Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedSecurity Affairs·Jul 24, 12:10 UTC · Jul 24, 2026VulnerabilityCVE-2021-4034CVE-2021-3156CVE-2017-726935
GuardFall Flaw Hits 10 of 11 Popular OpenSecurity Affairs·Jul 1, 08:31 UTC · Jul 1, 2026Vulnerability42
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached BinariesThe Hacker News·Jun 26, 13:57 UTC · Jun 26, 2026Exploit / PoCCVE-2026-4633150
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Miasma Supply Chain Attack Compromises Red Hat npm Packages with CredentialThe Hacker News·Jun 2, 08:55 UTC · Jun 2, 2026Vulnerability42
A SpaceX Security Engineer Used AI to Find a 19-YearSecurity Affairs·Jun 1, 09:55 UTC · Jun 1, 2026Exploit / PoC45
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware SitesThe Hacker News·May 27, 07:45 UTC · May 27, 2026MalwareCVE-2025-3307347
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)Help Net Security·May 18, 13:54 UTC · May 18, 2026Vulnerability in the wildCVE-2026-46300CVE-2026-4328460
Rocky Linux launches opt-in security repository for urgent fixesHelp Net Security·May 15, 00:00 UTC · May 15, 2026Exploit / PoC45
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-31431CVE-2022-27666CVE-2026-43284+1 CVEs60
UAT-4356's Targeting of Cisco Firepower DevicesCisco Talos·Apr 23, 15:10 UTC · Apr 23, 2026VulnerabilityCVE-2025-20333CVE-2025-2036247
Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limitsHelp Net Security·Apr 19, 00:00 UTC · Apr 19, 2026Data breach in the wildCVE-2026-34621CVE-2026-39813CVE-2026-3980860
NginRAT parasite targets NginxSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Malware42
Hackers exploit security flaw right before Black FridaySansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Data breach57
XM Cyber advances AI security with enhanced exposure and attack path visibilityHelp Net Security·Mar 25, 09:46 UTC · Mar 25, 2026Vulnerability55
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container IsolationThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Exploit / PoC60
New StackWarp Hardware Flaw Breaks AMD SEV-SNP Protections on Zen 1The Hacker News·Jan 19, 11:31 UTC · Jan 19, 2026VulnerabilityCVE-2025-29943CVE-2023-2059247
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Security Affairs newsletter Round 544 by Pierluigi Paganini – INTERNATIONAL EDITIONSecurity Affairs·Oct 5, 11:35 UTC · Oct 5, 2025Ransomware in the wildCVE-2025-4124460
CISA orders federal gov to patch critical Fortra file transfer bugThe Record·Sep 30, 17:33 UTC · Sep 30, 2025Vulnerability in the wildCVE-2025-10035CVE-2023-066960
Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 SecondsThe Hacker News·Sep 17, 04:13 UTC · Sep 17, 2025VulnerabilityCVE-2025-620235
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI CredentialsThe Hacker News·Sep 6, 11:31 UTC · Sep 6, 2025Malware55
Salt Typhoon Exploits Flaws in Edge Network Devices to Breach 600 Organizations WorldwideThe Hacker News·Sep 5, 12:40 UTC · Sep 5, 2025Threat actorCVE-2018-0171CVE-2023-20198CVE-2023-20273+3 CVEs60
Over 300 entities hit by a variant of Atomic macOS Stealer in recent campaignSecurity Affairs·Aug 23, 07:07 UTC · Aug 23, 2025Malware30
Toptal GitHub Breach Exposes 73 Repositories and Injects Malware into 10 npm PackagesThe Hacker News·Aug 6, 10:50 UTC · Aug 6, 2025Malware42
New Linux backdoor Plague bypasses auth via malicious PAM moduleSecurity Affairs·Aug 2, 23:22 UTC · Aug 2, 2025Malware42
Supply-chain attacks on open source software are getting out of handArs Technica · Security·Jul 25, 15:50 UTC · Jul 25, 2025Malware42
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
Security Affairs newsletter Round 531 by Pierluigi PaganiniSecurity Affairs·Jul 6, 04:54 UTC · Jul 6, 2025Ransomware in the wildCVE-2025-6543CVE-2025-655460
Shell No! (Part 2) Introducing Cknife, China Chopper’s SiblingRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Vulnerability landscape analysis for Q1 2025Kaspersky Securelist·May 30, 12:00 UTC · May 30, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Talos IR trends Q4 2024: Web shell usage and exploitation of publicCisco Talos·Jan 30, 11:00 UTC · Jan 30, 2025Ransomware57
Chinese threat actors used two advanced exploit chains to hack Ivanti CSASecurity Affairs·Jan 23, 14:23 UTC · Jan 23, 2025Threat actorCVE-2024-8963CVE-2024-9379CVE-2024-8190+1 CVEs60
Thai Officials Targeted in Yokai Backdoor Campaign Using DLL SideThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2024MalwareCVE-2017-11882160
Analyzing the vulnerability landscape in Q3 2024Kaspersky Securelist·Dec 6, 10:15 UTC · Dec 6, 2024VulnerabilityCVE-2023-38831CVE-2023-23397CVE-2023-36874+12 CVEs60
Pro-Ukrainian Hackers Strike Russian State TV on Putin's BirthdayThe Hacker News·Oct 8, 11:06 UTC · Oct 8, 2024Vulnerability55
Russian state media company operation disrupted by ‘unprecedented’ cyberattackThe Record·Oct 7, 14:46 UTC · Oct 7, 2024Data breach60
Printer bug sends researchers into uproar, affects major Linux distrosCyberScoop·Sep 27, 11:41 UTC · Sep 27, 2024Exploit / PoCCVE-2024-47176CVE-2024-47076CVE-2024-47175+1 CVEs60
Security Affairs newsletter Round 490 by Pierluigi PaganiniSecurity Affairs·Sep 22, 13:37 UTC · Sep 22, 2024Ransomware60
Critical RCE flaws in vCenter Server fixed (CVE-2024-37079, CVE-2024-37080)Help Net Security·Aug 28, 15:26 UTC · Aug 28, 2024VulnerabilityCVE-2024-37079CVE-2024-37080CVE-2024-3708160