TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain CampaignThe Hacker News·Aug 7, 06:50 UTC · Aug 7, 2026Threat actor60
Chinese Threat Actors Weaponize New Vulnerabilities in Under a DayInfosecurity Magazine·Aug 3, 15:00 UTC · Aug 3, 2026Vulnerability in the wild60
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, WaterThe Hacker News·Aug 3, 14:03 UTC · Aug 3, 2026Data breachCVE-2026-42897CVE-2026-6606660
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag ImagesThe Hacker News·Jul 19, 18:14 UTC · Jul 19, 2026Malware42
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News·May 19, 04:33 UTC · May 19, 2026Ransomware in the wildCVE-2026-42897CVE-2026-20182CVE-2026-2012760
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News·May 11, 12:36 UTC · May 11, 2026Malware in the wildCVE-2026-6973CVE-2026-030060
Vercel attack fallout expands to more customers and thirdCyberScoop·Apr 23, 22:05 UTC · Apr 23, 2026Data breach in the wild160
Vercel Finds More Compromised Accounts in Context.aiThe Hacker News·Apr 23, 08:47 UTC · Apr 23, 2026Data breach45
Vercel Breach Tied to Context AI Hack Exposes Limited Customer CredentialsThe Hacker News·Apr 22, 15:14 UTC · Apr 22, 2026Data breach157
Vercel's security breach started with malware disguised as Roblox cheatsCyberScoop·Apr 20, 20:24 UTC · Apr 20, 2026Malware in the wild60
Third-party AI hack triggers Vercel breach, internal environments accessedSecurity Affairs·Apr 20, 10:11 UTC · Apr 20, 2026AI tools & infra30
Vercel breached via compromised third-party AI toolHelp Net Security·Apr 20, 00:00 UTC · Apr 20, 2026Data breach60
RondoDox botnet expands arsenal targeting 174 flaws, and hits 15,000 daily exploit attemptsSecurity Affairs·Mar 17, 15:02 UTC · Mar 17, 2026Malware in the wildCVE-2023-1389CVE-2024-3721CVE-2024-12856+2 CVEs60
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade TakedownThe Hacker News·Feb 28, 09:34 UTC · Feb 28, 2026Malware30
More than half of public vulnerabilities bypass leading WAFsHelp Net Security·Feb 18, 05:11 UTC · Feb 18, 2026VulnerabilityCVE-2025-5518260
A security flaw at DavaIndia Pharmacy allowed attackers to access customers' data and moreSecurity Affairs·Feb 16, 19:22 UTC · Feb 16, 2026Vulnerability30
Pompelmi: Open-source secure file upload scanning for Node.jsHelp Net Security·Feb 2, 00:00 UTC · Feb 2, 2026Malware30
IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizationsCisco Talos·Jan 29, 11:00 UTC · Jan 29, 2026Threat actorCVE-2025-61882CVE-2025-5518260
ACME Flaw in Cloudflare allowed attackers to reach origin serversSecurity Affairs·Jan 21, 15:10 UTC · Jan 21, 2026Vulnerability30
Security Affairs newsletter Round 559 by Pierluigi PaganiniSecurity Affairs·Jan 18, 13:46 UTC · Jan 18, 2026Exploit / PoC in the wild60
⚡ Weekly Recap: IoT Exploits, Wallet Breaches, Rogue Extensions, AI Abuse & MoreThe Hacker News·Jan 5, 12:56 UTC · Jan 5, 2026VulnerabilityCVE-2025-55182CVE-2025-13915CVE-2025-52691+7 CVEs60
React2Shell Vulnerability Actively Exploited to Deploy Linux BackdoorsThe Hacker News·Dec 17, 07:26 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-29927CVE-2025-6647860
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Federal agencies now only have one more day to patch React2Shell bugThe Record·Dec 11, 19:54 UTC · Dec 11, 2025Vulnerability in the wildCVE-2025-5518260
New EtherRAT backdoor surfaces in React2Shell attacks tied to North KoreaSecurity Affairs·Dec 10, 14:45 UTC · Dec 10, 2025MalwareCVE-2025-5518260
AWS: China-linked threat actors weaponized React2Shell hours after disclosureSecurity Affairs·Dec 8, 13:37 UTC · Dec 8, 2025Threat actor in the wildCVE-2025-55182CVE-2025-133860
React2Shell Under Active Exploitation by ChinaInfosecurity Magazine·Dec 8, 11:40 UTC · Dec 8, 2025Exploit / PoC in the wildCVE-2025-5518260
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & MoreThe Hacker News·Dec 6, 11:14 UTC · Dec 6, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-38352CVE-2025-48543+25 CVEs160
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & MoreThe Hacker News·Dec 2, 05:36 UTC · Dec 2, 2025VulnerabilityCVE-2025-59287CVE-2025-12972CVE-2025-12970+17 CVEs147
Over 67,000 Fake npm Packages Flood Registry in WormThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Malware42
NCSC Launches Vulnerability Research Institute to Boost UK ResilienceInfosecurity Magazine·Jul 15, 10:00 UTC · Jul 15, 2025Vulnerability30
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreThe Hacker News·May 7, 10:33 UTC · May 7, 2025MalwareCVE-2025-29927CVE-2025-23120CVE-2024-56346+13 CVEs60
Horns&Hooves Campaign Delivers RATs via Fake Emails and JavaScript PayloadsThe Hacker News·Dec 3, 05:23 UTC · Dec 3, 2024Threat actor57
Kasada introduces CDN edge API integrations to block abuse and online fraudHelp Net Security·Mar 19, 00:00 UTC · Mar 19, 2024Phishing & fraud42