⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+23 CVEs160
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from JanuaryRecorded Future·Mar 13, 00:00 UTC · Mar 13, 2026Vulnerability in the wildCVE-2025-15556CVE-2026-21513CVE-2026-21533+4 CVEs160
Threat and Vulnerability Management in 2026Recorded Future·Jan 14, 00:00 UTC · Jan 14, 2026Vulnerability in the wild60
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039)Help Net Security·Nov 26, 13:25 UTC · Nov 26, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-43639+3 CVEs60
Google TAG shares details about exploit chains used to install commercial spywareSecurity Affairs·Mar 29, 14:20 UTC · Mar 29, 2023MalwareCVE-2022-42856CVE-2021-30900CVE-2022-3723+7 CVEs60
Chrome 0-day exploit CVE-2019Kaspersky Securelist·Nov 1, 16:00 UTC · Nov 1, 2019Exploit / PoCCVE-2019-1372060
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News·Jul 22, 15:41 UTC · Jul 22, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
Mythos Outperforms GPT5.5 on Google Chrome Vulnerability ExploitsInfosecurity Magazine·Jun 4, 13:00 UTC · Jun 4, 2026Vulnerability55
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
Network Attack Trends: Internet of Threats (November 2020Palo Alto Unit 42·Jun 6, 13:24 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2020-28188CVE-2020-17519CVE-2020-29227+62 CVEs60
Google: China dominates government exploitation of zeroSecurity Affairs·Mar 28, 12:16 UTC · Mar 28, 2024Ransomware in the wild60
Explosion of 0-day exploits: The bad news and the good newsHelp Net Security·Jul 15, 00:00 UTC · Jul 15, 2021Exploit / PoC in the wildCVE-2021-21166CVE-2021-30551CVE-2021-3374260
Sophisticated hacking campaign uses Windows and Android zeroSecurity Affairs·Jan 12, 23:32 UTC · Jan 12, 2021Threat actorCVE-2020-6418CVE-2020-0938CVE-2020-1020+1 CVEs60
The effectiveness of vulnerability disclosure and exploit developmentHelp Net Security·Nov 19, 00:00 UTC · Nov 19, 2020Vulnerability55
PoC Exploits for CVE-2019-0708 wormable Windows flaw released onlineSecurity Affairs·May 23, 22:37 UTC · May 23, 2019Exploit / PoCCVE-2019-070860
Fallout Exploit Kit now includes exploit for CVE-2018-15982 Flash zeroSecurity Affairs·Jan 18, 23:22 UTC · Jan 18, 2019VulnerabilityCVE-2018-1598260
React2Shell fallout spreads to sensitive targets as public exploits hit allCyberScoop·Dec 18, 16:12 UTC · Dec 18, 2025Ransomware in the wildCVE-2025-55182CVE-2025-55183CVE-2025-67779+1 CVEs60
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
The BetterBank DeFi protocol exploited for reward mintingKaspersky Securelist·Oct 22, 10:00 UTC · Oct 22, 2025Exploit / PoC60
The Right Threat Intelligence for PatchingRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Data breach in the wild60
Network Security Trends: MayPalo Alto Unit 42·Jun 6, 01:20 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2020-11978CVE-2020-13927CVE-2021-2785060
Zero-days exploited in the wild jumped 50% in 2023, fueled by spyware vendorsThe Record·Mar 27, 01:56 UTC · Mar 27, 2024Exploit / PoC in the wildCVE-2023-4863CVE-2023-41064CVE-2023-521760
Raspberry Robin spotted using two new 1Security Affairs·Feb 11, 19:37 UTC · Feb 11, 2024Exploit / PoC in the wildCVE-2023-36802CVE-2023-2936060
New iPhone Exploit Uses Four Zero-DaysSchneier on Security·Jan 4, 12:11 UTC · Jan 4, 2024Exploit / PoCCVE-2023-41990CVE-2023-32434CVE-2023-38606+1 CVEs60
Microsoft Patch TuesdayCisco Talos·Nov 8, 22:09 UTC · Nov 8, 2016VulnerabilityCVE-2016-7212CVE-2016-7248CVE-2016-7205+8 CVEs60
The Epic Turla OperationKaspersky Securelist·Aug 7, 13:55 UTC · Aug 7, 2014Threat actorCVE-2013-5065CVE-2013-3346CVE-2012-172360
Kaspersky Lab report: Evaluating the threat level of software vulnerabilitiesKaspersky Securelist·Feb 1, 14:30 UTC · Feb 1, 2013Vulnerability in the wild160
DarkSword emerges as powerful iOS exploit tool in global attacksSecurity Affairs·Mar 19, 14:09 UTC · Mar 19, 2026Exploit / PoCCVE-2025-31277CVE-2026-20700CVE-2025-43529+3 CVEs60
ToolShell Exploit: Critical SharePoint ZeroRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs160
44% Of The Zero-Days Exploited In 2024 Were In Enterprise SolutionsHelp Net Security·Apr 29, 00:00 UTC · Apr 29, 2025Exploit / PoCCVE-2024-53104CVE-2024-32896CVE-2024-29745+1 CVEs60
VulnCheck spotted 159 actively exploited vulnerabilities in first few months of 2025CyberScoop·Apr 24, 22:57 UTC · Apr 24, 2025Vulnerability in the wild60
China-linked APT Velvet Ant exploited zeroSecurity Affairs·Aug 23, 07:21 UTC · Aug 23, 2024Exploit / PoC in the wildCVE-2024-2039960
APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk PlusPalo Alto Unit 42·Jun 6, 01:25 UTC · Jun 6, 2024Threat actor in the wildCVE-2021-44077CVE-2021-3361760
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
CISA adds recently discovered Apple zero-days to Known Exploited Vulnerabilities CatalogSecurity Affairs·Sep 11, 18:22 UTC · Sep 11, 2023Exploit / PoC in the wildCVE-2023-41064CVE-2023-41061CVE-2023-37450+10 CVEs60
2022 Zero-Day exploitation continues at a worrisome paceSecurity Affairs·Mar 21, 15:28 UTC · Mar 21, 2023Exploit / PoCCVE-2022-24682CVE-2022-1040CVE-2022-30190+5 CVEs60
A threat actor exploited 11 zeroSecurity Affairs·Mar 20, 20:11 UTC · Mar 20, 2021Threat actor in the wildCVE-2020-27930CVE-2020-27950CVE-2020-27932+8 CVEs60
ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Exploit / PoC in the wildCVE-2021-2685560
Idaho National Lab researcher shines a light on the market for ICS zeroCyberScoop·Jan 22, 23:33 UTC · Jan 22, 2020Exploit / PoC in the wild60