Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploitedHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2026Exploit / PoC in the wildCVE-2026-35616CVE-2026-21643CVE-2026-20093+2 CVEs160
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and MoreThe Hacker News·Mar 2, 13:26 UTC · Mar 2, 2026Data breach in the wildCVE-2026-20127CVE-2025-40538CVE-2025-40539+27 CVEs60
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023Help Net Security·Mar 1, 00:00 UTC · Mar 1, 2026Malware in the wildCVE-2026-25108CVE-2026-20127160
Fed agencies ordered to patch Dell bug by Saturday after exploitation warningThe Record·Feb 18, 21:09 UTC · Feb 18, 2026Vulnerability in the wildCVE-2026-2276960
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
Three ZeroInfosecurity Magazine·Jan 14, 10:45 UTC · Jan 14, 2026Exploit / PoC in the wildCVE-2026-20805CVE-2026-21265CVE-2023-3109660
Microsoft Fixes Three ZeroInfosecurity Magazine·Dec 10, 09:45 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62221CVE-2025-54100CVE-2025-64671+4 CVEs60
React2Shell Exploit Campaigns Tied to North Korean Cyber TacticsInfosecurity Magazine·Dec 9, 17:15 UTC · Dec 9, 2025Threat actor in the wildCVE-2025-5518260
Chinese state hackers used Anthropic AI systems in dozens of attacksThe Record·Nov 14, 18:07 UTC · Nov 14, 2025Data breach in the wild60
CISA warns of ‘significant’ threat to federal networks after nation-state hackers stole F5 source code, undisclosed bug infoThe Record·Oct 15, 16:56 UTC · Oct 15, 2025Threat actor in the wildCVE-2023-4674760
Want fewer security fires to fight? Start with threat modelingHelp Net Security·Jun 12, 00:00 UTC · Jun 12, 2025Data breach in the wild60
Windows NTLM vulnerability exploited in multiple attack campaigns (CVE-2025-24054)Help Net Security·Apr 17, 00:00 UTC · Apr 17, 2025Vulnerability in the wildCVE-2025-24054CVE-2025-24071CVE-2024-43451160
Microsoft Fixes Four Actively Exploited ZeroInfosecurity Magazine·Sep 11, 09:30 UTC · Sep 11, 2024Ransomware in the wildCVE-2024-43491CVE-2024-38014CVE-2024-38217+1 CVEs160
‘RegreSSHion’ bug raises alarms but experts question chances of widespread exploitationThe Record·Jul 2, 21:17 UTC · Jul 2, 2024Exploit / PoC in the wildCVE-2024-6387CVE-2006-505160
March 2024 Patch Tuesday: Microsoft fixes critical bugs in Windows Hyper-VHelp Net Security·Mar 26, 12:34 UTC · Mar 26, 2024Vulnerability in the wildCVE-2024-21338CVE-2024-21407CVE-2024-21408+7 CVEs60
CISA warns federal agencies of exploited Google Chrome and openThe Record·Jan 3, 21:36 UTC · Jan 3, 2024Advisory in the wildCVE-2023-7101CVE-2023-702460
October Patch Tuesday Addresses Three ZeroInfosecurity Magazine·Oct 11, 10:30 UTC · Oct 11, 2023Vulnerability in the wildCVE-2023-41763CVE-2023-36563CVE-2023-44487+8 CVEs160
Patch Tuesday Fixes Two ZeroInfosecurity Magazine·Sep 13, 10:30 UTC · Sep 13, 2023Vulnerability in the wildCVE-2023-36761CVE-2023-36802CVE-2023-36793+3 CVEs60
MITRE Announces Most Dangerous Software WeaknessesInfosecurity Magazine·Jun 30, 10:30 UTC · Jun 30, 2023Exploit / PoC in the wild60
Microsoft Patches Three ZeroInfosecurity Magazine·May 10, 09:30 UTC · May 10, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2023-2932560
Debate rages over Microsoft vulnerability practices after Follina, Azure issuesThe Record·Jan 13, 00:00 UTC · Jan 13, 2023Vulnerability in the wildCVE-2022-3019060
Log4Shell, ProxyLogon and Atlassian bug top CISA\'s list of routinely exploited vulnerabilities in 2021The Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability in the wildCVE-2020-1472CVE-2018-13379CVE-2019-11510+3 CVEs60
CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ orgThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Ransomware in the wildCVE-2022-22954CVE-2022-22972CVE-2022-22973+1 CVEs60
CISA orders civilian agencies to patch Zimbra bug after mass exploitationThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-37042CVE-2022-27925CVE-2022-2792460
Microsoft updates guidance for ‘ProxyNotShell’ bugs after researchers get around mitigationsThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
CISA, Claroty highlight severe vulnerabilities in popular power distribution unit productThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Vulnerability in the wildCVE-2022-3183CVE-2022-318460
CISA adds Apple zero-day, Cisco and Gigabyte bugs to exploited vulnerabilities listThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Exploit / PoC in the wildCVE-2020-3433CVE-2020-315360
Week in review: 7 cybersecurity audiobooks to read, Patch Tuesday forecastHelp Net Security·Oct 9, 00:00 UTC · Oct 9, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2022-3525660
ID.me CEO backtracks on claims company doesn't use powerful facial recognition techCyberScoop·Jan 26, 17:37 UTC · Jan 26, 2022Exploit / PoC in the wild60
'Sandworm' book review: To understand cyberwar, you must understand UkraineCyberScoop·Nov 8, 16:37 UTC · Nov 8, 2019Threat actor in the wild60
Google Uncovers How Just Visiting Some Sites Were Secretly Hacking iPhones For YearsThe Hacker News·Sep 7, 07:40 UTC · Sep 7, 2019Exploit / PoC in the wildCVE-2019-7287CVE-2019-728660
Teenage hackers are offered a second chance under European experimentCyberScoop·Jul 24, 12:40 UTC · Jul 24, 2019Exploit / PoC in the wild60
Experts advocate for 'ATT&CK' as goCyberScoop·Oct 24, 14:01 UTC · Oct 24, 2018Exploit / PoC in the wild60
'TeleGrab' malware again shows how hackers can evade encryption to read private messagesCyberScoop·May 17, 14:53 UTC · May 17, 2018Malware in the wild60
Air gapping voting machines isn't enough, says one election security expertCyberScoop·Apr 10, 13:49 UTC · Apr 10, 2018Exploit / PoC in the wild60
Want to reduce cybercrime? Undermine black market, watch cryptocurrency exchanges, experts sayCyberScoop·Mar 16, 15:45 UTC · Mar 16, 2018Data breach in the wild60
Microsoft Issues Security Patch Update for 14 New Critical VulnerabilitiesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2018Vulnerability in the wildCVE-2018-0852CVE-2018-0850CVE-2018-0763+3 CVEs60
Feds upping their email security game in wake of DHS orderCyberScoop·Nov 8, 23:00 UTC · Nov 8, 2017Exploit / PoC in the wild60
Pawn Storm used a new Flash Zero-Day in attacks on the NATO & the While HouseSecurity Affairs·Oct 23, 21:41 UTC · Oct 23, 2017Exploit / PoC in the wild60
A reminder for why government officials really shouldn't use personal email accountsCyberScoop·Sep 27, 00:59 UTC · Sep 27, 2017Exploit / PoC in the wild60