Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)Help Net Security·Apr 2, 08:44 UTC · Apr 2, 2025Vulnerability in the wildCVE-2025-2992760
Network Attack Trends: FebruaryPalo Alto Unit 42·Jun 6, 12:33 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-25296CVE-2021-25297CVE-2021-25298+4 CVEs60
Network Security Trends: MayPalo Alto Unit 42·Jun 6, 01:20 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2020-11978CVE-2020-13927CVE-2021-2785060
Network Security Trends: AugustPalo Alto Unit 42·Jun 6, 00:57 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-40438CVE-2021-34473CVE-2021-38647+9 CVEs60
Network Security Trends: November 2021 to January 2022Palo Alto Unit 42·Jun 5, 20:41 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2021-44228CVE-2021-45046CVE-2021-38647+13 CVEs60
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, CrossPalo Alto Unit 42·Jun 5, 20:05 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-22954CVE-2022-22963CVE-2022-22965+20 CVEs60
Network Security Trends: MayPalo Alto Unit 42·Jun 5, 17:26 UTC · Jun 5, 2024Exploit / PoC in the wild60
NVD Leaves Exploited Vulnerabilities UncheckedInfosecurity Magazine·May 23, 14:00 UTC · May 23, 2024Vulnerability in the wild60
Global critical infrastructure faces relentless cyber activityHelp Net Security·Jan 29, 00:00 UTC · Jan 29, 2024Exploit / PoC in the wild60
Prevent and detect Adobe ColdFusion exploitation (CVE-2023-26360, CVE-2023-26359)Help Net Security·Dec 6, 09:33 UTC · Dec 6, 2023Vulnerability in the wildCVE-2023-26360CVE-2023-26359CVE-2023-2636160
Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing MalwareInfosecurity Magazine·Nov 22, 17:00 UTC · Nov 22, 2023Malware in the wildCVE-2023-46604CVE-2023-491160
BlueKeep RDP flaw: Nearly a million Internet-facing systems are vulnerableHelp Net Security·Nov 15, 08:03 UTC · Nov 15, 2023Ransomware in the wildCVE-2019-070860
Microsoft says Chinese hacking crew is targeting TaiwanCyberScoop·Aug 24, 21:34 UTC · Aug 24, 2023Exploit / PoC in the wild60
Online influence operators continue fine-tuning use of AI to deceive their targets, researchers sayCyberScoop·Aug 17, 12:00 UTC · Aug 17, 2023Exploit / PoC in the wild60
Staying ahead of the "professionals": The service-oriented ransomware crime industryHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2023Ransomware in the wild60
Experts devised a new exploit for the PaperCut flaw that can bypass all current detectionSecurity Affairs·May 5, 11:01 UTC · May 5, 2023Exploit / PoC in the wildCVE-2023-2735060
Advanced threat predictions for 2023Kaspersky Securelist·Nov 14, 08:00 UTC · Nov 14, 2022Ransomware in the wild60
Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)Help Net Security·Sep 23, 00:00 UTC · Sep 23, 2022Vulnerability in the wildCVE-2022-3540560
Chinese hackers zero in on Australian manufacturers, wind turbine operatorsCyberScoop·Aug 30, 11:32 UTC · Aug 30, 2022Exploit / PoC in the wild60
Researchers uncover potential ransomware network with U.S. connectionsCyberScoop·Jul 21, 22:15 UTC · Jul 21, 2022Ransomware in the wild60
CISA adds Zyxel Firewalls flaw to Known Exploited Vulnerabilities CatalogSecurity Affairs·May 17, 07:11 UTC · May 17, 2022Exploit / PoC in the wildCVE-2022-30525CVE-2022-2294760
Week in review: F5 BIG-IP RCE exploitation, URL spoofing flaws in Zoom, Google DocsHelp Net Security·May 15, 00:00 UTC · May 15, 2022Vulnerability in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs60
Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-dayHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2022Exploit / PoC in the wildCVE-2022-24521CVE-2022-26904CVE-2022-26809+1 CVEs60
April Records First Patch Tuesday of 2022 to Top 100 CVEsInfosecurity Magazine·Apr 13, 09:00 UTC · Apr 13, 2022Vulnerability in the wildCVE-2022-24521CVE-2022-26904CVE-2022-24491+1 CVEs160
Tens of thousands unpatched GitLab servers under attack via CVE-2021-22205Help Net Security·Nov 4, 00:00 UTC · Nov 4, 2021Vulnerability in the wildCVE-2021-2220560
Threat Source Newsletter (April 22, 2021)Cisco Talos·Apr 22, 18:00 UTC · Apr 22, 2021Ransomware in the wild60
Cybersecurity Firm FireEye Got Hacked; RedThe Hacker News·Dec 10, 16:36 UTC · Dec 10, 2020Ransomware in the wild60
Foreign spies use front companies to disguise their hacking, borrowing an old camouflage tacticCyberScoop·Oct 5, 17:48 UTC · Oct 5, 2020Data breach in the wild60
Attackers are bypassing F5 BIG-IP RCE mitigation - you might want to patch after allHelp Net Security·Jul 8, 00:00 UTC · Jul 8, 2020Vulnerability in the wildCVE-2020-590260
New release of Lampion trojan spreads in Portugal with some improvements on the VBS downloaderSecurity Affairs·Jul 7, 20:09 UTC · Jul 7, 2020Malware in the wild157
Cyber Command backs 'urgent' patch for F5 security vulnerabilityCyberScoop·Jul 6, 17:12 UTC · Jul 6, 2020Vulnerability in the wildCVE-2020-590260
How COVID-19 changed Cyber Command's 'Cyber Flag' exerciseCyberScoop·Jun 25, 21:51 UTC · Jun 25, 2020Exploit / PoC in the wild60
Magnitude exploit kitKaspersky Securelist·Jun 24, 10:00 UTC · Jun 24, 2020Ransomware in the wildCVE-2018-8174CVE-2018-8653CVE-2019-1367+3 CVEs60
Cisco warns about public exploit code for critical flaws in its 220 Series smart switchesHelp Net Security·Sep 3, 07:36 UTC · Sep 3, 2019Exploit / PoC in the wildCVE-2019-1938CVE-2019-1935CVE-2019-1974+4 CVEs60
Financial hacking teams FIN7, Cobalt Group update tactics to haunt banks and retailCyberScoop·Aug 14, 15:18 UTC · Aug 14, 2019Exploit / PoC in the wild60
Asia's hackers are finding a home on the dark webCyberScoop·Aug 8, 16:45 UTC · Aug 8, 2018Exploit / PoC in the wild60
Crooks included the code for CVE-2018-8174 IE ZeroSecurity Affairs·Jun 3, 07:32 UTC · Jun 3, 2018Vulnerability in the wildCVE-2018-8174CVE-2016-018960
Meet Money Taker, the latest hacking group tied to Russian cybercrimeCyberScoop·Dec 12, 03:44 UTC · Dec 12, 2017Exploit / PoC in the wild60