H1 2024 Malware & Vulnerability Trends Report: Zero-Day Exploits, Infostealers, and Emerging Malware ThreatsRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Exploit / PoC60
Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWTThe Hacker News·Jun 3, 16:58 UTC · Jun 3, 2025Vulnerability in the wildCVE-2025-2018860
China-linked threat actors stole 10% of Belgian State Security Service (VSSE)'s staff emailsSecurity Affairs·Feb 28, 07:54 UTC · Feb 28, 2025Threat actorCVE-2023-286860
Evilginx: Open-source man-in-the-middle attack frameworkHelp Net Security·Dec 23, 00:00 UTC · Dec 23, 2024Exploit / PoC60
Mystery malware destroys 600,000 routers from a single ISP during 72Ars Technica · Security·May 30, 14:00 UTC · May 30, 2024Malware55
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 20:17 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2024-20353CVE-2024-20359CVE-2024-4040+1 CVEs60
State-Sponsored Hackers Exploit Two Cisco ZeroThe Hacker News·Apr 25, 16:11 UTC · Apr 25, 2024Threat actor in the wildCVE-2024-20353CVE-2024-20359CVE-2024-2035860
State-Sponsored Espionage Campaign Exploits Cisco VulnerabilitiesInfosecurity Magazine·Apr 25, 14:00 UTC · Apr 25, 2024VulnerabilityCVE-2024-20353CVE-2024-2035960
Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networksSecurity Affairs·Apr 24, 20:31 UTC · Apr 24, 2024Exploit / PoCCVE-2024-20353CVE-2024-20359CVE-2018-0101160
Barracuda fixed a new ESG zeroSecurity Affairs·Dec 27, 14:13 UTC · Dec 27, 2023Data breach in the wildCVE-2023-7102CVE-2023-7101CVE-2023-286860
New P2PInfect Botnet MIPS Variant Targeting Routers and IoT DevicesThe Hacker News·Dec 5, 05:36 UTC · Dec 5, 2023MalwareCVE-2022-054360
Backdoor Implanted on Hacked Cisco Devices Modified to Evade DetectionThe Hacker News·Oct 25, 03:47 UTC · Oct 25, 2023MalwareCVE-2023-20198CVE-2023-2027360
Warning: Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the WildThe Hacker News·Oct 19, 11:31 UTC · Oct 19, 2023Exploit / PoC in the wildCVE-2023-20198CVE-2021-143560
UNC4841 threat actors hacked US government email servers exploiting Barracuda ESG flawSecurity Affairs·Aug 29, 20:15 UTC · Aug 29, 2023Threat actorCVE-2023-286860
FBI: Patches for Barracuda ESG CVE-2023Security Affairs·Aug 25, 06:44 UTC · Aug 25, 2023Vulnerability in the wildCVE-2023-286860
CISA discovered a new backdoor, named Whirlpool, used in Barracuda ESG attacksSecurity Affairs·Aug 10, 17:28 UTC · Aug 10, 2023MalwareCVE-2023-286860
CISA warns about SUBMARINE Backdoor employed in Barracuda ESG attacksSecurity Affairs·Jul 29, 22:58 UTC · Jul 29, 2023MalwareCVE-2023-286860
Chinese UNC4841 Group Exploits Zero-Day Flaw in Barracuda Email Security GatewayThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2023Exploit / PoCCVE-2023-286860
Attackers hacked Barracuda ESG appliances via zero-day since October 2022Help Net Security·Jun 9, 15:34 UTC · Jun 9, 2023Exploit / PoCCVE-2023-286860
Barracuda ESG appliances impacted by CVE-2023Security Affairs·Jun 8, 07:21 UTC · Jun 8, 2023Data breach in the wildCVE-2023-286860
Threat actors are exploiting Barracuda ESG bug since October 22Security Affairs·May 31, 13:36 UTC · May 31, 2023Threat actor in the wildCVE-2023-286860
Alert: Hackers Exploit Barracuda Email Security Gateway 0The Hacker News·May 31, 07:56 UTC · May 31, 2023Data breach in the wildCVE-2023-286860
APT Groups Expand Reach to New Industries and GeographiesInfosecurity Magazine·Apr 27, 16:30 UTC · Apr 27, 2023Threat actor60
Hackers Exploiting Redis Vulnerability to Deploy New Redigo Malware on ServersThe Hacker News·Dec 2, 12:45 UTC · Dec 2, 2022Vulnerability in the wildCVE-2022-054360
Ten most mysterious APT campaigns that remain unattributedKaspersky Securelist·Oct 7, 10:00 UTC · Oct 7, 2022Threat actorCVE-2021-21224CVE-2021-31955CVE-2021-31956160
Experts explained how to hack building controller widely adopted in RussiaSecurity Affairs·Mar 24, 22:09 UTC · Mar 24, 2022Exploit / PoC60
WARNING — Critical Remote Hacking Flaws Affect DThe Hacker News·Dec 8, 13:59 UTC · Dec 8, 2020Vulnerability55
ProjectSauron APT, aka Strider, found targeting firms in Russia, ChinaSecurity Affairs·Mar 10, 07:13 UTC · Mar 10, 2018Exploit / PoC60
Don't fear the Reaper: Botnet 'easy to stop,' says security researcherCyberScoop·Oct 27, 22:12 UTC · Oct 27, 2017Malware in the wild60
Babar & Casper,Malware likely designed by French IntelligenceSecurity Affairs·Sep 7, 13:31 UTC · Sep 7, 2017Malware55
Millions of mobile phones and laptops potentially exposed to attack leveraging baseband zeroSecurity Affairs·Apr 9, 08:57 UTC · Apr 9, 2017Exploit / PoC60
Gauss: Abnormal DistributionKaspersky Securelist·Aug 9, 17:01 UTC · Aug 9, 2012VulnerabilityCVE-2010-256860