U.S. CISA adds Microsoft Windows and Rejetto HTTP File Server bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 10, 07:33 UTC · Jul 10, 2024Exploit / PoC in the wildCVE-2024-23692CVE-2024-38080CVE-2024-38112+1 CVEs60
Security Affairs newsletter Round 479 by Pierluigi PaganiniSecurity Affairs·Jul 7, 09:14 UTC · Jul 7, 2024RansomwareCVE-2021-40444CVE-2024-0769CVE-2024-23692+1 CVEs60
Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView PlusThe Hacker News·Jul 5, 03:27 UTC · Jul 5, 2024VulnerabilityCVE-2023-2071CVE-2023-29464CVE-2024-2369260
IT threat evolution Q3 2022Kaspersky Securelist·Nov 18, 08:00 UTC · Nov 18, 2022RansomwareCVE-2017-1027160
Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPYRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025VulnerabilityCVE-2024-2369260
New Lucifer DDoS botnet targets Windows systems with multiple exploitsSecurity Affairs·Jun 26, 06:42 UTC · Jun 26, 2020MalwareCVE-2019-9081CVE-2014-6287CVE-2018-1000861+7 CVEs60
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch ClustersCisco Talos·Feb 26, 18:56 UTC · Feb 26, 2019Vulnerability in the wildCVE-2014-3120CVE-2015-1427CVE-2018-7600+2 CVEs60
Apache patch a zeroSecurity Affairs·Oct 5, 17:15 UTC · Oct 5, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-4152460
Critical shim bug impacts every Linux boot loader signed in the past decadeSecurity Affairs·Feb 7, 14:46 UTC · Feb 7, 2024MalwareCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
CISA Confirms Exploitation of SonicWall VulnerabilitiesInfosecurity Magazine·May 2, 15:00 UTC · May 2, 2025Vulnerability in the wildCVE-2023-44221CVE-2024-3847560
Apache fixes actively exploited web server zeroThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2021-4177360
Critical Boot Loader Vulnerability in Shim Impacts Nearly All Linux DistrosThe Hacker News·Feb 8, 03:11 UTC · Feb 8, 2024VulnerabilityCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
Apache Warns of Zero-Day Exploit in the Wild — Patch Your Web Servers Now!The Hacker News·Oct 7, 05:31 UTC · Oct 7, 2021Exploit / PoC in the wildCVE-2021-41773CVE-2021-4152460
Network Security Trends: AugustPalo Alto Unit 42·Jun 6, 00:57 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-40438CVE-2021-34473CVE-2021-38647+9 CVEs60
Expert published NMAP script for Apache CVE-2021Security Affairs·Oct 9, 12:04 UTC · Oct 9, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-42013160
Apache rolled out a new update in a few days to fix incomplete patch for actively exploited flawSecurity Affairs·Oct 8, 07:38 UTC · Oct 8, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-4201360
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense orgThe Record·Jun 11, 14:16 UTC · Jun 11, 2025Exploit / PoCCVE-2025-3305360
PSA: Conference Invite used as a Lure by Operation Lotus Blossom ActorsPalo Alto Unit 42·Nov 1, 10:25 UTC · Nov 1, 2018VulnerabilityCVE-2012-015860
Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility BillingInfosecurity Magazine·Jun 13, 11:00 UTC · Jun 13, 2025Ransomware in the wildCVE-2024-57727CVE-2024-57728CVE-2024-5772660
CLOP targets Gladinet CentreStack servers in largeSecurity Affairs·Dec 19, 11:48 UTC · Dec 19, 2025Ransomware in the wildCVE-2025-11371CVE-2025-30406CVE-2025-61882+2 CVEs60
Critical Flaws Found in Four VS Code Extensions with Over 125 Million InstallsThe Hacker News·Feb 18, 13:16 UTC · Feb 18, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-65715160
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild60
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Andariel deploys DTrack and Maui ransomwareKaspersky Securelist·Aug 9, 14:25 UTC · Aug 9, 2022RansomwareCVE-2017-1027160
Attack on French Diplomat Linked to Operation Lotus BlossomPalo Alto Unit 42·Nov 1, 09:57 UTC · Nov 1, 2018Exploit / PoCCVE-2014-633260
Healthcare organizations implementing zero trust to tackle cyberattacksHelp Net Security·Feb 5, 13:47 UTC · Feb 5, 2024Ransomware60
Attackers exploited old flaws to breach SonicWall SMA appliances (CVE-2024-38475, CVE-2023-44221)Help Net Security·May 2, 00:00 UTC · May 2, 2025Vulnerability in the wildCVE-2024-38475CVE-2023-4422160
Severe Flaws in SHAREit Android App Let Hackers Steal Your FilesThe Hacker News·Feb 27, 13:22 UTC · Feb 27, 2019Exploit / PoC60
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bugSecurity Affairs·Jan 16, 10:17 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-2039360
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web ManagerSecurity Affairs·Dec 19, 08:53 UTC · Dec 19, 2025Exploit / PoC in the wildCVE-2025-2039360
New Cloud Atlas APT campaignKaspersky Securelist·Dec 19, 10:00 UTC · Dec 19, 2025Threat actorCVE-2018-080260
Let It Ride: The Sofacy Group’s DealersChoice Attacks ContinuePalo Alto Unit 42·Nov 1, 10:41 UTC · Nov 1, 2018Exploit / PoC in the wildCVE-2016-7855CVE-2016-7255CVE-2015-7645160
Critical ASP.NET flaw hits QNAP NetBak PC AgentSecurity Affairs·Oct 28, 12:23 UTC · Oct 28, 2025VulnerabilityCVE-2025-5531560
OilRig campaign, Iran-Linked Hackers Target US Gov. & Energy GridSecurity Affairs·Jan 27, 20:43 UTC · Jan 27, 2018Threat actor60
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 ZeroThe Hacker News·Mar 23, 17:42 UTC · Mar 23, 2026Exploit / PoCCVE-2026-20700CVE-2025-43529CVE-2025-14174+3 CVEs60
Infostealers increasingly impact global securityHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2024MalwareCVE-2010-4598CVE-2011-2474CVE-2014-0130+15 CVEs60
New infostealer reaches enterprise devices through FortiClient EMS vulnerabilityHelp Net Security·May 29, 00:00 UTC · May 29, 2026VulnerabilityCVE-2026-3561660
China-linked APT group Salt Typhoon compromised some US ISPsSecurity Affairs·Sep 26, 14:04 UTC · Sep 26, 2024Threat actor in the wildCVE-2024-20399CVE-2021-3086960
New Ballista Botnet spreads using TPSecurity Affairs·Mar 12, 09:51 UTC · Mar 12, 2025MalwareCVE-2023-138960
GhostSec’s joint ransomware operation and evolution of their arsenalCisco Talos·Mar 5, 13:00 UTC · Mar 5, 2024Ransomware60