Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT SystemsThe Hacker News·Apr 24, 09:29 UTC · Apr 24, 2026Malware55
Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and MalwareThe Hacker News·Jul 29, 09:05 UTC · Jul 29, 2025MalwareCVE-2023-38950CVE-2023-38951CVE-2023-3895260
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated CyberattacksThe Hacker News·Nov 27, 04:06 UTC · Nov 27, 2024Exploit / PoCCVE-2024-9680CVE-2024-49039CVE-2023-3688460
Industrial companies in Europe targeted with GuLoaderHelp Net Security·Nov 7, 00:00 UTC · Nov 7, 2024Malware55
Lazarus APT steals cryptocurrency and user data via a decoy MOBA gameKaspersky Securelist·Oct 23, 11:00 UTC · Oct 23, 2024Threat actorCVE-2024-494760
North Korean Hackers Deploy FudModule Rootkit via Chrome ZeroThe Hacker News·Oct 23, 04:44 UTC · Oct 23, 2024Malware in the wildCVE-2024-7971CVE-2024-4947CVE-2024-5274+3 CVEs60
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 20:17 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2024-20353CVE-2024-20359CVE-2024-4040+1 CVEs60
Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networksSecurity Affairs·Apr 24, 20:31 UTC · Apr 24, 2024Exploit / PoCCVE-2024-20353CVE-2024-20359CVE-2018-0101160
Operation Triangulation attacks relied on an undocumented hardware featureSecurity Affairs·Dec 28, 23:10 UTC · Dec 28, 2023Exploit / PoCCVE-2023-41990CVE-2023-32434CVE-2023-38606160
Iranian Cyber Espionage Group Targets Financial and Government Sectors in Middle EastThe Hacker News·Nov 3, 04:45 UTC · Nov 3, 2023Threat actor60
ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom CompaniesThe Hacker News·Sep 20, 04:36 UTC · Sep 20, 2023Malware155
North Korea-linked threat actors target cybersecurity experts with a zeroSecurity Affairs·Sep 8, 19:51 UTC · Sep 8, 2023Threat actor in the wild60
Bitter APT adds Bangladesh to their targetsCisco Talos·May 11, 12:00 UTC · May 11, 2022Exploit / PoCCVE-2017-11882CVE-2018-0798CVE-2018-0802+1 CVEs60
Microsoft warns of more disruptive BlueKeep AttacksSecurity Affairs·Nov 8, 13:28 UTC · Nov 8, 2019Ransomware in the wildCVE-2019-070860
First mass BlueKeep exploitation spotted in the wildSecurity Affairs·Nov 3, 14:21 UTC · Nov 3, 2019Exploit / PoC in the wildCVE-2019-070860
2 Zero-Days found in March were part of a cyber weapon in an early development stageSecurity Affairs·Jul 3, 05:42 UTC · Jul 3, 2018Exploit / PoCCVE-2018-4990CVE-2018-812060
Experts uncovered a watering hole attack on leading Hong Kong Telecom Site exploiting CVE-2018Security Affairs·Mar 27, 07:34 UTC · Mar 27, 2018Exploit / PoCCVE-2018-487860
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More StoriesThe Hacker News·Jul 9, 15:09 UTC · Jul 9, 2026Phishing & fraudCVE-2026-918160
PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News·May 7, 17:58 UTC · May 7, 2026Vulnerability in the wildCVE-2026-030060
SloppyLemming Targets Pakistan and Bangladesh Governments Using Dual Malware ChainsThe Hacker News·Mar 3, 06:53 UTC · Mar 3, 2026Malware55
Notepad++ supply chain attack: Researchers reveal details, IoCs, targetsHelp Net Security·Feb 17, 10:13 UTC · Feb 17, 2026Exploit / PoC60
APT28 exploits Microsoft Office flaw in Operation NeusploitSecurity Affairs·Feb 3, 12:13 UTC · Feb 3, 2026Threat actor in the wildCVE-2026-2150960
Notepad++ infrastructure hack likely tied to ChinaSecurity Affairs·Feb 3, 09:35 UTC · Feb 3, 2026Exploit / PoC60
JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple StealersThe Hacker News·Dec 2, 05:40 UTC · Dec 2, 2025Malware55
Dynamic binary instrumentation (DBI) with DynamoRioCisco Talos·Oct 30, 09:59 UTC · Oct 30, 2025Vulnerability55
Memento Labs, the ghost of Hacking Team, has returned — or maybe it was never gone at all.Security Affairs·Oct 27, 20:31 UTC · Oct 27, 2025Exploit / PoCCVE-2025-2783CVE-2025-285760
Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePEThe Hacker News·Sep 3, 03:44 UTC · Sep 3, 2025Malware55
Analyzing evolution of the PipeMagic malwareSecurity Affairs·Aug 19, 08:02 UTC · Aug 19, 2025Malware in the wildCVE-2025-29824CVE-2017-014460
Taiwan Web Servers Breached by UAT-7237 Using Customized OpenThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Data breach160
New APT32 Malware Campaign Targets Cambodian GovernmentRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Malware55
Microsoft Patches 67 Vulnerabilities Including WEBDAV ZeroThe Hacker News·Jun 12, 15:47 UTC · Jun 12, 2025Vulnerability in the wildCVE-2025-33053CVE-2025-47966CVE-2025-32713+3 CVEs160
Earth Ammit Breached Drone Supply Chains via ERP in VENOM, TIDRONE CampaignsThe Hacker News·May 15, 00:00 UTC · May 15, 2025Data breach60
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60
Planet WGS-804HPT Industrial Switch flaws could be chained to achieve remote code executionSecurity Affairs·Jan 20, 00:27 UTC · Jan 20, 2025VulnerabilityCVE-2024-48871CVE-2024-52320CVE-2024-5255860
An X user claimed a 7-Zip zero-day vulnerability, but 7Security Affairs·Dec 31, 00:09 UTC · Dec 31, 2024Exploit / PoC60
Russian group RomCom exploited Firefox and Tor Browser zero-days to target attacks Europe and North AmericaSecurity Affairs·Nov 27, 08:37 UTC · Nov 27, 2024Exploit / PoC in the wildCVE-2024-9680CVE-2024-4903960
RomCom hackers chained Firefox and Windows zero-days to deliver backdoorHelp Net Security·Nov 26, 00:00 UTC · Nov 26, 2024MalwareCVE-2024-9680CVE-2024-49039CVE-2023-3688460
Warning: DEEPDATA Malware Exploiting Unpatched Fortinet Flaw to Steal VPN CredentialsThe Hacker News·Nov 18, 03:52 UTC · Nov 18, 2024Vulnerability55