Vendors defeat Magento security patch (+ simple check)Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2022-24086CVE-2022-24087CVE-2026-7565060
Magento wish list exploit bypasses WAF protectionSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026VulnerabilityCVE-2022-2408660
Anthropic Project Glasswing to Use AI to Fix Software Bugs With AIInfosecurity Magazine·Apr 8, 11:30 UTC · Apr 8, 2026Exploit / PoC60
China-Linked TA416 Targets European Governments with PlugX and OAuthThe Hacker News·Apr 3, 17:34 UTC · Apr 3, 2026VulnerabilityCVE-2025-31324CVE-2025-099460
Mass PolyShell attack wave hits 471 stores in one hourSansec (Magento / e-commerce security)·Mar 31, 07:45 UTC · Mar 31, 2026Vulnerability in the wildCVE-2026-7565060
Claude Code Security and Magecart: Getting the Threat Model RightThe Hacker News·Mar 18, 11:58 UTC · Mar 18, 2026Data breach60
It’s time to get serious about postCyberScoop·Mar 17, 10:00 UTC · Mar 17, 2026Data breach in the wild60
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-26127160
How to Protect Your SaaS from Bot Attacks with SafeLine WAFThe Hacker News·Mar 9, 14:16 UTC · Mar 9, 2026Vulnerability55
Coruna: Spy-grade iOS exploit kit powering financial crimeHelp Net Security·Mar 6, 10:01 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2024-23222CVE-2022-48503CVE-2023-43000+5 CVEs60
China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom AttacksThe Hacker News·Mar 6, 08:22 UTC · Mar 6, 2026Malware55
Google uncovers Coruna iOS Exploit Kit targeting iOS 13Security Affairs·Mar 5, 09:03 UTC · Mar 5, 2026Exploit / PoCCVE-2021-30952CVE-2022-48503CVE-2023-43000+9 CVEs60
Keenadu the tablet conqueror and the links between major Android botnetsKaspersky Securelist·Feb 17, 09:00 UTC · Feb 17, 2026Malware55
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 ScoreThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2026-24423CVE-2026-23760CVE-2026-2506760
Why a decade-old EnCase driver still works as an EDR killerHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2026Ransomware60
GootLoader uses malformed ZIP files to bypass security controlsSecurity Affairs·Jan 18, 18:22 UTC · Jan 18, 2026Malware55
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bugSecurity Affairs·Jan 16, 10:17 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-2039360
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade DetectionThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Malware55
UAT-7290 targets high value telecommunications infrastructure in South AsiaCisco Talos·Jan 8, 11:00 UTC · Jan 8, 2026Exploit / PoC60
Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full ControlThe Hacker News·Jan 8, 09:26 UTC · Jan 8, 2026VulnerabilityCVE-2026-21858CVE-2025-68613CVE-2025-68668+1 CVEs60
React2Shell under attack: RondoDox Botnet spreads miners and malwareSecurity Affairs·Jan 1, 14:31 UTC · Jan 1, 2026MalwareCVE-2025-55182CVE-2024-3721CVE-2024-1285660
Cisco Warns of Active Attacks Exploiting Unpatched 0The Hacker News·Dec 20, 12:11 UTC · Dec 20, 2025Vulnerability in the wildCVE-2025-2039360
Threat AdvisoryCisco Talos·Dec 19, 16:50 UTC · Dec 19, 2025Advisory in the wildCVE-2026-20182CVE-2025-20333CVE-2025-20362+6 CVEs160
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web ManagerSecurity Affairs·Dec 19, 08:53 UTC · Dec 19, 2025Exploit / PoC in the wildCVE-2025-2039360
A vehicle's head unit hacked via its modemKaspersky Securelist·Dec 16, 10:00 UTC · Dec 16, 2025VulnerabilityCVE-2024-39432CVE-2024-3943160
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Upwind adds real-time AI security and posture management to its CNAPPHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2025Vulnerability55
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential TheftThe Hacker News·Nov 25, 03:51 UTC · Nov 25, 2025Vulnerability55
Attackers deliver ShadowPad via newly patched WSUS RCE bugSecurity Affairs·Nov 24, 12:35 UTC · Nov 24, 2025Vulnerability in the wildCVE-2025-5928760
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
Amazon alerts: advanced threat actor exploits Cisco ISE & Citrix NetScaler zeroSecurity Affairs·Nov 13, 08:43 UTC · Nov 13, 2025Threat actor in the wildCVE-2025-5777CVE-2025-2033760
Ransomware Defense Using the Wazuh Open Source PlatformThe Hacker News·Nov 4, 11:06 UTC · Nov 4, 2025Ransomware60
Microsoft releases urgent fix for actively exploited WSUS vulnerability (CVE-2025-59287)Help Net Security·Nov 3, 09:36 UTC · Nov 3, 2025Vulnerability in the wildCVE-2025-5928760
Chinese-Linked Hackers Exploit Windows Flaw to Spy on EU DiplomatsInfosecurity Magazine·Oct 31, 12:10 UTC · Oct 31, 2025Vulnerability55
Dynamic binary instrumentation (DBI) with DynamoRioCisco Talos·Oct 30, 09:59 UTC · Oct 30, 2025Vulnerability55
⚡ Weekly Recap: WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach WidensThe Hacker News·Oct 27, 14:16 UTC · Oct 27, 2025Ransomware in the wildCVE-2025-59287CVE-2025-54957CVE-2025-6950+21 CVEs60
Wordfence blocks 8.7M attacks exploiting old GutenKit and Hunk Companion flawsSecurity Affairs·Oct 27, 08:40 UTC · Oct 27, 2025VulnerabilityCVE-2024-9234CVE-2024-9707CVE-2024-1197260