Chinese national charged for hacking thousands of Sophos firewallsSecurity Affairs·Dec 11, 10:20 UTC · Dec 11, 2024Policy & legal in the wildCVE-2020-1227160
Sophos details five years of China-linked threat actors' activity targeting network devices worldwideSecurity Affairs·Nov 2, 16:18 UTC · Nov 2, 2024Threat actor60
LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware AttacksThe Hacker News·Dec 7, 07:08 UTC · Dec 7, 2023Vulnerability30
Microsoft Patch Tuesday, May 2023 EditionKrebs on Security·May 10, 07:06 UTC · May 10, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2023-24941+2 CVEs60
Sneaky malware BlackLotus can bypass important Windows boot functionsThe Record·Mar 10, 14:17 UTC · Mar 10, 2023Malware in the wild57
Week in review: Finding stolen credentials on VirusTotal, BNPL attracting fraudstersHelp Net Security·Feb 28, 14:42 UTC · Feb 28, 2022Phishing & fraudCVE-2021-3524760
End of 2021 witnessed an explosion of RDP brute-force attacksHelp Net Security·Feb 9, 00:00 UTC · Feb 9, 2022VulnerabilityCVE-2017-1188247
IT threat evolution Q3 2021Kaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021Exploit / PoCCVE-2021-4044460
Advanced threat predictions for 2022Kaspersky Securelist·Nov 17, 10:00 UTC · Nov 17, 2021Ransomware60
Japanese businesses are the latest victims of attacks disguised as ransomwareCyberScoop·Nov 3, 18:51 UTC · Nov 3, 2017Ransomware in the wild60
Hacking 4G USB modems and SIM Card via SMSSecurity Affairs·Dec 31, 13:37 UTC · Dec 31, 2014Exploit / PoC60
Eleven Vulnerable UEFI Shims Enable Secure Boot BypassInfosecurity Magazine·Jul 15, 14:00 UTC · Jul 15, 2026VulnerabilityCVE-2026-8863CVE-2026-10797135
Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Threat actor60
SprySOCKS Backdoor Expands From Linux to WindowsInfosecurity Magazine·Jun 16, 14:30 UTC · Jun 16, 2026Malware42
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Friday Squid Blogging: Squid Fishing in PeruSchneier on Security·Feb 27, 22:04 UTC · Feb 27, 2026Ransomware60
Cisco ASA zero-day vulnerabilities exploited in sophisticated attacksHelp Net Security·Nov 13, 13:30 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Sprout: Open-source bootloader built for speed and securityHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2025Malware55
Cisco became aware of a new attack variant against Secure Firewall ASA and FTD devicesSecurity Affairs·Nov 6, 18:26 UTC · Nov 6, 2025Data breach in the wildCVE-2025-20333CVE-2025-2036260
Chrome Zero-Day Exploited to Deliver Italian Memento Labs' LeetAgent SpywareThe Hacker News·Nov 3, 17:57 UTC · Nov 3, 2025Exploit / PoC in the wildCVE-2025-2783160
Feds Tie ‘Scattered Spider’ Duo to $115M in RansomsKrebs on Security·Sep 24, 12:59 UTC · Sep 24, 2025Ransomware57
Vulnerability landscape analysis for Q2 2025Kaspersky Securelist·Aug 27, 10:00 UTC · Aug 27, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053)Help Net Security·Jun 16, 13:26 UTC · Jun 16, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-33073CVE-2025-33070+6 CVEs60
Friday Squid Blogging: Squid Run in Southern New EnglandSchneier on Security·Jun 6, 21:00 UTC · Jun 6, 2025Vulnerability130
RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell FeaturesThe Hacker News·Mar 31, 09:11 UTC · Mar 31, 2025MalwareCVE-2025-028260
CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360
ESET detailed a flaw that could allow a bypass of the Secure Boot in UEFI systemsSecurity Affairs·Jan 17, 11:15 UTC · Jan 17, 2025Exploit / PoCCVE-2024-7344CVE-2022-3430250
New UEFI Secure Boot bypass vulnerability discovered (CVE-2024-7344)Help Net Security·Jan 16, 00:00 UTC · Jan 16, 2025VulnerabilityCVE-2024-734435
Microsoft patches Windows to eliminate Secure Boot bypass threatArs Technica · Security·Jan 15, 00:00 UTC · Jan 15, 2025VulnerabilityCVE-2024-7344135
Security Affairs newsletter Round 501 by Pierluigi PaganiniSecurity Affairs·Dec 8, 12:13 UTC · Dec 8, 2024Ransomware57
Code found online exploits LogoFAIL to install Bootkitty Linux backdoorArs Technica · Security·Nov 29, 21:37 UTC · Nov 29, 2024Malware42
Sophos mounted counter-offensive operation to foil Chinese attackersHelp Net Security·Oct 31, 00:00 UTC · Oct 31, 2024Exploit / PoC in the wildCVE-2022-104060
"Perfect" Windows downgrade attack turns fixed vulnerabilities into zero-daysHelp Net Security·Aug 30, 12:36 UTC · Aug 30, 2024VulnerabilityCVE-2024-38202CVE-2024-2130260
Almost unfixable “Sinkclose” bug affects hundreds of millions of AMD chipsArs Technica · Security·Aug 10, 13:00 UTC · Aug 10, 2024Exploit / PoC60
Sonos Speaker Flaws Could Have Let Remote Hackers Eavesdrop on UsersThe Hacker News·Aug 10, 07:14 UTC · Aug 10, 2024VulnerabilityCVE-2023-50809CVE-2023-50810CVE-2024-2001860
Some good may come out of the CrowdStrike outageHelp Net Security·Jul 29, 00:00 UTC · Jul 29, 2024Vulnerability30