SonicWall warns of active exploitation of two SMA 1000 zeroSecurity Affairs·Jul 15, 08:03 UTC · Jul 15, 2026Exploit / PoC in the wildCVE-2026-15409CVE-2026-15410CVE-2025-2300660
AI Can Find Bugs, But Human Knowledge Still Proves ThemThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC57
Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)Help Net Security·Jun 26, 09:26 UTC · Jun 26, 2026Vulnerability in the wildCVE-2026-20230CVE-2026-2004560
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
Critical Cisco Unified CM Bug Patched as Public Exploit Code EmergesSecurity Affairs·Jun 4, 13:12 UTC · Jun 4, 2026VulnerabilityCVE-2026-2023060
Is the new OWASP API Top 10 helpful to defenders?Help Net Security·Apr 23, 13:36 UTC · Apr 23, 2026Phishing & fraud30
CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively ExploitedThe Hacker News·Mar 11, 07:17 UTC · Mar 11, 2026Vulnerability in the wildCVE-2021-22054CVE-2025-26399CVE-2026-160360
CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV UpdateThe Hacker News·Feb 24, 15:30 UTC · Feb 24, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2024-7694CVE-2020-7796+1 CVEs60
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV CatalogThe Hacker News·Feb 5, 03:59 UTC · Feb 5, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-40536CVE-2025-40537+7 CVEs60
ACME Flaw in Cloudflare allowed attackers to reach origin serversSecurity Affairs·Jan 21, 15:10 UTC · Jan 21, 2026Vulnerability30
Chainlit Security Flaws Highlight Infrastructure Risks in AI AppsInfosecurity Magazine·Jan 20, 16:30 UTC · Jan 20, 2026VulnerabilityCVE-2026-22218CVE-2026-2221935
October 2025 CVE LandscapeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Ransomware in the wildCVE-2025-59287CVE-2025-61882CVE-2025-41244+29 CVEs60
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3The Hacker News·Aug 25, 17:53 UTC · Aug 25, 2025VulnerabilityCVE-2025-9074160
Zoom and Xerox Release Critical Security Updates Fixing Privilege Escalation and RCE FlawsThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025VulnerabilityCVE-2025-49457CVE-2025-8355CVE-2025-835660
WWBN, MedDream, Eclipse vulnerabilitiesCisco Talos·Aug 6, 12:00 UTC · Aug 6, 2025VulnerabilityCVE-2025-46410CVE-2025-53084CVE-2025-50128+8 CVEs35
U.S. CISA adds MRLG, PHPMailer, Rails Ruby on Rails, and Synacor Zimbra Collaboration Suite flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 8, 14:13 UTC · Jul 8, 2025Exploit / PoC in the wildCVE-2014-3931CVE-2016-10033CVE-2019-5418+1 CVEs60
How Breaches Start: Breaking Down 5 Real VulnsThe Hacker News·Apr 28, 11:00 UTC · Apr 28, 2025VulnerabilityCVE-2021-2220460
Microsoft SharePoint Connector Flaw Could've Enabled Credential Theft Across Power PlatformThe Hacker News·Feb 6, 04:41 UTC · Feb 6, 2025Vulnerability130
File Transfer Threats: Risk Factors and How Network Traffic Visibility Can HelpPalo Alto Unit 42·Jun 6, 12:43 UTC · Jun 6, 2024VulnerabilityCVE-2021-24144CVE-2021-24142CVE-2021-25277+7 CVEs60
Network Attack Trends: FebruaryPalo Alto Unit 42·Jun 6, 12:33 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-25296CVE-2021-25297CVE-2021-25298+4 CVEs60
Finding Azurescape – Cross-Account Container Takeover in Azure Container InstancesPalo Alto Unit 42·Jun 6, 01:32 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2019-5736CVE-2018-1002102160
A Look Into Public Clouds From the Ransomware Actor's PerspectivePalo Alto Unit 42·Jun 5, 22:33 UTC · Jun 5, 2024Ransomware60
Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)Palo Alto Unit 42·Jun 5, 17:51 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-41040CVE-2022-41082CVE-2021-34473+2 CVEs60
Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete TakeoverThe Hacker News·May 4, 08:19 UTC · May 4, 2024VulnerabilityCVE-2024-28185CVE-2024-28189CVE-2024-2902160
Attackers injected novel DSLog backdoor into 670 vulnerable Ivanti devices (CVE-2024-21893)Help Net Security·Feb 15, 11:46 UTC · Feb 15, 2024VulnerabilityCVE-2024-21893CVE-2024-21888CVE-2023-46805+1 CVEs60
Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT InfrastructuresThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability in the wildCVE-2024-21893CVE-2024-2188860
Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA GatewaysThe Hacker News·Feb 10, 06:48 UTC · Feb 10, 2024Vulnerability in the wildCVE-2024-22024CVE-2023-46805CVE-2024-21887+2 CVEs60
CVE-2023-23560 flaw exposes 100 Lexmark printer models to hackSecurity Affairs·Jan 27, 08:29 UTC · Jan 27, 2023VulnerabilityCVE-2023-2356047
OWASP Top 10 ranking has a new leader after ten yearsThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Vulnerability55
Multiple Vulnerabilities Reported in Checkmk IT Infrastructure Monitoring SoftwareThe Hacker News·Nov 2, 13:11 UTC · Nov 2, 2022Vulnerability55
Microsoft Confirms 2 New Exchange ZeroThe Hacker News·Oct 1, 05:48 UTC · Oct 1, 2022Exploit / PoC in the wildCVE-2022-41040CVE-2022-4108260
PrinterLogic fixes high severity flaws in Printer Management SuiteSecurity Affairs·Jan 26, 07:46 UTC · Jan 26, 2022VulnerabilityCVE-2021-42631CVE-2021-42635CVE-2021-42638+6 CVEs47
Apache fixed a couple of severe vulnerabilities in Apache HTTP ServerSecurity Affairs·Dec 27, 18:26 UTC · Dec 27, 2021VulnerabilityCVE-2021-44790CVE-2021-44224CVE-2021-4043847
Three trivial bugs in Microsoft Teams Software remain unpatchedSecurity Affairs·Dec 23, 12:04 UTC · Dec 23, 2021Vulnerability130
New Nagios Software Bugs Could Let Hackers Take Over IT InfrastructuresThe Hacker News·Sep 27, 04:39 UTC · Sep 27, 2021Exploit / PoCCVE-2021-37344CVE-2021-37346CVE-2021-37350+8 CVEs160
Flaws in Nagios Network Management systems pose risk to companiesSecurity Affairs·Sep 22, 15:08 UTC · Sep 22, 2021Exploit / PoCCVE-2021-37353CVE-2021-37352CVE-2021-37351+8 CVEs60
New Bug Could Let Attackers Hijack Zimbra Server by Sending Malicious EmailThe Hacker News·Jul 27, 15:46 UTC · Jul 27, 2021VulnerabilityCVE-2021-35208CVE-2021-3520935