vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code ExecutionThe Hacker News·May 11, 03:55 UTC · May 11, 2026VulnerabilityCVE-2026-24118CVE-2026-24120CVE-2023-37466+11 CVEs60
CosmicSting attack & defense overviewSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Data breach in the wildCVE-2024-2961CVE-2024-3410260
Adobe fixes actively exploited Acrobat Reader flaw CVE-2026Security Affairs·Apr 12, 17:47 UTC · Apr 12, 2026Data breach in the wildCVE-2026-3462160
Mass PolyShell attack wave hits 471 stores in one hourSansec (Magento / e-commerce security)·Mar 31, 07:45 UTC · Mar 31, 2026Vulnerability in the wildCVE-2026-7565060
Apple urges iPhone users to update as Coruna and DarkSword exploit kits emergeSecurity Affairs·Mar 20, 11:22 UTC · Mar 20, 2026Exploit / PoCCVE-2021-30952CVE-2022-48503CVE-2023-43000+15 CVEs160
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet FormulasThe Hacker News·Jan 27, 14:07 UTC · Jan 27, 2026VulnerabilityCVE-2026-24002CVE-2025-6866860
Google fixed a new actively exploited Chrome zeroSecurity Affairs·Dec 11, 18:19 UTC · Dec 11, 2025Exploit / PoC in the wildCVE-2025-14372CVE-2025-14373CVE-2025-6554+6 CVEs60
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution FlawsThe Hacker News·Dec 10, 09:13 UTC · Dec 10, 2025VulnerabilityCVE-2025-59718CVE-2025-59719CVE-2025-10573+6 CVEs60
APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ DomainsThe Hacker News·Nov 22, 06:13 UTC · Nov 22, 2025Threat actorCVE-2012-0158CVE-2014-1761CVE-2025-808860
Google fixed the seventh Chrome zeroSecurity Affairs·Nov 18, 08:59 UTC · Nov 18, 2025Exploit / PoC in the wildCVE-2025-13223CVE-2025-13224CVE-2025-10585+5 CVEs60
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
When Browsers Become the Attack Surface: Rethinking Security for Scattered SpiderThe Hacker News·Sep 1, 11:55 UTC · Sep 1, 2025Ransomware60
Russian Espionage Operation Targets Organizations Tied to Ukraine WarInfosecurity Magazine·May 16, 11:15 UTC · May 16, 2025Threat actorCVE-2024-11182CVE-2023-4377060
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February]The Hacker News·May 6, 07:05 UTC · May 6, 2025Ransomware in the wildCVE-2024-57726CVE-2024-57727CVE-2024-57728+18 CVEs60
Case Study: Are CSRF Tokens Sufficient in Preventing CSRF Attacks?The Hacker News·Apr 3, 10:49 UTC · Apr 3, 2025Data breach60
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of CaseThe Hacker News·Dec 24, 05:50 UTC · Dec 24, 2024Malware in the wild160
U.S. CISA adds Cisco ASA and FTD, and RoundCube Webmail bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 25, 07:40 UTC · Oct 25, 2024Exploit / PoC in the wildCVE-2024-20481CVE-2024-3738360
Google fixes seventh actively exploited Chrome zeroSecurity Affairs·May 16, 13:13 UTC · May 16, 2024Exploit / PoC in the wildCVE-2024-4947CVE-2024-4671CVE-2024-4761+7 CVEs160
Cybercriminal adoption of browser fingerprintingHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2024Threat actor60
New iPhone Exploit Uses Four Zero-DaysSchneier on Security·Jan 4, 12:11 UTC · Jan 4, 2024Exploit / PoCCVE-2023-41990CVE-2023-32434CVE-2023-38606+1 CVEs60
4-year campaign backdoored iPhones using possibly the most advanced exploit everArs Technica · Security·Dec 27, 17:03 UTC · Dec 27, 2023MalwareCVE-2023-32434CVE-2023-32435CVE-2023-38606+1 CVEs160
Operation Triangulation: The last (hardware) mysteryKaspersky Securelist·Dec 27, 14:00 UTC · Dec 27, 2023Vulnerability in the wildCVE-2023-41990CVE-2023-32434CVE-2023-38606+1 CVEs160
Apple news: iLeakage attack, MAC address leakage bugHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2023Exploit / PoCCVE-2023-32434CVE-2023-4284660
CISA adds Zimbra bug exploited in attacks against NATO countries to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 8, 22:11 UTC · Apr 8, 2023Exploit / PoC in the wildCVE-2022-2792660
Google fixed the ninth actively exploited Chrome zeroday this yearSecurity Affairs·Dec 3, 15:24 UTC · Dec 3, 2022Exploit / PoC in the wildCVE-2022-4262CVE-2022-4135CVE-2022-3723+6 CVEs60
IT threat evolution Q3 2022Kaspersky Securelist·Nov 18, 08:00 UTC · Nov 18, 2022RansomwareCVE-2017-1027160
F5 warns its customers of tens of flaws in its productsSecurity Affairs·May 5, 09:47 UTC · May 5, 2022VulnerabilityCVE-2022-1388CVE-2022-25946CVE-2022-27806+1 CVEs60
How Just Visiting A Site Could Have Hacked Your iPhone or MacBook CameraThe Hacker News·Jan 31, 05:24 UTC · Jan 31, 2022Exploit / PoCCVE-2020-3852CVE-2020-3864CVE-2020-3865+4 CVEs60
Tackling cross-site request forgery (CSRF) on company websitesHelp Net Security·Mar 23, 00:00 UTC · Mar 23, 2021Exploit / PoC in the wild60
Vulnerability Spotlight: Remote code execution vulnerabilities in Adobe Acrobat ReaderCisco Talos·May 12, 17:00 UTC · May 12, 2020Vulnerability in the wildCVE-2020-9607CVE-2020-960960
100k+ WordPress sites exposed to hack due to a bug in RealSecurity Affairs·Apr 28, 09:03 UTC · Apr 28, 2020Exploit / PoC in the wild60
Crooks are attempting to take over tens of thousands of WordPress sitesSecurity Affairs·Feb 29, 16:15 UTC · Feb 29, 2020Exploit / PoC in the wild60
Vulnerability Spotlight: Information leak vulnerability in Adobe Acrobat ReaderCisco Talos·Dec 10, 19:48 UTC · Dec 10, 2019Vulnerability in the wildCVE-2019-1646360
Vulnerability Spotlight: Google V8 Array.prototype memory corruption vulnerabilityCisco Talos·Jul 1, 13:57 UTC · Jul 1, 2019Vulnerability in the wildCVE-2019-583160
Magecart hackers change tactic and target vulnerable Magento extensionsSecurity Affairs·Oct 24, 20:55 UTC · Oct 24, 2018Exploit / PoC60
Magecart strikes again, this time at electronics retailer NeweggCyberScoop·Sep 19, 15:35 UTC · Sep 19, 2018Exploit / PoC in the wild60
Arxan launches advanced protection for client-side web appsHelp Net Security·Sep 14, 00:00 UTC · Sep 14, 2018Data breach60
Firefox 0-day exploited in the wild to unmask Tor usersHelp Net Security·Jun 26, 21:24 UTC · Jun 26, 2018Exploit / PoC in the wild60