CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively ExploitedThe Hacker News·Jun 26, 16:00 UTC · Jun 26, 2026Advisory in the wildCVE-2025-67038CVE-2026-34908CVE-2026-34909+1 CVEs60
Patch now: TP-Link Archer NX routers vulnerable to firmware takeoverSecurity Affairs·Mar 25, 14:44 UTC · Mar 25, 2026Vulnerability in the wildCVE-2025-15517CVE-2025-15605CVE-2025-9377+1 CVEs60
Critical Zyxel router flaw exposed devices to remote attacksSecurity Affairs·Feb 25, 20:28 UTC · Feb 25, 2026VulnerabilityCVE-2025-13942CVE-2026-1459CVE-2025-11847+4 CVEs60
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in OnThe Hacker News·Jan 9, 10:01 UTC · Jan 9, 2026VulnerabilityCVE-2025-69258CVE-2025-69259CVE-2025-6926060
Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy DThe Hacker News·Jan 7, 09:23 UTC · Jan 7, 2026Vulnerability in the wildCVE-2026-062560
U.S. CISA adds a flaw in Digiever DS-2105 Pro to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 23, 08:43 UTC · Dec 23, 2025Exploit / PoC in the wildCVE-2023-5216360
Ivanti warns customers of new EPM flaw enabling remote code executionSecurity Affairs·Dec 9, 22:11 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-10573CVE-2024-13159CVE-2024-13160+1 CVEs60
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
CISA Adds 3 D-Link Vulnerabilities to KEV Catalog Amid Active Exploitation EvidenceThe Hacker News·Aug 6, 06:51 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2020-25078CVE-2020-25079CVE-2020-4079960
U.S. CISA adds D-Link cameras and Network Video Recorder flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 6, 06:09 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2020-25078CVE-2020-25079CVE-2022-4079960
⚡ Weekly Recap: APT Intrusions, AI Malware, ZeroThe Hacker News·Jun 3, 04:04 UTC · Jun 3, 2025Malware in the wildCVE-2025-3935CVE-2025-47577CVE-2025-2760+14 CVEs60
251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and ElasticsearchThe Hacker News·May 28, 09:23 UTC · May 28, 2025Vulnerability in the wildCVE-2018-15961CVE-2017-5638CVE-2022-26134+2 CVEs60
CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek DevicesThe Hacker News·Mar 29, 03:45 UTC · Mar 29, 2025Vulnerability in the wildCVE-2019-9874CVE-2019-9875CVE-2020-8515+2 CVEs60
Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig MinersThe Hacker News·Mar 19, 15:52 UTC · Mar 19, 2025Malware in the wildCVE-2024-457760
Patch it up: Old vulnerabilities are everyone’s problemsCisco Talos·Mar 13, 18:04 UTC · Mar 13, 2025Vulnerability in the wildCVE-2025-22224CVE-2024-457760
CISA Adds Five Actively Exploited Vulnerabilities in Advantive VeraCore and Ivanti EPM to KEV ListThe Hacker News·Mar 11, 04:06 UTC · Mar 11, 2025Exploit / PoC in the wildCVE-2024-57968CVE-2025-25181CVE-2024-13159+3 CVEs60
Winnti APT41 Targets Japanese Firms in RevivalStone Cyber Espionage CampaignThe Hacker News·Feb 20, 03:54 UTC · Feb 20, 2025Threat actor60
U.S. CISA adds Microsoft Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 12, 08:01 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2024-40891CVE-2024-40890CVE-2025-21418+1 CVEs60
Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024The Hacker News·Feb 5, 04:14 UTC · Feb 5, 2025Vulnerability in the wildCVE-2024-40891CVE-2024-40890CVE-2024-57726+3 CVEs60
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [6 Jan]The Hacker News·Jan 6, 12:05 UTC · Jan 6, 2025Exploit / PoCCVE-2024-49113CVE-2024-49112160
