Progress quietly fixes MOVEit auth bypass flaws (CVE-2024-5805, CVE-2024-5806)Help Net Security·Jun 8, 10:33 UTC · Jun 8, 2026Vulnerability in the wildCVE-2024-5805CVE-2024-580660
Cisco zero-day under ongoing attack by persistent threat groupCyberScoop·May 15, 14:16 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-20182CVE-2026-20122CVE-2026-20128+2 CVEs60
Former DigitalMint ransomware negotiator pleads guilty to extortion schemeCyberScoop·Apr 21, 21:04 UTC · Apr 21, 2026Ransomware in the wild60
Unpublished security flaws (0days) massively exploitedSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in Recent Mass AttacksThe Hacker News·Apr 2, 07:21 UTC · Apr 2, 2026Exploit / PoC in the wildCVE-2023-32434CVE-2023-3860660
Cisco’s latest vulnerability spree has a more troubling pattern underneathCyberScoop·Mar 18, 21:31 UTC · Mar 18, 2026Vulnerability in the wildCVE-2026-20127CVE-2022-20775CVE-2026-20122+6 CVEs60
U.S. robotics companies want federal help to keep Chinese robots out of America’s networksCyberScoop·Mar 18, 19:42 UTC · Mar 18, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and MoreThe Hacker News·Mar 2, 13:26 UTC · Mar 2, 2026Data breach in the wildCVE-2026-20127CVE-2025-40538CVE-2025-40539+27 CVEs60
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023Help Net Security·Mar 1, 00:00 UTC · Mar 1, 2026Malware in the wildCVE-2026-25108CVE-2026-20127160
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Other DevicesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-20700CVE-2025-14174CVE-2025-4352960
Apple fixed first actively exploited zeroSecurity Affairs·Feb 12, 10:50 UTC · Feb 12, 2026Exploit / PoC in the wildCVE-2026-20700CVE-2025-14174CVE-2025-4352960
DOJ seizes piracy sites, Italian police dismantle illegal IPTV operationCyberScoop·Jan 30, 18:29 UTC · Jan 30, 2026Exploit / PoC in the wild60
ThreatsDay Bulletin: DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs RisingThe Hacker News·Nov 5, 10:38 UTC · Nov 5, 2025Malware in the wildCVE-2017-1188260
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Fortra cops to exploitation of GoAnywhere fileCyberScoop·Oct 13, 21:22 UTC · Oct 13, 2025Ransomware in the wildCVE-2025-1003560
FreePBX Servers Targeted by ZeroThe Hacker News·Sep 12, 12:01 UTC · Sep 12, 2025Ransomware in the wildCVE-2025-5781960
Vulnerability Spotlight: Dirty PipeRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Vulnerability in the wildCVE-2022-0847CVE-2016-519560
UAT-6382 exploits Cityworks zeroCisco Talos·May 22, 10:00 UTC · May 22, 2025Vulnerability in the wildCVE-2025-0994CVE-2025-094460
Cybercriminal marketplace Rydox seized in international law enforcement operationCyberScoop·Dec 12, 21:20 UTC · Dec 12, 2024Exploit / PoC in the wild60
Fortinet Warns of Critical Vulnerability in FortiManager Under Active ExploitationThe Hacker News·Nov 15, 04:35 UTC · Nov 15, 2024Vulnerability in the wildCVE-2024-4757560
Fuzzing µCOS protocol stacks, Part 2: Handling multiple requests per test caseCisco Talos·Aug 28, 16:00 UTC · Aug 28, 2024Vulnerability in the wild57
New MOVEit Transfer critical bug is actively exploitedSecurity Affairs·Jun 26, 19:54 UTC · Jun 26, 2024Vulnerability in the wildCVE-2024-5805CVE-2024-580660
Pro-Russia hacktivists attacking vital tech in water and other sectors, agencies sayCyberScoop·May 1, 18:35 UTC · May 1, 2024Exploit / PoC in the wild60
Friday Squid Blogging: Giant Squid from Newfoundland in the 1800sSchneier on Security·Jan 12, 22:06 UTC · Jan 12, 2024Malware in the wild60
Critical libwebp Vulnerability Under Active ExploitationThe Hacker News·Oct 3, 16:10 UTC · Oct 3, 2023Vulnerability in the wildCVE-2023-5129CVE-2023-41064CVE-2023-4863+5 CVEs60
Watch out! CVE-2023-5129 in libwebp library affects millions appsSecurity Affairs·Sep 27, 13:35 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-5129CVE-2023-4863CVE-2023-41064+1 CVEs160
EU adopts more robust data privacy agreement with USCyberScoop·Jul 10, 16:04 UTC · Jul 10, 2023Exploit / PoC in the wild60
Week in review: MOVEit Transfer critical zero-day vulnerability, Kali Linux 2023.2 releasedHelp Net Security·Jun 4, 00:00 UTC · Jun 4, 2023Exploit / PoC in the wildCVE-2023-28771CVE-2023-2868CVE-2023-2798860
Week in review: 3CX supply chain attack, ChatGPT data leakHelp Net Security·Apr 2, 00:00 UTC · Apr 2, 2023Ransomware in the wildCVE-2022-47986CVE-2023-2352960
SOHO routers impacted by bug in USB-overThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC in the wildCVE-2021-4538860
European regulators fine Meta over $400 million for targeted ad programCyberScoop·Jan 4, 21:35 UTC · Jan 4, 2023Policy & legal in the wild60
White House announces new surveillance guardrails to meet EU Privacy Shield expectationsCyberScoop·Oct 7, 18:00 UTC · Oct 7, 2022AI safety & security in the wild45
Metasploit 6.2.0 comes with 138 new modules, 148 enhancements and featuresHelp Net Security·Jun 13, 00:00 UTC · Jun 13, 2022Exploit / PoC in the wildCVE-2021-44228CVE-2022-1388CVE-2022-22954+3 CVEs60
Week in review: Spring4Shell vulnerability, attackers exploiting patched RCE in Sophos FirewallHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2022Vulnerability in the wildCVE-2022-104060
Attack on Viasat modems possibly came from wiper malware deployed through supply chainCyberScoop·Mar 31, 19:26 UTC · Mar 31, 2022Malware in the wild60
Notes on CVE-2022Kaspersky Securelist·Mar 14, 14:11 UTC · Mar 14, 2022Exploit / PoC in the wildCVE-2022-084760
KCodes NetUSB flaw impacts millions of SOHO routersSecurity Affairs·Jan 13, 00:07 UTC · Jan 13, 2022Vulnerability in the wildCVE-2021-45608CVE-2021-45388CVE-2015-303660
Announcing the 2021 CyberScoop 50 awards winnersCyberScoop·Oct 18, 20:51 UTC · Oct 18, 2021Ransomware in the wild60
US arrests suspected hackers accused of video game piracyCyberScoop·Oct 5, 14:07 UTC · Oct 5, 2020Exploit / PoC in the wild60
Malicious Autodesk plugin at root of cyberCyberScoop·Aug 26, 13:40 UTC · Aug 26, 2020Exploit / PoC in the wild60