GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking AttackThe Hacker News·May 29, 05:25 UTC · May 29, 2024RansomwareCVE-2021-44228CVE-2023-24860CVE-2023-3601060
Thai Officials Targeted in Yokai Backdoor Campaign Using DLL SideThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2024MalwareCVE-2017-11882160
Remcos RAT Malware Evolves with New TechniquesInfosecurity Magazine·Dec 12, 16:30 UTC · Dec 12, 2024MalwareCVE-2017-1188260
AvosLocker Ransomware Variant Using New Trick to Disable Antivirus ProtectionThe Hacker News·May 3, 05:50 UTC · May 3, 2022RansomwareCVE-2021-40539CVE-2021-4422860
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
CISA, FBI Warn of Medusa Ransomware Impacting Critical InfrastructureInfosecurity Magazine·Mar 13, 16:30 UTC · Mar 13, 2025RansomwareCVE-2024-1709CVE-2023-4878860
Citrix NetScaler Alert: Ransomware Hackers Exploiting Critical VulnerabilityThe Hacker News·Aug 30, 03:26 UTC · Aug 30, 2023RansomwareCVE-2023-351960
FIN8-linked actor targets Citrix NetScaler systemsSecurity Affairs·Aug 29, 15:14 UTC · Aug 29, 2023RansomwareCVE-2023-351960
Ransomware group exploits Citrix NetScaler systems for initial accessHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2023Ransomware in the wildCVE-2023-351960
Iran-linked APT Rocket Kitten exploited VMware bug in recent attacksSecurity Affairs·Apr 26, 18:01 UTC · Apr 26, 2022VulnerabilityCVE-2022-2295460
Ransomware operators target CVE-2020Security Affairs·Nov 7, 17:28 UTC · Nov 7, 2020RansomwareCVE-2020-1488260
Review: Group-IB Threat Hunting FrameworkHelp Net Security·Jun 15, 08:51 UTC · Jun 15, 2021Ransomware60
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
Middle East-linked hacking group is working hard to mask its movesCyberScoop·May 20, 22:26 UTC · May 20, 2019Exploit / PoC60
The return of the AdvisorsBot malwareSecurity Affairs·Feb 1, 16:46 UTC · Feb 1, 2019MalwareCVE-2017-1188260
Quarterly Report: Incident Response Trends in Q4 2022Cisco Talos·Jan 26, 09:00 UTC · Jan 26, 2023Ransomware60
What the continued escalation of tensions in the Middle East means for securityCisco Talos·Jan 8, 22:32 UTC · Jan 8, 2020Vulnerability in the wildCVE-2018-2025060
13,000 MikroTik Routers Hijacked by Botnet for Malspam and CyberattacksThe Hacker News·Jan 21, 12:46 UTC · Jan 21, 2025Malware in the wildCVE-2023-3079960
Iranian group Pay2Key.I2P ramps Up ransomware attacks against Israel and US with incentives for affiliatesSecurity Affairs·Jul 9, 12:37 UTC · Jul 9, 2025Ransomware60
Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the GlobeThe Hacker News·Jan 9, 14:12 UTC · Jan 9, 2024Ransomware60
Hackers Behind Cuba Ransomware Attacks Using New RAT MalwareThe Hacker News·Aug 12, 02:23 UTC · Aug 12, 2022RansomwareCVE-2022-24521CVE-2020-147260
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & MoreThe Hacker News·Dec 31, 05:07 UTC · Dec 31, 2025Malware in the wildCVE-2025-14847CVE-2020-12812CVE-2025-68664+7 CVEs260
VMware advances intrinsic security for the world’s digital infrastructureHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2020Data breach60
⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 BitThe Hacker News·Sep 22, 15:16 UTC · Sep 22, 2025Ransomware in the wildCVE-2025-10585CVE-2025-55241CVE-2025-10035+14 CVEs160
Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBotPalo Alto Unit 42·Jun 5, 23:28 UTC · Jun 5, 2024MalwareCVE-2017-1188260
Multiple threat actors exploit PHP flaw CVE-2024Security Affairs·Jul 11, 14:31 UTC · Jul 11, 2024Threat actor in the wildCVE-2024-4577CVE-2012-182360
New Mispadu Banking Trojan Exploiting Windows SmartScreen FlawThe Hacker News·Feb 5, 15:49 UTC · Feb 5, 2024Malware in the wildCVE-2023-3602560
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More StoriesThe Hacker News·Jan 10, 14:25 UTC · Jan 10, 2026MalwareCVE-2025-59295CVE-2025-10294CVE-2025-5923060
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & VibeThe Hacker News·Mar 9, 18:22 UTC · Mar 9, 2026Data breach in the wildCVE-2026-21385CVE-2026-2796CVE-2026-2256+13 CVEs60
From credit card fraud to zero-day exploits: Xe Group expanding cybercriminal effortsCyberScoop·Feb 3, 14:03 UTC · Feb 3, 2025Exploit / PoC60
CVE-2019-2725 Oracle WebLogic flaw exploited in cryptojacking campaignSecurity Affairs·Jun 11, 05:53 UTC · Jun 11, 2019Vulnerability in the wildCVE-2019-272560
APT29 group exploited WinRAR 0day in attacks against embassiesSecurity Affairs·Nov 20, 13:44 UTC · Nov 20, 2023Threat actorCVE-2023-3883160
Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware DeliveryThe Hacker News·Feb 12, 06:21 UTC · Feb 12, 2026Malware in the wildCVE-2025-0108CVE-2024-41713CVE-2024-10914+2 CVEs60
Is Emotet gang targeting companies with external SOC?Security Affairs·Oct 14, 17:49 UTC · Oct 14, 2019Exploit / PoC60
Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVDSecurity Affairs·Oct 27, 10:45 UTC · Oct 27, 2025Ransomware60
Spam and phishing in Q1 2021Kaspersky Securelist·May 3, 10:00 UTC · May 3, 2021Phishing & fraud in the wild60