ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More StoriesThe Hacker News·Jan 10, 14:25 UTC · Jan 10, 2026MalwareCVE-2025-59295CVE-2025-10294CVE-2025-5923060
Three A's of SaaS adoption, and why every company goes through themHelp Net Security·Aug 14, 00:00 UTC · Aug 14, 2018Data breach60
Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete TakeoverThe Hacker News·May 4, 08:19 UTC · May 4, 2024VulnerabilityCVE-2024-28185CVE-2024-28189CVE-2024-2902160
Unauthenticated file upload in Amasty Order Attributes for MagentoSansec (Magento / e-commerce security)·Jun 15, 20:13 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2026-5378760
NailaoLocker ransomware targets EU healthcareSecurity Affairs·Feb 20, 15:48 UTC · Feb 20, 2025RansomwareCVE-2024-2491960
Urgent WordPress Update Fixes Critical Flaw in Jetpack Plugin on Million of SitesThe Hacker News·Jun 1, 04:02 UTC · Jun 1, 2023Exploit / PoC in the wildCVE-2023-2878260
Nightfall AI unveils list of investors and partners with Slack as a DLP vendorHelp Net Security·May 28, 10:03 UTC · May 28, 2020Policy & legal55
Attestiv DeepScan combines AI and forensic analysis for file validationHelp Net Security·Jul 8, 00:00 UTC · Jul 8, 2026Phishing & fraud55
Malware Persistence via Telegram and GitHubSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Malware55
Russia-linked threat actors targets Ukraine with PathWiper wiperSecurity Affairs·Jun 6, 18:30 UTC · Jun 6, 2025Malware55
Microsoft Patch TuesdayCisco Talos·Nov 8, 22:09 UTC · Nov 8, 2016VulnerabilityCVE-2016-7212CVE-2016-7248CVE-2016-7205+8 CVEs60
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious ExtensionsThe Hacker News·Mar 29, 05:21 UTC · Mar 29, 2024Exploit / PoC in the wildCVE-2024-2138860
T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
Unverified COTS hardware enables persistent attacks in small satellites via SpyChainSecurity Affairs·Oct 14, 08:39 UTC · Oct 14, 2025Ransomware60
Critical Cisco Unity Connection flaw gives attackers root privileges. Patch now! (CVE-2024-20272)Help Net Security·Jan 11, 00:00 UTC · Jan 11, 2024Vulnerability in the wildCVE-2024-20272CVE-2023-20269CVE-2023-2019860
Chinese Hackers Caught Stealing Intellectual Property from Multinational CompaniesThe Hacker News·May 4, 13:10 UTC · May 4, 2022Malware55
SEGA Europe left AWS S3 bucket unsecured exposing data and infrastructure to attackSecurity Affairs·Jan 3, 14:26 UTC · Jan 3, 2022Ransomware60
⚡ Weekly Recap: Windows 0-Day, VPN Exploits, Weaponized AI, Hijacked Antivirus and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-29824CVE-2024-11859CVE-2025-3102+17 CVEs60
Warning: 3 Critical Vulnerabilities Expose ownCloud Users to Data BreachesThe Hacker News·Nov 29, 03:36 UTC · Nov 29, 2023Data breach in the wildCVE-2023-49103CVE-2023-49105CVE-2023-49104+1 CVEs60
Top must-visit companies at RSAC 2026Help Net Security·Mar 23, 00:00 UTC · Mar 23, 2026Vulnerability55
Island Enterprise Browser: Intelligent security built into the browsing sessionHelp Net Security·Jul 5, 00:00 UTC · Jul 5, 2023Malware55
Container security requires continuous security in new DevSecOps modelsHelp Net Security·Jan 22, 00:00 UTC · Jan 22, 2020VulnerabilityCVE-2018-1002105160
Qualys at Infosecurity Europe 2018: Best practices presentations from industry leadersHelp Net Security·Jun 4, 00:00 UTC · Jun 4, 2018Vulnerability55
Pastebin just made it easier for hackers to avoid detection, researchers sayCyberScoop·Apr 17, 12:20 UTC · Apr 17, 2020Data breach in the wild60
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential StealerThe Hacker News·May 31, 12:13 UTC · May 31, 2026MalwareCVE-2026-3561660
New Wiper Malware Targets Ukrainian InfrastructureInfosecurity Magazine·Jun 9, 16:00 UTC · Jun 9, 2025Malware55
Researchers found flaws in MEGA that allowed to decrypt of user dataSecurity Affairs·Jun 23, 07:53 UTC · Jun 23, 2022Vulnerability55
FBI, CISA, and CGCYBER warn of nation-state actors exploiting CVE-2021Security Affairs·Sep 16, 22:07 UTC · Sep 16, 2021Threat actor in the wildCVE-2021-4053960
Analyze Recent Atlassian Vulnerabilities and Keep Your Infrastructure ProtectedRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2017VulnerabilityCVE-2017-14589CVE-2019-3394CVE-2019-11581+11 CVEs60
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI CredentialsThe Hacker News·Sep 6, 11:31 UTC · Sep 6, 2025Malware55
How do I select a CDR solution for my business?Help Net Security·Jun 8, 10:39 UTC · Jun 8, 2026Exploit / PoC60
Thousands of Adobe Commerce e-stores hacked by exploiting CosmicSting bugSecurity Affairs·Oct 3, 14:36 UTC · Oct 3, 2024Exploit / PoC in the wildCVE-2024-34102CVE-2024-296160
WordPress Rushes Out Jetpack Patch to MillionsInfosecurity Magazine·May 31, 10:00 UTC · May 31, 2023Vulnerability in the wild60
Jungle Disk announces new software version including Google Cloud Platform supportHelp Net Security·Sep 20, 00:00 UTC · Sep 20, 2018Ransomware60
Critical Vulnerabilities Found in WordPress Plugins WPLMS and VibeBPInfosecurity Magazine·Dec 23, 17:15 UTC · Dec 23, 2024VulnerabilityCVE-2024-56046CVE-2024-56043CVE-2024-5604260
CISA Warns of Actively Exploited Zoho ManageEngine ADSelfService VulnerabilityThe Hacker News·Sep 17, 04:49 UTC · Sep 17, 2021Vulnerability in the wildCVE-2021-40539CVE-2021-37421CVE-2021-37417+3 CVEs60
Mem3nt0 moriKaspersky Securelist·Oct 27, 03:00 UTC · Oct 27, 2025Exploit / PoC in the wildCVE-2025-278360