What I’ve learned in my first 7Cisco Talos·Oct 17, 18:00 UTC · Oct 17, 2024Ransomware in the wildCVE-2024-4304760
Microsoft seizes domain used by Vietnamese group to sell fake accounts, servicesCyberScoop·Jul 31, 23:58 UTC · Jul 31, 2024Ransomware in the wild60
New MOVEit Transfer critical bug is actively exploitedSecurity Affairs·Jun 26, 19:54 UTC · Jun 26, 2024Vulnerability in the wildCVE-2024-5805CVE-2024-580660
Most Sophisticated iPhone Hack Ever Exploited Apple's Hidden Hardware FeatureThe Hacker News·Jan 4, 05:41 UTC · Jan 4, 2024Exploit / PoC in the wildCVE-2023-41990CVE-2023-32434CVE-2023-32435+4 CVEs160
BlueKeep RDP flaw: Nearly a million Internet-facing systems are vulnerableHelp Net Security·Nov 15, 08:03 UTC · Nov 15, 2023Ransomware in the wildCVE-2019-070860
“This vulnerability is now under mass exploitation.” Citrix Bleed bug bites hardArs Technica · Security·Oct 30, 21:39 UTC · Oct 30, 2023Vulnerability in the wild60
Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP ServerThe Hacker News·Oct 9, 06:43 UTC · Oct 9, 2023Ransomware in the wildCVE-2023-40044CVE-2023-42657CVE-2023-40045+5 CVEs60
They’ve begun: Attacks exploiting vulnerability with maximum 10 severity ratingArs Technica · Security·Oct 3, 21:53 UTC · Oct 3, 2023Vulnerability in the wildCVE-2023-40044CVE-2023-4265760
Hackers seen exploiting bugs in browsers and popular file transfer toolThe Record·Oct 3, 13:21 UTC · Oct 3, 2023Ransomware in the wildCVE-2023-5217CVE-2023-4004460
SAP systems usually come under attack 72 hours after a patchThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Vulnerability in the wild57
Most attackers lose interest in Log4ShellThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC in the wildCVE-2021-4422860
FortiOS flaw was exploited to compromise governmental targets (CVE-2022-42475)Help Net Security·Jan 13, 00:00 UTC · Jan 13, 2023Vulnerability in the wildCVE-2022-4247560
Auth bypass bug in FortiOS, FortiProxy is exploited in the wild (CVE-2022-40684)Help Net Security·Oct 14, 14:21 UTC · Oct 14, 2022Exploit / PoC in the wildCVE-2022-4068460
Critical flaw in Zyxel firewalls grants access to corporate networks (CVE-2022-30525)Help Net Security·May 16, 10:05 UTC · May 16, 2022Vulnerability in the wildCVE-2022-3052560
NSA Discovers New Vulnerabilities Affecting Microsoft Exchange ServersThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2021Vulnerability in the wildCVE-2021-28310CVE-2021-1732CVE-2021-28480+6 CVEs60
Update Your Chrome Browser to Patch 2 New In-the-Wild 0The Hacker News·Apr 15, 00:00 UTC · Apr 15, 2021Vulnerability in the wildCVE-2021-21220CVE-2021-21206CVE-2021-21148+2 CVEs160
SAP systems are targeted within 72 hours after updates are releasedSecurity Affairs·Apr 6, 17:22 UTC · Apr 6, 2021Ransomware in the wildCVE-2010-5326CVE-2018-2380CVE-2016-3976+3 CVEs60
Critical F5 BIG-IP Bug Under Active Attacks After PoC Exploit Posted OnlineThe Hacker News·Mar 22, 14:27 UTC · Mar 22, 2021Exploit / PoC in the wildCVE-2021-22986CVE-2020-590260
ProxyLogon Microsoft Exchange exploit is completely out of the bagSecurity Affairs·Mar 15, 12:56 UTC · Mar 15, 2021Ransomware in the wildCVE-2021-2685560
ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Exploit / PoC in the wildCVE-2021-2685560
Expert publishes PoC exploit code for Microsoft Exchange flawsSecurity Affairs·Mar 11, 21:33 UTC · Mar 11, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Baidu apps in Google Play Store left users vulnerable to tracking, Palo Alto findsCyberScoop·Nov 25, 19:53 UTC · Nov 25, 2020Exploit / PoC in the wild60
Microsoft's new 'Pluton' security processor gets buyCyberScoop·Nov 17, 17:26 UTC · Nov 17, 2020Exploit / PoC in the wild60
Chrome 86.0.4240.111 fixes actively exploited CVE-2020-15999 zeroSecurity Affairs·Oct 21, 12:55 UTC · Oct 21, 2020Vulnerability in the wildCVE-2020-15999CVE-2019-13720CVE-2020-641860
Old vulnerabilities die hard: researchers uncover 20-yearCyberScoop·Aug 7, 18:03 UTC · Aug 7, 2020Vulnerability in the wild60
New Highly-Critical SAP Bug Could Let Attackers Take Over Corporate ServersThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2020Vulnerability in the wildCVE-2020-628760
Critical SAP Recon flaw exposes thousands of system to full take overSecurity Affairs·Jul 14, 10:08 UTC · Jul 14, 2020Vulnerability in the wildCVE-2020-628760
Facebook reinstates NSO Group employee accounts amid ongoing lawsuitCyberScoop·Jul 2, 00:35 UTC · Jul 2, 2020Policy & legal in the wild60
An Undisclosed Critical Vulnerability Affect vBulletin Forums — Patch NowThe Hacker News·May 11, 19:11 UTC · May 11, 2020Vulnerability in the wildCVE-2020-1272060
A malicious Android app is trying to scam Brazilian bank customersCyberScoop·Apr 21, 15:57 UTC · Apr 21, 2020Phishing & fraud in the wild60
9 Years of AMD Processors Vulnerable to 2 New SideThe Hacker News·Mar 9, 14:20 UTC · Mar 9, 2020Vulnerability in the wild57
Department of Interior grounding drone fleet over cybersecurity concernsCyberScoop·Jan 29, 18:21 UTC · Jan 29, 2020Exploit / PoC in the wild60
Navy letter shows military worried about unknown vulnerabilities in DJI dronesCyberScoop·Dec 16, 18:15 UTC · Dec 16, 2019Vulnerability in the wild60
Microsoft Patch Tuesday updates fix CVE-2019Security Affairs·Nov 13, 08:26 UTC · Nov 13, 2019Vulnerability in the wildCVE-2019-1429CVE-2019-137360
The latest on BlueKeep and DejaBlue vulnerabilities — Using Firepower to defend against encrypted DejaBlueCisco Talos·Nov 4, 15:43 UTC · Nov 4, 2019Vulnerability in the wildCVE-2019-0708CVE-2019-1181CVE-2019-118260
NSA’s reverse engineering tool Ghidra impacted by a bug — but there's no need to panicCyberScoop·Oct 1, 21:13 UTC · Oct 1, 2019Exploit / PoC in the wildCVE-2019-1694160
How an NSA researcher plans to allow everyone to guard against firmware attacksCyberScoop·Aug 23, 21:17 UTC · Aug 23, 2019Exploit / PoC in the wild60
The developers of the notorious FinSpy spyware are innovating — and thrivingCyberScoop·Jul 11, 16:51 UTC · Jul 11, 2019Malware in the wild60
Chinese hackers found and repurposed elite NSACyberScoop·May 7, 13:43 UTC · May 7, 2019Exploit / PoC in the wild60
Magento sites under attack through easily exploitable SQLi flawHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2019Exploit / PoC in the wild60