New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP SystemsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2024Exploit / PoC in the wildCVE-2023-51467CVE-2023-49070CVE-2020-9496+2 CVEs60
Multiple nation-state hackers infiltrate single aviation organizationCyberScoop·Sep 7, 17:07 UTC · Sep 7, 2023Threat actor in the wild60
Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities DetectedThe Hacker News·May 3, 04:08 UTC · May 3, 2023Vulnerability in the wildCVE-2023-1389CVE-2021-45046CVE-2023-21839+1 CVEs60
Understanding your attack surface makes it easier to prioritize technologies and systemsHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2023Ransomware in the wild60
CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ orgThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Ransomware in the wildCVE-2022-22954CVE-2022-22972CVE-2022-22973+1 CVEs60
CISA urges defenders to update after VMware patches vulnerabilities in multiple productsThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-31656CVE-2022-31659CVE-2021-4422860
US and Australian security agencies release list of 2021's 'top' malware strainsThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Malware in the wild60
Google fixes a new actively exploited Chrome zeroSecurity Affairs·Oct 28, 13:01 UTC · Oct 28, 2022Exploit / PoC in the wildCVE-2022-3723CVE-2022-3075CVE-2022-2856+4 CVEs60
Experts warn of CVE-2022Security Affairs·Oct 21, 20:51 UTC · Oct 21, 2022Vulnerability in the wildCVE-2022-42889160
Flaw in the Packagist PHP repository could have allowed a supply chain attackSecurity Affairs·Oct 4, 20:19 UTC · Oct 4, 2022Exploit / PoC in the wildCVE-2022-24828CVE-2021-2947260
Surge in Magento 2 template attacks exploiting CVE-2022Security Affairs·Sep 23, 13:55 UTC · Sep 23, 2022Exploit / PoC in the wildCVE-2022-2408660
Hackers Targeting WebLogic Servers and Docker APIs for Mining CryptocurrenciesThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2022Vulnerability in the wildCVE-2022-26134CVE-2020-14882160
IT threat evolution Q2 2022Kaspersky Securelist·Aug 15, 09:54 UTC · Aug 15, 2022Exploit / PoC in the wildCVE-2022-22965CVE-2022-26925CVE-2022-30190160
Microsoft’s Final Patch Tuesday Fixes Follina BugInfosecurity Magazine·Jun 15, 09:00 UTC · Jun 15, 2022Vulnerability in the wildCVE-2022-30190CVE-2022-30136CVE-2022-30139+1 CVEs60
How fast do cybercriminals capitalize on new security weaknesses?Help Net Security·Apr 21, 00:00 UTC · Apr 21, 2022Ransomware in the wild60
Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet MalwareThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2022Vulnerability in the wildCVE-2022-2296560
Threat Source newsletter (April 7, 2022) — More money for cybersecurity still doesn't solve the skills gap problemCisco Talos·Apr 7, 18:00 UTC · Apr 7, 2022Ransomware in the wildCVE-2022-2296560
Spring4Shell: No need to panic, but mitigations are advisedHelp Net Security·Apr 6, 12:06 UTC · Apr 6, 2022Exploit / PoC in the wildCVE-2022-22963CVE-2010-1622CVE-2022-2296560
Almost a Fifth of Global Firms Targeted with Spring4ShellInfosecurity Magazine·Apr 6, 10:00 UTC · Apr 6, 2022Exploit / PoC in the wildCVE-2022-22965CVE-2022-22963CVE-2022-2294760
Spring4Shell (CVE-2022Kaspersky Securelist·Apr 4, 16:42 UTC · Apr 4, 2022Vulnerability in the wildCVE-2022-22965CVE-2022-22963CVE-2010-162260
Muhstik Botnet Targeting Redis Servers Using Recently Disclosed VulnerabilityThe Hacker News·Mar 28, 06:59 UTC · Mar 28, 2022Vulnerability in the wildCVE-2022-0543CVE-2017-10271CVE-2018-7600+3 CVEs60
CVSS 9.9-Rated Samba Bug Requires Immediate PatchingInfosecurity Magazine·Feb 2, 10:10 UTC · Feb 2, 2022Vulnerability in the wildCVE-2021-4414260
Why vulnerability scanners aren't enough to prevent a ransomware attack on your businessHelp Net Security·Jan 31, 00:00 UTC · Jan 31, 2022Ransomware in the wild60
US Adds 17 Exploited Bugs to “Must Patch” ListInfosecurity Magazine·Jan 24, 10:13 UTC · Jan 24, 2022Vulnerability in the wildCVE-2021-32648CVE-2021-3524760
CISA warns of potential critical threats following attacks against UkraineSecurity Affairs·Jan 19, 15:46 UTC · Jan 19, 2022Advisory in the wildCVE-2021-3264860
White House hosts open-source software security summit in light of expansive Log4j flawCyberScoop·Jan 13, 14:08 UTC · Jan 13, 2022Exploit / PoC in the wild60
The worst cyber attacks of 2021Security Affairs·Jan 4, 21:18 UTC · Jan 4, 2022Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+5 CVEs60
New Apache Log4j Update Released to Patch Newly Discovered VulnerabilityThe Hacker News·Dec 29, 05:00 UTC · Dec 29, 2021Vulnerability in the wildCVE-2021-44832CVE-2021-44228CVE-2021-45046+2 CVEs60
HackDHS program accepts reports of Log4jSecurity Affairs·Dec 23, 10:04 UTC · Dec 23, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-4504660
Apache Issues 3rd Patch to Fix New HighThe Hacker News·Dec 20, 05:02 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-4422860
Ransomware hits HR solutions provider Kronos, locking customers out of vital servicesHelp Net Security·Dec 14, 00:00 UTC · Dec 14, 2021Ransomware in the wild60
CVE-2021-44228 vulnerability in Apache Log4j libraryKaspersky Securelist·Dec 13, 14:10 UTC · Dec 13, 2021Vulnerability in the wildCVE-2021-44228CVE-2021-4504660
Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228)Help Net Security·Dec 13, 12:51 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-4422860
Extremely Critical Log4J Vulnerability Leaves Much of the Internet at RiskThe Hacker News·Dec 11, 05:29 UTC · Dec 11, 2021Vulnerability in the wildCVE-2021-4422860