CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco ZeroThe Hacker News·Mar 20, 04:36 UTC · Mar 20, 2026Advisory in the wildCVE-2025-66376CVE-2026-20963CVE-2026-20131+5 CVEs60
International alert spotlights RussiaThe Record·Jul 23, 17:07 UTC · Jul 23, 2026RansomwareCVE-2025-6637660
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
October 2025 CVE LandscapeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Ransomware in the wildCVE-2025-59287CVE-2025-61882CVE-2025-41244+29 CVEs60
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breachedHelp Net Security·Jul 26, 00:00 UTC · Jul 26, 2026Data breach in the wildCVE-2026-6875CVE-2026-15409CVE-2026-15410+4 CVEs60
Russian Hackers Exploit New ‘ZeroInfosecurity Magazine·Jul 23, 15:50 UTC · Jul 23, 2026Exploit / PoCCVE-2025-6637660
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User SessionsThe Hacker News·Jul 11, 06:45 UTC · Jul 11, 2026Exploit / PoC in the wildCVE-2025-27915CVE-2023-37580CVE-2024-2744360
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksThe Hacker News·Jun 27, 12:06 UTC · Jun 27, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs60
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike BeaconKaspersky Securelist·Jun 24, 14:23 UTC · Jun 24, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs47
April 2026 CVE LandscapeRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2026-33032CVE-2026-39987CVE-2009-0238+30 CVEs160
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC ZeroRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2017-7921CVE-2026-27483CVE-2026-27944+10 CVEs260
CISA Adds 8 Exploited Flaws to KEV, Sets AprilThe Hacker News·Apr 21, 13:51 UTC · Apr 21, 2026Exploit / PoC in the wildCVE-2023-27351CVE-2024-27199CVE-2025-2749+7 CVEs60
CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133)Help Net Security·Apr 21, 00:00 UTC · Apr 21, 2026Vulnerability in the wildCVE-2026-20133CVE-2026-20128CVE-2026-20122+5 CVEs160
U.S. CISA adds Microsoft SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 18, 21:11 UTC · Mar 18, 2026Exploit / PoC in the wildCVE-2026-20963CVE-2025-6637660
CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV UpdateThe Hacker News·Feb 24, 15:30 UTC · Feb 24, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2024-7694CVE-2020-7796+1 CVEs60
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
CISA Updates KEV Catalog with Four Actively Exploited Software VulnerabilitiesThe Hacker News·Jan 23, 15:24 UTC · Jan 23, 2026Exploit / PoC in the wildCVE-2025-68645CVE-2025-34026CVE-2025-31125+1 CVEs60
RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global ScaleRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2022-24682CVE-2022-27924CVE-2022-27925+2 CVEs60
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe Hacker News·Jul 8, 05:08 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+3 CVEs60
U.S. CISA adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 21, 10:14 UTC · May 21, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2024-11182+3 CVEs60
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active ExploitationThe Hacker News·Feb 26, 04:33 UTC · Feb 26, 2025Exploit / PoC in the wildCVE-2024-49035CVE-2023-3419260
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
Earth Lusca expands its arsenal with SprySOCKS Linux malwareSecurity Affairs·Sep 19, 07:52 UTC · Sep 19, 2023MalwareCVE-2022-40684CVE-2022-39952CVE-2021-22205+6 CVEs160
CISA, FBI, NSA reveal five enterprise bugs exploited by Russia's APT29 groupThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Threat actorCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs60
Microsoft: Two New 0-Day Flaws in Exchange ServerKrebs on Security·Sep 30, 17:03 UTC · Sep 30, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-41082160
US Sanctions Russia and Expels 10 Diplomats Over SolarWinds CyberattackThe Hacker News·Jun 4, 10:27 UTC · Jun 4, 2021Policy & legal in the wildCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs60
Top 12 Security Flaws Russian Spy Hackers Are Exploiting in the WildThe Hacker News·May 11, 06:23 UTC · May 11, 2021Exploit / PoCCVE-2018-13379CVE-2019-9670CVE-2019-11510+9 CVEs60
US Issues Russian SVR WarningInfosecurity Magazine·Apr 16, 17:57 UTC · Apr 16, 2021VulnerabilityCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs47
NSA, FBI, DHS expose Russian intelligence hacking tradecraftCyberScoop·Apr 15, 13:56 UTC · Apr 15, 2021Exploit / PoC in the wild60
Biomedical orgs working on COVID-19 vaccines open to cyber attacksHelp Net Security·Jul 17, 00:00 UTC · Jul 17, 2020Data breachCVE-2019-19781CVE-2019-11510CVE-2018-13379+1 CVEs60
Synacor Zimbra Cloud: Supporting multiple collaboration tools from an email-centric workspaceHelp Net Security·Sep 3, 00:00 UTC · Sep 3, 2020AI tools & infra30
Bitter APT adds Bangladesh to their targetsCisco Talos·May 11, 12:00 UTC · May 11, 2022Exploit / PoCCVE-2017-11882CVE-2018-0798CVE-2018-0802+1 CVEs60
⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & MoreThe Hacker News·Oct 6, 11:38 UTC · Oct 6, 2025RansomwareCVE-2025-61882CVE-2025-27915CVE-2025-4008+16 CVEs60
New Bug Could Let Attackers Hijack Zimbra Server by Sending Malicious EmailThe Hacker News·Jul 27, 15:46 UTC · Jul 27, 2021VulnerabilityCVE-2021-35208CVE-2021-3520935
CISA adds Zimbra bug to Known Exploited Vulnerabilities CatalogSecurity Affairs·Aug 5, 13:03 UTC · Aug 5, 2022Exploit / PoC in the wildCVE-2022-2792460
A flaw in Zimbra email suite allows stealing login credentials of the usersSecurity Affairs·Jun 14, 23:12 UTC · Jun 14, 2022Exploit / PoCCVE-2022-2792460
CISA Adds Zimbra Email Vulnerability to its Exploited Vulnerabilities CatalogThe Hacker News·Aug 5, 05:54 UTC · Aug 5, 2022Vulnerability in the wildCVE-2022-2792460
July 2026 CVE LandscapeRecorded Future·Aug 7, 00:00 UTC · Aug 7, 2026Ransomware in the wildCVE-2025-3248CVE-2008-4128CVE-2017-17215+78 CVEs160
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February]The Hacker News·May 6, 07:05 UTC · May 6, 2025Ransomware in the wildCVE-2024-57726CVE-2024-57727CVE-2024-57728+18 CVEs60