Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent PatchThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025VulnerabilityCVE-2025-66516CVE-2025-5498860
TruffleHog, Fade In and BSAFE CryptoCisco Talos·Nov 4, 14:26 UTC · Nov 4, 2025VulnerabilityCVE-2025-53855CVE-2025-53814CVE-2025-41390+1 CVEs35
Efimer Trojan delivered via email and hacked WordPress websitesKaspersky Securelist·Aug 8, 09:00 UTC · Aug 8, 2025Malware30
U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 24, 06:48 UTC · Jul 24, 2025Exploit / PoC in the wildCVE-2025-54309CVE-2025-6558CVE-2025-2776+2 CVEs60
SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in OnThe Hacker News·Jul 23, 09:22 UTC · Jul 23, 2025VulnerabilityCVE-2025-2775CVE-2025-2776CVE-2025-2777+3 CVEs60
CISA Warns: SysAid Flaws Under Active Attack Enable Remote File Access and SSRFThe Hacker News·Jul 23, 06:24 UTC · Jul 23, 2025Advisory in the wildCVE-2025-2775CVE-2025-2776CVE-2025-2777+1 CVEs60
SVG files with embedded HTML code used in phishingKaspersky Securelist·Apr 21, 08:00 UTC · Apr 21, 2025Phishing & fraud30
New Windows Task Scheduler Bugs Let Attackers Bypass UAC and Tamper with LogsThe Hacker News·Apr 17, 01:48 UTC · Apr 17, 2025VulnerabilityCVE-2023-2172635
GOFFEE’s recent attacks: new tools and techniquesKaspersky Securelist·Apr 10, 10:00 UTC · Apr 10, 2025Vulnerability130
GitHub Uncovers New ruby-saml Vulnerabilities Allowing Account Takeover AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025VulnerabilityCVE-2025-25291CVE-2025-25292CVE-2025-25293+1 CVEs60
Progress Software fixed multiple highSecurity Affairs·Feb 11, 15:40 UTC · Feb 11, 2025Exploit / PoC in the wildCVE-2024-56131CVE-2024-56132CVE-2024-56133+3 CVEs60
U.S. CISA adds Adobe Commerce and Magento, SolarWinds Serv-U, and VMware vCenter Server bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 21, 08:29 UTC · Jul 21, 2024Exploit / PoC in the wildCVE-2024-34102CVE-2024-28995CVE-2022-2294860
A patched Windows attack surface is still exploitableKaspersky Securelist·Mar 14, 10:00 UTC · Mar 14, 2024Vulnerability in the wildCVE-2022-22047CVE-2022-37989CVE-2022-29104+3 CVEs60
Attacks on web applications spike in third quarter, new Talos IR data showsCisco Talos·Oct 24, 12:00 UTC · Oct 24, 2023Ransomware60
Four vulnerabilities found in Dell SonicWALL Email Security virtual appliance applicationHelp Net Security·May 24, 08:31 UTC · May 24, 2023Vulnerability30
API Vulnerabilities Discovered in LEGO MarketplaceInfosecurity Magazine·Dec 19, 09:30 UTC · Dec 19, 2022Vulnerability30
Messages Sent Through Zoom Can Expose People to CyberInfosecurity Magazine·May 25, 13:47 UTC · May 25, 2022VulnerabilityCVE-2022-22784CVE-2022-22787CVE-2022-22785+1 CVEs60
Magnat campaigns use malvertising to deliver information stealer, backdoor and malicious Chrome extensionCisco Talos·Dec 2, 12:48 UTC · Dec 2, 2021Malware42
Malicious Campaign Targets Latin America: The seller, The operator and a curious linkCisco Talos·Aug 19, 11:58 UTC · Aug 19, 2021Threat actor57
Friday Squid Blogging: Squid Found on Provincetown SandbarSchneier on Security·Jul 17, 16:13 UTC · Jul 17, 2020Industry42
Vulnerability Spotlight: Two code execution vulnerabilities in Microsoft ExcelCisco Talos·Jun 10, 20:21 UTC · Jun 10, 2020Vulnerability in the wildCVE-2020-1226CVE-2020-1225160
Factors driving API growth in industryHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2020Vulnerability42
Juniper releases barrage of security fixes for security, networking devicesHelp Net Security·May 28, 11:18 UTC · May 28, 2020Exploit / PoC in the wildCVE-2019-0006CVE-2019-0007CVE-2015-1283+4 CVEs60
Three flaws in Nitro Pro PDF reader expose businesses to hackSecurity Affairs·May 20, 09:03 UTC · May 20, 2020VulnerabilityCVE-2020-6074CVE-2020-6092CVE-2020-609360
NSA’s reverse engineering tool Ghidra impacted by a bug — but there's no need to panicCyberScoop·Oct 1, 21:13 UTC · Oct 1, 2019Exploit / PoC in the wildCVE-2019-1694160
Experts dissect NanoCore Crimeware Attack ChainSecurity Affairs·Jun 14, 12:22 UTC · Jun 14, 2019Malware30
Researcher Hijacks a Microsoft Service Using Loophole in Azure Cloud PlatformThe Hacker News·Apr 17, 20:16 UTC · Apr 17, 2019Vulnerability30
SAP April 2019 Security Patch Day addresses High severity flaws in Crystal Reports, NetWeaverSecurity Affairs·Apr 11, 05:28 UTC · Apr 11, 2019VulnerabilityCVE-2019-0285CVE-2019-0283CVE-2019-0265+5 CVEs60
Vulnerability Deep Dive: TP-Link TL-R600VPN remote code execution vulnerabilitiesCisco Talos·Jan 15, 20:02 UTC · Jan 15, 2019Vulnerability42
New Emotet Thanksgiving campaign differs from previous onesSecurity Affairs·Nov 23, 13:52 UTC · Nov 23, 2018Threat actor45
High risk vulnerability discovered in Sauter CASE Suite building automation softwareHelp Net Security·Nov 6, 00:00 UTC · Nov 6, 2018Vulnerability30
Unpatched MS Word Flaw Could Allow Hackers to Infect Your ComputerThe Hacker News·Oct 31, 08:50 UTC · Oct 31, 2018Vulnerability30
CVE-2018-7783 flaw in Schneider SoMachine Basic can be exploited to read arbitrary files on the targeted systemSecurity Affairs·May 26, 06:42 UTC · May 26, 2018VulnerabilityCVE-2018-778360
Windows Remote Assistance flaw could be exploited to steal sensitive filesSecurity Affairs·Mar 21, 07:26 UTC · Mar 21, 2018Exploit / PoCCVE-2018-087860
For the second time CISCO issues security patch to fix a critical vulnerability in CISCO ASASecurity Affairs·Feb 8, 00:26 UTC · Feb 8, 2018VulnerabilityCVE-2018-010160
Critical Flaw in Major Android Tools Targets Developers and Reverse EngineersThe Hacker News·Dec 6, 11:54 UTC · Dec 6, 2017Exploit / PoC60
Vulnerabilities in ProcessMaker, WebFOCUS, and OpenFire Identified and PatchedCisco Talos·Jul 19, 16:13 UTC · Jul 19, 2017VulnerabilityCVE-2016-9048CVE-2016-9045CVE-2016-9044+1 CVEs47