Apache Tomcat Vulnerability CVE-2024The Hacker News·Dec 24, 06:06 UTC · Dec 24, 2024VulnerabilityCVE-2024-56337CVE-2024-50379CVE-2024-1282860
AndroxGh0st Malware Integrates Mozi Botnet to Target IoT and Cloud ServicesThe Hacker News·Dec 18, 10:49 UTC · Dec 18, 2024MalwareCVE-2021-41773CVE-2018-15133CVE-2017-9841+12 CVEs60
Ivanti Releases Urgent Security Updates for Endpoint Manager VulnerabilitiesThe Hacker News·Sep 12, 04:16 UTC · Sep 12, 2024Vulnerability in the wildCVE-2024-29847CVE-2024-32840CVE-2024-32842+8 CVEs60
Zyxel fixes critical command injection flaw in EOL NAS devices (CVE-2024-6342)Help Net Security·Sep 10, 00:00 UTC · Sep 10, 2024Vulnerability in the wildCVE-2024-6342CVE-2024-2997360
Critical flaw in Zyxel's secure routers allows OS command execution via cookie (CVE-2024-7261)Help Net Security·Sep 3, 00:00 UTC · Sep 3, 2024VulnerabilityCVE-2024-7261CVE-2024-6343CVE-2024-7203+6 CVEs60
Multiple threat actors exploit PHP flaw CVE-2024Security Affairs·Jul 11, 14:31 UTC · Jul 11, 2024Threat actor in the wildCVE-2024-4577CVE-2012-182360
Ransomware Surges Annually Despite Law Enforcement TakedownsInfosecurity Magazine·Jul 11, 10:45 UTC · Jul 11, 2024RansomwareCVE-2024-457760
Week in review: JetBrains GitHub plugin vulnerability, 20k FortiGate appliances compromisedHelp Net Security·Jun 16, 00:00 UTC · Jun 16, 2024VulnerabilityCVE-2024-37051CVE-2024-4577CVE-2024-30080+1 CVEs160
CISA adds Arm Mali GPU Kernel Driver, PHP bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 13, 20:45 UTC · Jun 13, 2024Exploit / PoC in the wildCVE-2024-4610CVE-2024-4577CVE-2012-1823160
Top 10 Critical Pentest Findings 2024: What You Need to KnowThe Hacker News·Jun 11, 12:43 UTC · Jun 11, 2024Data breachCVE-2019-0708CVE-2018-120760
PHP addressed critical RCE potentially impacting millions of serversSecurity Affairs·Jun 9, 13:27 UTC · Jun 9, 2024VulnerabilityCVE-2024-4577CVE-2012-182360
Network Attack Trends: FebruaryPalo Alto Unit 42·Jun 6, 12:33 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-25296CVE-2021-25297CVE-2021-25298+4 CVEs60
Network Security Trends: MayPalo Alto Unit 42·Jun 6, 01:20 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2020-11978CVE-2020-13927CVE-2021-2785060
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious PurposesPalo Alto Unit 42·Jun 6, 01:14 UTC · Jun 6, 2024Exploit / PoCCVE-2017-9506CVE-2017-12629CVE-2019-2767+23 CVEs60
US Government Urges Action to Mitigate Androxgh0st Malware ThreatInfosecurity Magazine·Jan 17, 11:05 UTC · Jan 17, 2024Malware in the wildCVE-2017-9841CVE-2018-15133CVE-2021-4177360
Nation-State Actors Weaponize Ivanti VPN ZeroThe Hacker News·Jan 17, 01:56 UTC · Jan 17, 2024Threat actor in the wildCVE-2023-46805CVE-2024-21887160
Ivanti Connect Secure zero-days exploited by attackers (CVE-2023-46805, CVE-2024-21887)Help Net Security·Jan 16, 16:05 UTC · Jan 16, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-2188760
Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networksArs Technica · Security·Jan 10, 22:18 UTC · Jan 10, 2024Malware in the wildCVE-2023-46805CVE-2024-2188760
CISA adds five vulnerabilities in Juniper devices to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 13, 18:51 UTC · Nov 13, 2023Exploit / PoC in the wildCVE-2023-36844CVE-2023-36845CVE-2023-36846+3 CVEs160