Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript ZeroPalo Alto Unit 42·Jul 3, 01:11 UTC · Jul 3, 2020Exploit / PoCCVE-2016-6957CVE-2016-695860
RiskIQ JavaScript Threats Module protects orgs' high-traffic payment pages from JavaScript attacksHelp Net Security·Aug 1, 00:00 UTC · Aug 1, 2019Data breach60
The Acrobat JavaScript Blocklist FrameworkCisco Talos·Jan 20, 17:56 UTC · Jan 20, 2010Exploit / PoC in the wildCVE-2008-2992CVE-2009-0927CVE-2009-1493+5 CVEs60
Take a walk on the client side: The importance of front-end JavaScript security assessmentsHelp Net Security·Mar 9, 20:14 UTC · Mar 9, 2023Data breach60
Adobe fixes flaws in Adobe InDesign,Framemaker, Experience ManagerSecurity Affairs·Sep 8, 20:43 UTC · Sep 8, 2020VulnerabilityCVE-2020-9727CVE-2020-9728CVE-2020-9729+15 CVEs60
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 ZeroThe Hacker News·Mar 23, 17:42 UTC · Mar 23, 2026Exploit / PoCCVE-2026-20700CVE-2025-43529CVE-2025-14174+3 CVEs60
Lazarus APT steals cryptocurrency and user data via a decoy MOBA gameKaspersky Securelist·Oct 23, 11:00 UTC · Oct 23, 2024Threat actorCVE-2024-494760
JavaScript attack aimed to reroute bitcoin transactionsCyberScoop·Nov 7, 20:17 UTC · Nov 7, 2018Exploit / PoC in the wild60
Zerodium Offers $1 Million for Tor Browser 0The Hacker News·Sep 15, 00:00 UTC · Sep 15, 2017Exploit / PoC60
Microsoft Patch TuesdayCisco Talos·Jun 13, 20:48 UTC · Jun 13, 2017VulnerabilityCVE-2017-0283CVE-2017-0291CVE-2017-0292+37 CVEs60
Here's why Google is forcing JavaScript use on its signCyberScoop·Nov 1, 14:45 UTC · Nov 1, 2018Exploit / PoC in the wild60
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix AttacksThe Hacker News·Jun 26, 07:33 UTC · Jun 26, 2026VulnerabilityCVE-2026-2698060
Attackers exploit critical Flowise flaw CVE-2025Security Affairs·Apr 7, 20:16 UTC · Apr 7, 2026Exploit / PoC in the wildCVE-2025-59528CVE-2025-8943CVE-2025-2631960
CERT/CC Warns binary-parser Bug Allows Node.js PrivilegeThe Hacker News·Jan 27, 14:10 UTC · Jan 27, 2026VulnerabilityCVE-2026-124560
5 Threats That Reshaped Web Security This Year [2025]The Hacker News·Dec 4, 11:30 UTC · Dec 4, 2025VulnerabilityCVE-2025-54135CVE-2025-53109CVE-2025-5528460
Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage CampaignRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2023-2339760
Google addressed the tenth actively exploited Chrome zeroSecurity Affairs·Aug 26, 22:59 UTC · Aug 26, 2024Exploit / PoC in the wildCVE-2024-7965CVE-2024-7971CVE-2024-5274+7 CVEs60
A Data Exfiltration Attack Scenario: The Porsche ExperienceThe Hacker News·Jul 28, 11:48 UTC · Jul 28, 2023Exploit / PoC60
Week in review: Avast breach, deepfakes, VisibleV8 monitors JavaScript in the wildHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2019Data breach60
Mysterious hackers ingenuously reveal two ZeroSecurity Affairs·May 16, 11:49 UTC · May 16, 2018Exploit / PoCCVE-2018-4990CVE-2018-812060
Zerodium is offers $1 Million for Tor Browser ExploitsSecurity Affairs·Nov 4, 09:24 UTC · Nov 4, 2017Exploit / PoC60
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News·Jul 30, 07:40 UTC · Jul 30, 2026Data breachCVE-2026-42897CVE-2025-6637660
Google addressed the ninth actively exploited Chrome zeroSecurity Affairs·Aug 26, 22:50 UTC · Aug 26, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-0519CVE-2024-2887+6 CVEs60
Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain AttackThe Hacker News·Jun 28, 04:05 UTC · Jun 28, 2024VulnerabilityCVE-2024-34102CVE-2024-296160
Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBotPalo Alto Unit 42·Jun 5, 23:28 UTC · Jun 5, 2024MalwareCVE-2017-1188260
Critical Flaws in vm2 JavaScript Library Can Lead to Remote Code ExecutionThe Hacker News·Apr 20, 04:45 UTC · Apr 20, 2023VulnerabilityCVE-2023-29199CVE-2023-30547CVE-2023-29017+1 CVEs60
Researchers Detail Critical RCE Flaw Reported in Popular vm2 JavaScript SandboxThe Hacker News·Oct 11, 11:28 UTC · Oct 11, 2022VulnerabilityCVE-2022-3606760
Google aims to improve security of browser engines, third-party Android devices and apps on Google PlayHelp Net Security·Oct 7, 11:57 UTC · Oct 7, 2020Exploit / PoC in the wild60
Over 800K WordPress sites are at risk due to a flaw in Ninja Forms pluginSecurity Affairs·May 1, 08:38 UTC · May 1, 2020Exploit / PoC in the wild60
Flaws in Popup Builder WordPress plugin expose 100K+ websites to hackSecurity Affairs·Mar 13, 11:42 UTC · Mar 13, 2020Exploit / PoC in the wildCVE-2020-10196CVE-2020-1019560
Chrome 0-day exploit CVE-2019Kaspersky Securelist·Nov 1, 16:00 UTC · Nov 1, 2019Exploit / PoCCVE-2019-1372060
Protecting applications from malicious scriptsHelp Net Security·Oct 17, 00:00 UTC · Oct 17, 2018Data breach60
Zerodium disclose exploit for NoScript bug in version 7 of Tor BrowserSecurity Affairs·Sep 11, 07:57 UTC · Sep 11, 2018Exploit / PoC60
Samsung Android Browser is affected by a critical SOP bypass issue, a Metasploit exploit code is availableSecurity Affairs·Dec 29, 16:14 UTC · Dec 29, 2017Exploit / PoCCVE-2017-1769260
Critical "Same Origin Policy" Bypass Flaw Found in Samsung Android BrowserThe Hacker News·Dec 29, 12:26 UTC · Dec 29, 2017Exploit / PoCCVE-2017-1769260
Experts at ZDI reported two critical ZeroSecurity Affairs·Aug 22, 07:57 UTC · Aug 22, 2017Exploit / PoCCVE-2017-10951CVE-2017-1095260
The msvidctl Internet Explorer 0dayKaspersky Securelist·Jul 7, 19:58 UTC · Jul 7, 2009Exploit / PoC in the wild60
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660