers and popular file transfer toolThe Record·Oct 3, 13:21 UTC · Oct 3, 2023Ransomware in the wildCVE-2023-5217CVE-2023-4004460
Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670)Help Net Security·Jun 8, 10:28 UTC · Jun 8, 2026VulnerabilityCVE-2026-4670CVE-2026-5174CVE-2023-3436260
Third Flaw Uncovered in MOVEit Transfer App Amidst Cl0p Ransomware Mass AttackThe Hacker News·Jun 19, 08:42 UTC · Jun 19, 2023RansomwareCVE-2023-35708CVE-2023-35036CVE-2023-3436260
It's time to patch your MOVEit Transfer solution again!Help Net Security·Jun 12, 00:00 UTC · Jun 12, 2023Vulnerability in the wildCVE-2023-3436260
New Critical MOVEit Transfer SQL Injection Vulnerabilities DiscoveredThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2023Vulnerability in the wildCVE-2023-3436260
PoC exploit for exploited MOVEit vulnerability released (CVE-2023-34362)Help Net Security·Jun 13, 00:00 UTC · Jun 13, 2023Exploit / PoCCVE-2023-34362CVE-2023-3503660
MOVEit Developer Patches Critical File Transfer BugInfosecurity Magazine·Sep 29, 09:30 UTC · Sep 29, 2023VulnerabilityCVE-2023-40044CVE-2023-4265760
National Student Clearinghouse data breach impacted approximately 900 US schoolsSecurity Affairs·Sep 24, 09:19 UTC · Sep 24, 2023Data breachCVE-2023-3436260
Warning: VMware vCenter and Kemp LoadMaster Flaws Under Active ExploitationThe Hacker News·Nov 21, 03:53 UTC · Nov 21, 2024Ransomware in the wildCVE-2024-1212CVE-2024-38812CVE-2024-38813+1 CVEs60
Almost 900 US Schools Breached Via MOVEitInfosecurity Magazine·Sep 25, 09:30 UTC · Sep 25, 2023Data breach60
Progress warns customers of a new critical flaw in MOVEit TransferSecurity Affairs·Jul 7, 16:49 UTC · Jul 7, 2023RansomwareCVE-2023-36934CVE-2023-36932CVE-2023-3693360
MOVEit Transfer software zeroSecurity Affairs·Jun 7, 13:57 UTC · Jun 7, 2023Exploit / PoC in the wild60
Concerns grow as LockBit knockoffs increasingly target popular vulnerabilitiesThe Record·Oct 19, 19:27 UTC · Oct 19, 2023RansomwareCVE-2023-4004460
Progress WhatsUp Gold Exploited Just Hours After PoC Release for Critical FlawThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2024Exploit / PoC in the wildCVE-2024-6670CVE-2024-6671CVE-2024-4885+1 CVEs60
7 DevSecOps myths and how to overcome themHelp Net Security·Jun 22, 00:00 UTC · Jun 22, 2022Data breach60
Clop Starts MOVEit Extortion as New Bug is DiscoveredInfosecurity Magazine·Jun 16, 08:45 UTC · Jun 16, 2023RansomwareCVE-2023-34362CVE-2023-3503660
CISA: US agency breached by cybercriminals, gov’t hackersThe Record·Mar 15, 18:29 UTC · Mar 15, 2023Data breachCVE-2019-18935CVE-2017-11357CVE-2017-11317+1 CVEs60
Is it bad to have a major security incident on your résumé? (Seriously I don’t know)Cisco Talos·Oct 5, 18:00 UTC · Oct 5, 2023RansomwareCVE-2023-4004460
Third-party risk management best practices and why they matterHelp Net Security·Feb 15, 11:52 UTC · Feb 15, 2024Ransomware in the wild60
Microsoft Patches 61 Flaws, Including Two Actively Exploited ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2024Vulnerability in the wildCVE-2024-4671CVE-2024-4761CVE-2024-30040+9 CVEs60
Now’s not the time to take our foot off the gas when it comes to fighting disinformation onlineCisco Talos·Jun 8, 18:00 UTC · Jun 8, 2023RansomwareCVE-2023-34362CVE-2023-307960
Clop: Behind MOVEit Lies a Loud, Adaptable and Persistent Threat GroupInfosecurity Magazine·Jul 11, 17:15 UTC · Jul 11, 2023RansomwareCVE-2023-3436260
Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS VulnerabilityThe Hacker News·Dec 11, 15:01 UTC · Dec 11, 2024Vulnerability in the wildCVE-2024-49138CVE-2022-24521CVE-2022-37969+6 CVEs60
2023 Threat Analysis and 2024 PredictionsRecorded Future·Jun 26, 00:00 UTC · Jun 26, 2026RansomwareCVE-2023-2799760
CISA Alerts on Active Exploitation of Flaws in Fortinet, Ivanti, and Nice ProductsThe Hacker News·Mar 28, 04:45 UTC · Mar 28, 2024Ransomware in the wildCVE-2023-48788CVE-2021-44529CVE-2019-7256+1 CVEs60
Progress Discloses Two New Vulnerabilities in MOVEit ProductsInfosecurity Magazine·Jun 26, 17:15 UTC · Jun 26, 2024Vulnerability in the wildCVE-2024-5806CVE-2024-580560
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246)Help Net Security·Nov 9, 00:00 UTC · Nov 9, 2023Exploit / PoCCVE-2023-47246CVE-2023-3436260
Third-Party Cyber Attacks: The Threat No One Sees ComingThe Hacker News·Jul 30, 09:59 UTC · Jul 30, 2024Ransomware60