JSP webshells being dropped on unpatched PTC Windchill instancesHelp Net Security·Jul 27, 12:30 UTC · Jul 27, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-468160
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe Hacker News·Jul 25, 09:59 UTC · Jul 25, 2026Exploit / PoC in the wildCVE-2026-1256960
JadePuffer Returns With Ransomware Designed to Wipe AI ModelsInfosecurity Magazine·Jul 20, 14:05 UTC · Jul 20, 2026Ransomware in the wildCVE-2025-3248160
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware in the wildCVE-2026-46817CVE-2023-434660
New macOS malware steals passwords by posing as Apple's crash-reporting toolHelp Net Security·Jul 14, 00:00 UTC · Jul 14, 2026Malware in the wild57
Australia Alerts Organizations to Ongoing CMS Exploitation AttacksSecurity Affairs·Jul 13, 07:39 UTC · Jul 13, 2026Exploit / PoC in the wildCVE-2025-34085CVE-2020-36847CVE-2025-12057+15 CVEs60
Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)Help Net Security·Jul 7, 00:00 UTC · Jul 7, 2026Vulnerability in the wildCVE-2026-4828260
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)Help Net Security·Jun 19, 00:00 UTC · Jun 19, 2026Vulnerability in the wildCVE-2026-2025360
CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Under Active Targeted ExploitationSecurity Affairs·Jun 16, 10:53 UTC · Jun 16, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-20245CVE-2026-20122+5 CVEs60
OptinMonster supply chain attack hits 1.2 million sitesSansec (Magento / e-commerce security)·Jun 15, 18:34 UTC · Jun 15, 2026Vulnerability in the wild57
Cisco Releases Security Updates for Actively Exploited SDThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-20245CVE-2026-20182+5 CVEs60
Langflow Vulnerability CVE-2026The Hacker News·Jun 12, 04:10 UTC · Jun 12, 2026Vulnerability in the wildCVE-2026-5027CVE-2026-0770CVE-2026-33017+2 CVEs60
Cleo patches zero-day exploited by ransomware gangHelp Net Security·Jun 8, 10:32 UTC · Jun 8, 2026Ransomware in the wildCVE-2024-50623CVE-2024-55956160
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code executionCyberScoop·Apr 21, 15:43 UTC · Apr 21, 2026Vulnerability in the wild60
CISA Adds 8 Exploited Flaws to KEV, Sets AprilThe Hacker News·Apr 21, 13:51 UTC · Apr 21, 2026Exploit / PoC in the wildCVE-2023-27351CVE-2024-27199CVE-2025-2749+7 CVEs60
DarkSword: Researchers uncover another iOS exploit kitHelp Net Security·Mar 19, 00:00 UTC · Mar 19, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-43510CVE-2025-43520+3 CVEs160
U.S. CISA adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 16, 21:08 UTC · Mar 16, 2026Exploit / PoC in the wildCVE-2025-4781360
Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilitiesHelp Net Security·Mar 5, 00:00 UTC · Mar 5, 2026Vulnerability in the wildCVE-2026-20128CVE-2026-20122CVE-2026-20127+2 CVEs60
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 ScoreThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2026-24423CVE-2026-23760CVE-2026-2506760
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
JPCERT/CC Reports Widespread Exploitation of Array Networks AG Gateway VulnerabilitySecurity Affairs·Dec 5, 13:19 UTC · Dec 5, 2025Vulnerability in the wildCVE-2023-2846160
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
SonicWall adds rootkit removal capabilities to the SMA 100 seriesHelp Net Security·Oct 9, 13:10 UTC · Oct 9, 2025Malware in the wildCVE-2024-38475CVE-2025-4059960
Microsoft Patch Tuesday, September 2025 EditionKrebs on Security·Sep 9, 22:58 UTC · Sep 9, 2025Vulnerability in the wildCVE-2025-54918CVE-2025-55234CVE-2025-54916+4 CVEs60
Someone Created the First AI-Powered Ransomware Using OpenAI's gptThe Hacker News·Sep 5, 12:39 UTC · Sep 5, 2025Ransomware in the wild60
Git vulnerability leading to RCE is being exploited by attackers (CVE-2025-48384)Help Net Security·Aug 26, 00:00 UTC · Aug 26, 2025Vulnerability in the wildCVE-2025-4838460
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 20, 13:38 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-2525760
Fortinet FortiWeb flaw CVE-2025Security Affairs·Jul 19, 16:25 UTC · Jul 19, 2025Exploit / PoC in the wildCVE-2025-2525760
Patch immediately: CVE-2025-25257 PoC enables remote code execution on Fortinet FortiWebSecurity Affairs·Jul 13, 18:10 UTC · Jul 13, 2025Exploit / PoC in the wildCVE-2025-2525760
U.S. CISA adds MRLG, PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 8, 14:13 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+1 CVEs60
Attackers are chaining flaws to breach Palo Alto Networks firewallsHelp Net Security·Apr 18, 10:11 UTC · Apr 18, 2025Exploit / PoC in the wildCVE-2025-0108CVE-2024-9474CVE-2025-0111+1 CVEs60
CISA Adds Palo Alto Networks and SonicWall Flaws to Exploited Vulnerabilities ListThe Hacker News·Feb 21, 04:45 UTC · Feb 21, 2025Vulnerability in the wildCVE-2025-0108CVE-2024-53704CVE-2024-9474+1 CVEs60
Cleo File Transfer Vulnerability Under ExploitationThe Hacker News·Dec 18, 04:09 UTC · Dec 18, 2024Vulnerability in the wildCVE-2024-50623CVE-2024-5595660
CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active AttacksThe Hacker News·Nov 27, 04:06 UTC · Nov 27, 2024Vulnerability in the wildCVE-2023-28461CVE-2023-45727CVE-2023-2799760
Security Affairs newsletter Round 488 by Pierluigi PaganiniSecurity Affairs·Sep 8, 11:58 UTC · Sep 8, 2024Ransomware in the wildCVE-2024-32896CVE-2024-30078CVE-2024-3640160
Critical Docker Engine Flaw Allows Attackers to Bypass Authorization PluginsThe Hacker News·Jul 25, 05:47 UTC · Jul 25, 2024Exploit / PoC in the wildCVE-2024-41110160
CISA adds Apache Flink flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 24, 10:25 UTC · May 24, 2024Exploit / PoC in the wildCVE-2020-1751960
CISA Warns of Actively Exploited Apache Flink Security VulnerabilityThe Hacker News·May 24, 05:00 UTC · May 24, 2024Vulnerability in the wildCVE-2020-17519CVE-2020-28188CVE-2020-2922760
Ivanti Patches Critical Remote Code Execution Flaws in Endpoint ManagerThe Hacker News·May 23, 09:21 UTC · May 23, 2024Vulnerability in the wildCVE-2024-29822CVE-2024-29827CVE-2024-29828+12 CVEs60