Week in review: Veeam Backup & Replication RCE fixed, free file converter sites deliver malwareHelp Net Security·Mar 23, 00:00 UTC · Mar 23, 2025Vulnerability in the wildCVE-2025-23120CVE-2024-4824860
Apple fixes 2 zero-days exploited to breach macOS systems (CVE-2024-44309, CVE-2024-44308)Help Net Security·Nov 27, 18:24 UTC · Nov 27, 2024Vulnerability in the wildCVE-2024-44309CVE-2024-4430860
Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)Help Net Security·Nov 4, 00:00 UTC · Nov 4, 2024Vulnerability in the wildCVE-2024-1044360
Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security toolsHelp Net Security·Oct 13, 00:00 UTC · Oct 13, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-9680+5 CVEs160
Critical Acronis Cyber Infrastructure vulnerability exploited in the wild (CVE-2023-45249)Help Net Security·Jul 29, 00:00 UTC · Jul 29, 2024Exploit / PoC in the wildCVE-2023-4524960
PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)Help Net Security·Jun 6, 10:01 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2024-4358CVE-2024-1800CVE-2023-3436260
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
Hackers exploited Windows 0-day for 6 months after Microsoft knew of itArs Technica · Security·Mar 4, 22:47 UTC · Mar 4, 2024Exploit / PoC in the wildCVE-2024-2133860
Two Ivanti ZeroInfosecurity Magazine·Jan 11, 09:30 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2023-35078+1 CVEs60
Citrix Bleed: Mass exploitation in progress (CVE-2023-4966)Help Net Security·Nov 2, 14:31 UTC · Nov 2, 2023Vulnerability in the wildCVE-2023-496660
Turns out even the NFL is worried about deepfakesCisco Talos·Sep 14, 18:01 UTC · Sep 14, 2023Ransomware in the wildCVE-2023-36802CVE-2023-3676160
Security Affairs newsletter Round 425 by Pierluigi PaganiniSecurity Affairs·Jun 25, 15:26 UTC · Jun 25, 2023Ransomware in the wildCVE-2023-20178CVE-2023-20887CVE-2023-27992+4 CVEs60
Where from, Where to — The Evolution of Network SecurityThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2023Ransomware in the wild60
Microsoft patches zero-day exploited by attackers (CVE-2023-28252)Help Net Security·Apr 11, 00:00 UTC · Apr 11, 2023Exploit / PoC in the wildCVE-2023-28252CVE-2023-23376CVE-2023-21554+4 CVEs60
Attackers are attempting to exploit critical F5 BIG-IP RCEHelp Net Security·Feb 21, 17:27 UTC · Feb 21, 2023Vulnerability in the wildCVE-2022-138860
CISA adds F5 vulnerability to catalog of exploited bugsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability in the wildCVE-2022-138860
Apache fixes actively exploited web server zeroThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2021-4177360
Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devicesHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2022Exploit / PoC in the wildCVE-2022-41033CVE-2022-40684CVE-2022-36067+1 CVEs160
Researchers Develop RCE Exploit for the Latest F5 BIGThe Hacker News·May 10, 05:05 UTC · May 10, 2022Vulnerability in the wildCVE-2022-138860
Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-dayHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2022Exploit / PoC in the wildCVE-2022-24521CVE-2022-26904CVE-2022-26809+1 CVEs60
Week in review: Critical RCE in Palo Alto Networks firewalls, how to select a DRaaS solutionHelp Net Security·Nov 14, 00:00 UTC · Nov 14, 2021Vulnerability in the wildCVE-2021-3064CVE-2021-42321CVE-2021-4229260
Aleksandr Zhukov, self-described 'king of fraud,' is sentenced to 10 yearsCyberScoop·Nov 10, 23:05 UTC · Nov 10, 2021Phishing & fraud in the wild60
Week in review: Patch Tuesday forecast, how to select a DLP solution, is it OK to publish PoC exploits?Help Net Security·May 9, 00:00 UTC · May 9, 2021Exploit / PoC in the wild60
Victims of Microsoft Exchange Server zeroCyberScoop·Mar 5, 15:14 UTC · Mar 5, 2021Exploit / PoC in the wild60
CISA Issues Emergency Vulnerability WarningInfosecurity Magazine·Jul 17, 18:01 UTC · Jul 17, 2020Vulnerability in the wildCVE-2020-135060
Threat actors are attempting to exploit recently fixed F5 BIGSecurity Affairs·Jul 8, 12:43 UTC · Jul 8, 2020Threat actor in the wildCVE-2020-590260
Week in review: Fileless malware, usable cybersecurity, Magecart goes after S3 bucketsHelp Net Security·May 13, 13:23 UTC · May 13, 2020Malware in the wild60
Week in review: Password psychology, SaltStack Salt vulnerabilities exploited, Patch Tuesday forecastHelp Net Security·May 10, 00:00 UTC · May 10, 2020Vulnerability in the wild60
Week in review: Cloud migration and cybersecurity, data trending on the dark web, Zoom securityHelp Net Security·Apr 19, 00:00 UTC · Apr 19, 2020Vulnerability in the wildCVE-2020-395260
Two critical Firefox vulnerabilities exploited by attackers, patch now!Help Net Security·Apr 6, 00:00 UTC · Apr 6, 2020Vulnerability in the wildCVE-2020-6819CVE-2020-682060
Firefox 74.0.1 addresses two zeroSecurity Affairs·Apr 4, 16:22 UTC · Apr 4, 2020Exploit / PoC in the wildCVE-2020-6819CVE-2020-6820CVE-2019-1702660
March 2020 Patch Tuesday: Microsoft fixes 115 vulnerabilities, Adobe noneHelp Net Security·Mar 10, 00:00 UTC · Mar 10, 2020Vulnerability in the wildCVE-2020-0852CVE-2020-0684CVE-2020-0872+3 CVEs60
Attackers are targeting vulnerable Fortigate and Pulse Secure SSL VPNsHelp Net Security·Aug 28, 10:05 UTC · Aug 28, 2019Exploit / PoC in the wildCVE-2019-11510CVE-2018-1337960
Magento sites under attack through easily exploitable SQLi flawHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2019Exploit / PoC in the wild60
WordPress Social Warfare plugin zeroSecurity Affairs·Mar 24, 11:01 UTC · Mar 24, 2019Exploit / PoC in the wild60
Google plugs Chrome zero-day exploited in the wildHelp Net Security·Mar 6, 00:00 UTC · Mar 6, 2019Exploit / PoC in the wildCVE-2019-578660
Week in review: CAPTCHA-breaking AI, Australian anti-encryption bill, new issue of (IN)SECUREHelp Net Security·Dec 9, 00:00 UTC · Dec 9, 2018Policy & legal in the wildCVE-2018-1598260
The confrontation that fueled the fallout between Kaspersky and the U.S. governmentCyberScoop·Oct 10, 13:00 UTC · Oct 10, 2017Exploit / PoC in the wild60
Apache Foundation rejects allegation Equifax hackers exploited CVE-2017Security Affairs·Sep 11, 15:51 UTC · Sep 11, 2017Data breach in the wildCVE-2017-9805CVE-2017-563860
SQLi flaw in the NextGEN Gallery plugin exposes at risk of hack more than 1 Million WordPress InstallsSecurity Affairs·Mar 1, 11:00 UTC · Mar 1, 2017Exploit / PoC in the wild60