APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch TuesdayThe Hacker News·Mar 2, 10:36 UTC · Mar 2, 2026VulnerabilityCVE-2026-21513CVE-2026-21509160
APT28 Uses Microsoft Office CVE-2026-21509 in EspionageThe Hacker News·Feb 4, 16:49 UTC · Feb 4, 2026VulnerabilityCVE-2026-21509147
Microsoft reveals actively exploited Office zero-day, provides emergency fix (CVE-2026-21509)Help Net Security·Feb 3, 18:36 UTC · Feb 3, 2026Exploit / PoC in the wildCVE-2026-2150960
Microsoft Releases Patch for Exploited Office Zero DayInfosecurity Magazine·Jan 27, 10:45 UTC · Jan 27, 2026Vulnerability in the wildCVE-2026-21509160
Microsoft Office Zero-Day (CVE-2026-21509) - Emergency Patch Issued for Active ExploitationThe Hacker News·Jan 27, 10:37 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2026-2150960
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-65046CVE-2026-0628CVE-2026-20805+5 CVEs160
Integrating Threat Intelligence and Vulnerability Management: A Modern ApproachRecorded Future·Dec 17, 00:00 UTC · Dec 17, 2025Vulnerability in the wild60
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Patch Tuesday: Microsoft fixes actively exploited Windows kernel vulnerability (CVE-2025-62215)Help Net Security·Nov 12, 00:00 UTC · Nov 12, 2025Vulnerability in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62199+1 CVEs60
Zero Day Quest returns: Microsoft ups the stakes with $5M bug bountySecurity Affairs·Aug 5, 17:51 UTC · Aug 5, 2025Vulnerability55
Moldovan Police arrested a 45-year-old foreign man participating in ransomware attacks on Dutch companiesSecurity Affairs·May 13, 12:03 UTC · May 13, 2025Ransomware57
⚡ Weekly Recap: VPN Exploits, Oracle's Silent Breach, ClickFix Surge and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Data breachCVE-2025-22457CVE-2025-24061CVE-2025-2407+15 CVEs60
The controversial case of the threat actor EncryptHubSecurity Affairs·Apr 7, 13:14 UTC · Apr 7, 2025Threat actorCVE-2025-24061CVE-2025-24071CVE-2025-26633+1 CVEs60
Microsoft announces Zero Day Quest hacking event with big rewardsHelp Net Security·Nov 19, 00:00 UTC · Nov 19, 2024Vulnerability55
New Chrome zero-day actively exploited, patch quickly! (CVE-2024-7971)Help Net Security·Sep 19, 11:32 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-796560
North Korea-linked APT Citrine Sleet exploit Chrome zero-day to deliver FudModule rootkitSecurity Affairs·Aug 31, 18:22 UTC · Aug 31, 2024Exploit / PoCCVE-2024-7971CVE-2024-3810660
Google addressed the ninth actively exploited Chrome zeroSecurity Affairs·Aug 26, 22:50 UTC · Aug 26, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-0519CVE-2024-2887+6 CVEs60
Google Fixes High-Severity Chrome Flaw Actively Exploited in the WildThe Hacker News·Aug 23, 10:01 UTC · Aug 23, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-4947CVE-2024-5274+6 CVEs160
Microsoft urges customers to fix Windows RCE in the TCP/IP stackSecurity Affairs·Aug 16, 07:10 UTC · Aug 16, 2024Vulnerability in the wildCVE-2024-38063CVE-2024-38189CVE-2024-38178+4 CVEs60
Azure Service Tags Vulnerability: Microsoft Warns of Potential Abuse by HackersThe Hacker News·Jun 10, 11:55 UTC · Jun 10, 2024Vulnerability in the wild60
Threat Brief: OMI Vulnerabilities (CVE-2021-38645, CVE-2021-38647, CVE-2021-38648 and CVE-2021Palo Alto Unit 42·Jun 6, 01:21 UTC · Jun 6, 2024VulnerabilityCVE-2021-38645CVE-2021-38647CVE-2021-38648+1 CVEs160
Windows DOS-to-NT flaws exploited to achieve unprivileged rootkitSecurity Affairs·Apr 22, 10:45 UTC · Apr 22, 2024MalwareCVE-2023-36396CVE-2023-32054CVE-2023-4275747
Linux Devs Rush to Patch Critical Vulnerability in ShimInfosecurity Magazine·Feb 8, 16:30 UTC · Feb 8, 2024VulnerabilityCVE-2023-4054760
Critical Boot Loader Vulnerability in Shim Impacts Nearly All Linux DistrosThe Hacker News·Feb 8, 03:11 UTC · Feb 8, 2024VulnerabilityCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
Critical shim bug impacts every Linux boot loader signed in the past decadeSecurity Affairs·Feb 7, 14:46 UTC · Feb 7, 2024MalwareCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
Microsoft's Top Execs' Emails Breached in Sophisticated RussiaThe Hacker News·Jan 23, 10:38 UTC · Jan 23, 2024Data breach57
Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023Kaspersky Securelist·Dec 21, 10:30 UTC · Dec 21, 2023RansomwareCVE-2022-24521CVE-2023-23376CVE-2023-28252+3 CVEs60
Google, Microsoft increase bug bountiesHelp Net Security·Dec 14, 13:34 UTC · Dec 14, 2023Vulnerability55
Microsoft launched its new Microsoft Defender Bounty ProgramSecurity Affairs·Nov 24, 19:49 UTC · Nov 24, 2023Exploit / PoC160
October Patch Tuesday Addresses Three ZeroInfosecurity Magazine·Oct 11, 10:30 UTC · Oct 11, 2023Vulnerability in the wildCVE-2023-41763CVE-2023-36563CVE-2023-44487+8 CVEs160
Microsoft AI research division accidentally exposed 38TB of sensitive dataSecurity Affairs·Sep 18, 20:58 UTC · Sep 18, 2023Data breach45
Outlook Hack: Microsoft Reveals How a Crash Dump Led to a Major Security BreachThe Hacker News·Sep 8, 05:00 UTC · Sep 8, 2023Data breach60
Windows feature that resets system clocks based on random data is wreaking havocArs Technica · Security·Aug 15, 00:00 UTC · Aug 15, 2023Industry255
Microsoft takes pains to obscure role in 0Ars Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2023Data breach45
Microsoft Blames Massive DDoS Attack for Azure, Outlook, and OneDrive DisruptionsThe Hacker News·Jun 22, 05:40 UTC · Jun 22, 2023Malware130
Researchers Uncover XSS Vulnerabilities in Azure ServicesInfosecurity Magazine·Jun 14, 14:00 UTC · Jun 14, 2023Vulnerability55
European police dismantled the DoppelPaymer ransomware gangSecurity Affairs·Mar 6, 16:01 UTC · Mar 6, 2023Ransomware57
APT29 abused Windows Credential Roaming in attacksSecurity Affairs·Nov 10, 10:41 UTC · Nov 10, 2022Threat actorCVE-2022-3017060