Llamafile, Mozilla's portable LLM runner, gets GPU support and a rebuilt coreHelp Net Security·Jun 14, 15:32 UTC · Jun 14, 2026Model release50
GitHub Copilot app launches as desktop home for AI coding agentsHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2026AI research130
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD WorkflowsThe Hacker News·May 26, 11:56 UTC · May 26, 2026Ransomware57
Sandyaa: Open-source autonomous security bug hunterHelp Net Security·May 13, 00:00 UTC · May 13, 2026Exploit / PoC45
HEIDI: Free IDE security plugin for open-source vulnerability checksHelp Net Security·May 12, 00:00 UTC · May 12, 2026Vulnerability42
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & MoreThe Hacker News·Apr 28, 07:38 UTC · Apr 28, 2026MalwareCVE-2025-20333CVE-2025-20362CVE-2026-40372+20 CVEs147
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Surge in Magento 2 template attacksSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Hewlett Packard Enterprise fixes critical authentication bypass in Aruba AOSSecurity Affairs·Mar 11, 11:28 UTC · Mar 11, 2026VulnerabilityCVE-2026-23813CVE-2026-23814CVE-2026-23815+3 CVEs60
Active exploitation of Cisco Catalyst SD-WAN by UATCisco Talos·Feb 25, 16:13 UTC · Feb 25, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2022-2077560
Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT MalwareThe Hacker News·Feb 6, 08:40 UTC · Feb 6, 2026Malware42
DockerDash Exposes AI Supply Chain Weakness In Docker's Ask GordonInfosecurity Magazine·Feb 3, 15:15 UTC · Feb 3, 2026Vulnerability155
ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware WavesThe Hacker News·Nov 21, 06:45 UTC · Nov 21, 2025MalwareCVE-2025-61757CVE-2025-1124360
Cisco ASA zero-day vulnerabilities exploited in sophisticated attacksHelp Net Security·Nov 13, 13:30 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Jenkins patched a critical RCE flaw in its open source automation serverSecurity Affairs·Oct 4, 15:37 UTC · Oct 4, 2025VulnerabilityCVE-2017-1000353CVE-2017-1000354CVE-2017-100035560
UK NCSC warns that attackers exploited Cisco firewall zero-days to deploy RayInitiator and LINE VIPER malwareSecurity Affairs·Sep 26, 11:49 UTC · Sep 26, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI CredentialsThe Hacker News·Sep 6, 11:31 UTC · Sep 6, 2025Malware55
CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, DThe Hacker News·Jun 27, 05:06 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2024-54085CVE-2024-0769CVE-2019-669360
GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLsThe Hacker News·Jan 28, 03:11 UTC · Jan 28, 2025VulnerabilityCVE-2025-23040CVE-2024-50338CVE-2024-53263+4 CVEs35
HPE Issues Critical Security Patches for Aruba Access Point VulnerabilitiesThe Hacker News·Nov 11, 09:57 UTC · Nov 11, 2024Vulnerability in the wildCVE-2024-42509CVE-2024-47460CVE-2024-47461+3 CVEs60
Security Flaw in Styra's OPA Exposes NTLM Hashes to Remote AttackersThe Hacker News·Oct 23, 05:48 UTC · Oct 23, 2024VulnerabilityCVE-2024-8260CVE-2024-4353235
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
Hillstone Networks launches StoneOS 5.5R11 to enhance threat protectionHelp Net Security·Aug 27, 00:00 UTC · Aug 27, 2024Malware30
CISA adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 8, 07:16 UTC · Jul 8, 2024Exploit / PoC in the wildCVE-2024-2039960
China-linked APT exploited Cisco NX-OS zeroSecurity Affairs·Jul 2, 07:25 UTC · Jul 2, 2024Exploit / PoC in the wildCVE-2024-2039960
PoC exploit for Ivanti EPMM privilege escalation flaw released (CVE 2024-22026)Help Net Security·May 20, 00:00 UTC · May 20, 2024Exploit / PoCCVE-2024-22026CVE-2023-46806CVE-2023-4680760
Cisco warns of a command injection escalation flaw in its IMCSecurity Affairs·Apr 18, 07:16 UTC · Apr 18, 2024Exploit / PoCCVE-2024-2029560
LeakyCLI Flaw Exposes AWS and Google Cloud CredentialsInfosecurity Magazine·Apr 16, 14:15 UTC · Apr 16, 2024VulnerabilityCVE-2023-3605260
Multiple PoC exploits released for Jenkins flaw CVE-2024Security Affairs·Jan 28, 18:25 UTC · Jan 28, 2024Exploit / PoCCVE-2024-2389760
Tell Me Your Secrets Without Telling Me Your SecretsThe Hacker News·Nov 24, 10:53 UTC · Nov 24, 2023Threat actor57
Comprehensive analysis of initial attack samples exploiting CVE-2023Kaspersky Securelist·Jul 19, 12:00 UTC · Jul 19, 2023Exploit / PoCCVE-2023-23397CVE-2023-2932460
Surge in Magento 2 template attacks exploiting CVE-2022Security Affairs·Sep 23, 13:55 UTC · Sep 23, 2022Exploit / PoC in the wildCVE-2022-2408660
Zyxel addressed a critical RCE flaw in its NAS devicesSecurity Affairs·Sep 7, 08:53 UTC · Sep 7, 2022VulnerabilityCVE-2022-34747CVE-2022-26532CVE-2022-0734+2 CVEs60
Fortinet addressed multiple vulnerabilities in several productsSecurity Affairs·Jul 9, 13:17 UTC · Jul 9, 2022VulnerabilityCVE-2022-26117CVE-2021-43072CVE-2022-30302+1 CVEs47
GitGuardian announces new features to help developers reduce risks of exposureHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2022Vulnerability130
Zyxel addresses four flaws affecting APs, AP controllers, and firewallsSecurity Affairs·May 26, 19:28 UTC · May 26, 2022VulnerabilityCVE-2022-26532CVE-2022-0734CVE-2022-26531+1 CVEs35
Orca Security unveils Shift Left Security capabilities to prevent cloud application issuesHelp Net Security·May 12, 00:00 UTC · May 12, 2022Vulnerability55