⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and MoreThe Hacker News·Mar 2, 13:26 UTC · Mar 2, 2026Data breach in the wildCVE-2026-20127CVE-2025-40538CVE-2025-40539+27 CVEs60
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More StoriesThe Hacker News·Dec 18, 12:15 UTC · Dec 18, 2025MalwareCVE-2024-3721CVE-2025-5518260
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
Researchers warn of widespread RDP attacks by 100KSecurity Affairs·Oct 14, 18:20 UTC · Oct 14, 2025Vulnerability30
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860
Fortinet SSL VPNs Hit by Global Brute-Force Wave Before Attackers Shift to FortiManagerThe Hacker News·Aug 12, 17:05 UTC · Aug 12, 2025Threat actor45
CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target EnterprisesThe Hacker News·Jul 18, 04:54 UTC · Jul 18, 2025Exploit / PoC in the wildCVE-2025-5777CVE-2023-4966CVE-2025-6543+1 CVEs60
TP-Link Router Flaw CVE-2023-33538 Under Active Exploit, CISA Issues Immediate AlertThe Hacker News·Jun 19, 03:14 UTC · Jun 19, 2025Vulnerability in the wildCVE-2023-33538CVE-2023-2877160
295 Malicious IPs Launch Coordinated BruteThe Hacker News·Jun 11, 13:49 UTC · Jun 11, 2025Ransomware45
U.S. CISA adds ASUS RT-AX55 devices, Craft CMS, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 3, 19:35 UTC · Jun 3, 2025Exploit / PoC in the wildCVE-2021-32030CVE-2023-39780CVE-2024-56145+2 CVEs60
Thousands of Asus routers are being hit with stealthy, persistent backdoorsArs Technica · Security·May 28, 22:12 UTC · May 28, 2025MalwareCVE-2023-3978047
Questions mount as Ivanti tackles another round of zeroCyberScoop·May 28, 21:39 UTC · May 28, 2025Ransomware in the wildCVE-2025-4427CVE-2025-442860
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger ImpactThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-25015CVE-2025-22224CVE-2025-22225+18 CVEs60
⚡ Weekly Recap: Windows 0-Day, VPN Exploits, Weaponized AI, Hijacked Antivirus and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-29824CVE-2024-11859CVE-2025-3102+17 CVEs60
⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain BackdoorsThe Hacker News·May 6, 05:03 UTC · May 6, 2025MalwareCVE-2025-3928CVE-2025-1976CVE-2025-46271+33 CVEs60
Attackers are chaining flaws to breach Palo Alto Networks firewallsHelp Net Security·Apr 18, 10:11 UTC · Apr 18, 2025Exploit / PoC in the wildCVE-2025-0108CVE-2024-9474CVE-2025-0111+1 CVEs60
Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISAThe Hacker News·Feb 25, 04:10 UTC · Feb 25, 2025Data breach in the wildCVE-2017-3066CVE-2024-20953CVE-2024-21287+3 CVEs60
Palo Alto Networks Patches Authentication Bypass Exploit in PANThe Hacker News·Feb 18, 06:46 UTC · Feb 18, 2025Vulnerability in the wildCVE-2025-0108CVE-2025-0109CVE-2025-0110+1 CVEs60
Multiple threat actors exploit PHP flaw CVE-2024Security Affairs·Jul 11, 14:31 UTC · Jul 11, 2024Threat actor in the wildCVE-2024-4577CVE-2012-182360
PHP addressed critical RCE potentially impacting millions of serversSecurity Affairs·Jun 9, 13:27 UTC · Jun 9, 2024VulnerabilityCVE-2024-4577CVE-2012-182360
Check Point Warns of ZeroThe Hacker News·Jun 6, 04:42 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2024-2491960
92,000+ internet-facing D-Link NAS devices accessible via "backdoor" account (CVE-2024-3273)Help Net Security·Apr 12, 11:05 UTC · Apr 12, 2024Vulnerability in the wildCVE-2024-3273CVE-2024-327260
CISA orders Ivanti devices targeted by Chinese hackers be disconnectedCyberScoop·Feb 1, 20:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2024-2188760
Hackers Exploit Critical Vulnerability in ownCloudInfosecurity Magazine·Nov 29, 10:00 UTC · Nov 29, 2023Vulnerability in the wildCVE-2023-49105CVE-2023-4910460
ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitationArs Technica · Security·Nov 29, 00:38 UTC · Nov 29, 2023Vulnerability in the wildCVE-2023-49103CVE-2023-4966CVE-2023-94105+1 CVEs60
Experts warn of critical ownCloud vulnerability being exploitedThe Record·Nov 28, 22:23 UTC · Nov 28, 2023VulnerabilityCVE-2023-4910360
Threat actors started exploiting critical ownCloud flawSecurity Affairs·Nov 28, 21:33 UTC · Nov 28, 2023Threat actor in the wildCVE-2023-4910360
BlueKeep RDP flaw: Nearly a million Internet-facing systems are vulnerableHelp Net Security·Nov 15, 08:03 UTC · Nov 15, 2023Ransomware in the wildCVE-2019-070860
11 Search Engines For Cybersecurity Research You Can Use Right NowHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2023Vulnerability30
CISA Adds Citrix ShareFile Flaw to KEV Catalog Due to In-theThe Hacker News·Aug 21, 03:43 UTC · Aug 21, 2023Exploit / PoC in the wildCVE-2023-24489CVE-2023-351960
Citrix ShareFile vulnerability actively exploited (CVE-2023-24489)Help Net Security·Aug 17, 00:00 UTC · Aug 17, 2023Vulnerability in the wildCVE-2023-2448960
CISA: Ivanti hacks targeting Norway began in AprilThe Record·Aug 1, 19:55 UTC · Aug 1, 2023Data breach in the wildCVE-2023-3507860
CISA says latest VMware analytics bug being exploitedThe Record·Jun 23, 12:17 UTC · Jun 23, 2023Exploit / PoC in the wildCVE-2023-20887CVE-2016-9079CVE-2016-016560
Critical RCE CVE-2023-20887 in VMware vRealize exploited in the wildSecurity Affairs·Jun 21, 06:13 UTC · Jun 21, 2023Exploit / PoC in the wildCVE-2023-2088760
VMware Aria Operations for Networks vulnerability exploited in the wild (CVE-2023-20887)Help Net Security·Jun 21, 00:00 UTC · Jun 21, 2023Exploit / PoC in the wildCVE-2023-20887CVE-2023-20888CVE-2023-2088960
CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut BugThe Hacker News·Apr 24, 04:36 UTC · Apr 24, 2023Exploit / PoC in the wildCVE-2023-28432CVE-2023-27350CVE-2023-213660
CISA adds printer bug, Chrome zero-day and ChatGPT issue to exploited vulnerabilities catalogThe Record·Apr 23, 23:34 UTC · Apr 23, 2023Exploit / PoC in the wildCVE-2023-2136CVE-2023-2843260
Versa Networks strengthens marketing team with three new executivesHelp Net Security·Mar 30, 00:00 UTC · Mar 30, 2023Industry55
Fortinet FortiNAC CVE-2022-39952 flaw exploited in the wild hours after release of PoC exploitSecurity Affairs·Feb 23, 19:45 UTC · Feb 23, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-4275660