Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT InfrastructuresThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability in the wildCVE-2024-21893CVE-2024-2188860
Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass ExploitationThe Hacker News·Feb 6, 14:36 UTC · Feb 6, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2024-21887CVE-2023-36661+1 CVEs60
Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN VulnerabilitiesThe Hacker News·Feb 2, 04:53 UTC · Feb 2, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Exploits for Citrix ADC and Gateway flaw abound, attacks are ongoingHelp Net Security·Jan 19, 12:41 UTC · Jan 19, 2024VulnerabilityCVE-2019-1978147
Chinese Hackers Exploited New ZeroThe Hacker News·Dec 28, 11:07 UTC · Dec 28, 2023Exploit / PoC in the wildCVE-2023-7102CVE-2023-2868CVE-2023-710160
Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129)Help Net Security·Sep 29, 10:48 UTC · Sep 29, 2023Exploit / PoC in the wildCVE-2023-5129CVE-2023-4863CVE-2023-4106460
Barracuda thought it drove 0-day hackers out of customers’ networks. It was wrong.Ars Technica · Security·Aug 30, 17:31 UTC · Aug 30, 2023VulnerabilityCVE-2023-286860
Cryptographic Flaw in Libbitcoin Explorer Cryptocurrency WalletSchneier on Security·Aug 15, 00:00 UTC · Aug 15, 2023Malware42
Uncovering weaknesses in Apple macOS and VMWare vCenter: 12 vulnerabilities in RPC implementationCisco Talos·Jul 13, 16:00 UTC · Jul 13, 2023Vulnerability55
Barracuda email security appliances hacked via zero-day vulnerability (CVE-2023-2868)Help Net Security·May 30, 17:14 UTC · May 30, 2023Exploit / PoCCVE-2023-286860
Barracuda Warns of Zero-Day Exploited to Breach Email Security Gateway AppliancesThe Hacker News·May 27, 07:08 UTC · May 27, 2023Exploit / PoC in the wildCVE-2023-286860
WordPress Advanced Custom Fields plugin XSS exposes +2M sites to attacksSecurity Affairs·May 6, 10:56 UTC · May 6, 2023VulnerabilityCVE-2023-29489135
Quarterly Report: Incident Response Trends in Q1 2023Cisco Talos·Apr 26, 12:00 UTC · Apr 26, 2023Ransomware57
Moobot botnet spreads by targeting Cacti and RealTek flawsSecurity Affairs·Apr 3, 07:45 UTC · Apr 3, 2023MalwareCVE-2022-46169CVE-2021-35394CVE-2021-3626060
New ShellBot bot targets poorly managed Linux SSH ServersSecurity Affairs·Mar 21, 19:18 UTC · Mar 21, 2023Malware42
New ShellBot DDoS Malware Variants Targeting Poorly Managed Linux ServersThe Hacker News·Mar 21, 14:44 UTC · Mar 21, 2023Malware42
New shc-based Linux Malware Targeting Systems with Cryptocurrency MinerThe Hacker News·Jan 5, 04:05 UTC · Jan 5, 2023Malware30
New shc Linux Malware used to deploy CoinMinerSecurity Affairs·Jan 4, 11:52 UTC · Jan 4, 2023Malware30
Cloud-Based Cryptocurrency mining attacks abuse GitHub Actions and Azure VMSecurity Affairs·Jul 12, 07:26 UTC · Jul 12, 2022Vulnerability42
Exploit in the Wild: #drupalgeddon2 - Analysis of CVE-2018Palo Alto Unit 42·Jan 28, 21:25 UTC · Jan 28, 2022Exploit / PoC in the wildCVE-2018-760060
Researchers Warn of Linux Cryptojacking Attackers Operating from RomaniaThe Hacker News·Jul 20, 05:49 UTC · Jul 20, 2021Malware30
Privacy and security in the software designing ...........Security Affairs·Apr 22, 16:09 UTC · Apr 22, 2021Vulnerability55
Hundreds of thousands of projects affected by netmask npm package flawSecurity Affairs·Mar 30, 11:16 UTC · Mar 30, 2021VulnerabilityCVE-2021-2891847
We infiltrated an IRC botnet. Here’s what we foundSecurity Affairs·Nov 19, 15:31 UTC · Nov 19, 2020Malware42
Review: Netsparker Enterprise web application scannerHelp Net Security·Oct 19, 00:00 UTC · Oct 19, 2020Vulnerability130
What are script-based attacks and what can be done to prevent them?Help Net Security·Jul 31, 00:00 UTC · Jul 31, 2020RansomwareCVE-2017-0199CVE-2017-1188260
Thinking of a Cybersecurity Career? Read ThisKrebs on Security·Jul 29, 17:36 UTC · Jul 29, 2020Exploit / PoC60
Sudo CVE-2019-18634 flaw allows Non-Privileged Linux and macOS Users run commands as RootSecurity Affairs·Feb 3, 20:44 UTC · Feb 3, 2020VulnerabilityCVE-2019-1863435
Hackers continue to exploit the Drupalgeddon2 flaw in attacks in the wildSecurity Affairs·Oct 8, 05:32 UTC · Oct 8, 2019Exploit / PoCCVE-2018-760060
Interview With the Guy Who Tried to Frame Me for Heroin PossessionKrebs on Security·Sep 26, 01:15 UTC · Sep 26, 2019Vulnerability30
0x20k of Ghost Squad released ODay Exploit Targeting Apache HadoopSecurity Affairs·Nov 1, 14:34 UTC · Nov 1, 2018Exploit / PoC60
Recently discovered DemonBot Botnet targets Hadoop serversSecurity Affairs·Oct 30, 06:55 UTC · Oct 30, 2018Malware30
Hackers targeting Drupal vulnerabilities to install the Shellbot BackdoorSecurity Affairs·Oct 12, 11:21 UTC · Oct 12, 2018VulnerabilityCVE-2018-7600CVE-2018-7602CVE-2017-563860
Hacked Drupal sites involved in mining campaigns, RATs distributions, scamsSecurity Affairs·May 21, 12:00 UTC · May 21, 2018Threat actorCVE-2018-7600CVE-2018-760260
Experts are observing Drupalgeddon2 (CVE-2018Security Affairs·Apr 19, 04:02 UTC · Apr 19, 2018Exploit / PoCCVE-2018-7600CVE-2017-1027160
Hackers Exploiting Drupal Vulnerability to Inject Cryptocurrency MinersThe Hacker News·Apr 18, 09:50 UTC · Apr 18, 2018Vulnerability in the wildCVE-2018-7600CVE-2017-1027160
Hackers running Linux Operation Windigo are changing tactictsSecurity Affairs·Aug 6, 20:31 UTC · Aug 6, 2017Exploit / PoC60
Hidden Mac malware designed to spy on 'everyday people'CyberScoop·Jul 24, 14:59 UTC · Jul 24, 2017Malware in the wild60