ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More StoriesThe Hacker News·Jan 10, 14:25 UTC · Jan 10, 2026MalwareCVE-2025-59295CVE-2025-10294CVE-2025-5923060
A Data Exfiltration Attack Scenario: The Porsche ExperienceThe Hacker News·Jul 28, 11:48 UTC · Jul 28, 2023Exploit / PoC60
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
Ghostwriter group resumes attacks on Ukrainian Government targetsSecurity Affairs·May 15, 10:38 UTC · May 15, 2026Malware55
IT threat evolution Q1 2021Kaspersky Securelist·May 31, 07:32 UTC · May 31, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
New Phishing Attack Uses Sophisticated Infostealer MalwareInfosecurity Magazine·Aug 14, 17:00 UTC · Aug 14, 2024Malware55
North Korea’s Fraudulent IT Employment Scheme: A Cybersecurity ThreatRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Phishing & fraud55
When transparency is also obscurity: The conundrum that is open-source securityHelp Net Security·Oct 4, 00:00 UTC · Oct 4, 2022Vulnerability55
APT review: what the world’s threat actors got up to in 2019Kaspersky Securelist·Dec 4, 10:00 UTC · Dec 4, 2019Threat actor60
ThreatsDay Bulletin: Pixel Zero-Click, Redis RCE, China C2s, RAT Ads, Crypto Scams & 15+ StoriesThe Hacker News·Jan 24, 08:04 UTC · Jan 24, 2026Vulnerability55
Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limitsHelp Net Security·Apr 19, 00:00 UTC · Apr 19, 2026Data breach in the wildCVE-2026-34621CVE-2026-39813CVE-2026-3980860
Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVDSecurity Affairs·Oct 27, 10:45 UTC · Oct 27, 2025Ransomware60
NetSpectre attack can exploit CPUs to leak information remotely, researchers sayCyberScoop·Jul 27, 20:37 UTC · Jul 27, 2018Exploit / PoC in the wild60
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade DetectionThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Malware55
Malicious AI Agent Server Reportedly Steals EmailsInfosecurity Magazine·Sep 25, 16:30 UTC · Sep 25, 2025Exploit / PoC60
Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Threat actor60
Critical vm2 sandbox escape flaw uncovered, patch ASAP! (CVE-2022-36067)Help Net Security·Apr 24, 13:36 UTC · Apr 24, 2023VulnerabilityCVE-2022-3606760
The leaked NSA hacking tools keep showing up in criminal schemesCyberScoop·Sep 25, 19:05 UTC · Sep 25, 2017Ransomware in the wildCVE-2017-014460
Here’s how carefully concealed backdoor in fake AWS files escaped mainstream noticeArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2024Malware55
Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT TechniquesRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Threat actor60
Valak a sophisticated malware that completely changed in 6 monthsSecurity Affairs·May 28, 10:21 UTC · May 28, 2020Malware55
Unofficial Patch Released for New Actively Exploited Windows MotW VulnerabilityThe Hacker News·Nov 1, 11:03 UTC · Nov 1, 2022Vulnerability in the wild60
Package hallucination: LLMs may deliver malicious code to careless devsHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2025Data breach160
Google white hackers disclosed critical vulnerabilities in uTorrent clientsSecurity Affairs·Feb 22, 07:45 UTC · Feb 22, 2018Vulnerability55
Flaws in Popular IDE Extensions Allow Data ExfiltrationInfosecurity Magazine·Feb 19, 10:45 UTC · Feb 19, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-6571560
How Just Visiting A Site Could Have Hacked Your iPhone or MacBook CameraThe Hacker News·Jan 31, 05:24 UTC · Jan 31, 2022Exploit / PoCCVE-2020-3852CVE-2020-3864CVE-2020-3865+4 CVEs60
Critical Bug Reported in NPM Package With Millions of Downloads WeeklyThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2021VulnerabilityCVE-2021-2340660
Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware DeliveryThe Hacker News·Feb 12, 06:21 UTC · Feb 12, 2026Malware in the wildCVE-2025-0108CVE-2024-41713CVE-2024-10914+2 CVEs60
Why the Axios attack proves AI is mandatory for supply chain securityCyberScoop·Apr 20, 13:17 UTC · Apr 20, 2026Exploit / PoC in the wild60
CSE Malware ZLab - Preliminary analysis of Bad Rabbit attackSecurity Affairs·Oct 26, 11:26 UTC · Oct 26, 2017Malware55
Multi-Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoaderThe Hacker News·Apr 18, 12:03 UTC · Apr 18, 2025MalwareCVE-2021-4044960
Crooks use HTML smuggling to spread QBot malware via SVG filesSecurity Affairs·Dec 15, 07:54 UTC · Dec 15, 2022Malware55
OpenAI's Mac apps need updates thanks to the Axios hackCyberScoop·Apr 13, 21:11 UTC · Apr 13, 2026Ransomware in the wild60
Spam report: June 2010Kaspersky Securelist·Jul 21, 17:08 UTC · Jul 21, 2010Vulnerability in the wild60
5 Must-Have Tools for Effective Dynamic Malware AnalysisThe Hacker News·Oct 2, 12:21 UTC · Oct 2, 2024Malware55
CountLoader Broadens Russian Ransomware Operations With MultiThe Hacker News·Sep 19, 03:44 UTC · Sep 19, 2025Ransomware60
Chrome 0-day exploit CVE-2019Kaspersky Securelist·Nov 1, 16:00 UTC · Nov 1, 2019Exploit / PoCCVE-2019-1372060
North Korea-linked APT37 exploited IE zeroSecurity Affairs·Oct 19, 14:07 UTC · Oct 19, 2024Threat actor in the wildCVE-2024-38178CVE-2022-4112860