Cisco Warns of Active Attacks Exploiting Unpatched 0The Hacker News·Dec 20, 12:11 UTC · Dec 20, 2025Vulnerability in the wildCVE-2025-2039360
Threat AdvisoryCisco Talos·Dec 19, 16:50 UTC · Dec 19, 2025Advisory in the wildCVE-2026-20182CVE-2025-20333CVE-2025-20362+6 CVEs160
China-linked APT UAT-9686 is targeting Cisco Secure Email Gateway and Secure Email and Web ManagerSecurity Affairs·Dec 19, 08:53 UTC · Dec 19, 2025Exploit / PoC in the wildCVE-2025-2039360
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active ExploitationThe Hacker News·Dec 9, 06:18 UTC · Dec 9, 2025Exploit / PoC in the wildCVE-2025-5518260
AWS: China-linked threat actors weaponized React2Shell hours after disclosureSecurity Affairs·Dec 8, 13:37 UTC · Dec 8, 2025Threat actor in the wildCVE-2025-55182CVE-2025-133860
Attackers deliver ShadowPad via newly patched WSUS RCE bugSecurity Affairs·Nov 24, 12:35 UTC · Nov 24, 2025Vulnerability in the wildCVE-2025-5928760
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
Amazon alerts: advanced threat actor exploits Cisco ISE & Citrix NetScaler zeroSecurity Affairs·Nov 13, 08:43 UTC · Nov 13, 2025Threat actor in the wildCVE-2025-5777CVE-2025-2033760
Microsoft releases urgent fix for actively exploited WSUS vulnerability (CVE-2025-59287)Help Net Security·Nov 3, 09:36 UTC · Nov 3, 2025Vulnerability in the wildCVE-2025-5928760
⚡ Weekly Recap: WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach WidensThe Hacker News·Oct 27, 14:16 UTC · Oct 27, 2025Ransomware in the wildCVE-2025-59287CVE-2025-54957CVE-2025-6950+21 CVEs60
Week in review: Actively exploited Windows SMB flaw, trusted OAuth apps turned into cloud backdoorsHelp Net Security·Oct 26, 00:00 UTC · Oct 26, 2025Malware in the wildCVE-2025-59287CVE-2025-61932CVE-2025-54236+2 CVEs60
CVE-2025-59287: Microsoft fixes critical WSUS flaw under active attackSecurity Affairs·Oct 25, 10:49 UTC · Oct 25, 2025Vulnerability in the wildCVE-2025-59287160
Leaked Oracle EBS exploit scripts expected to drive new wave of attacks (CVE-2025-61882)Help Net Security·Oct 9, 16:24 UTC · Oct 9, 2025Vulnerability in the wildCVE-2025-6188260
CISA warns of malware deployed through Ivanti EPMM flawsSecurity Affairs·Sep 20, 14:07 UTC · Sep 20, 2025Malware in the wildCVE-2025-4427CVE-2025-4428160
Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues WarningThe Hacker News·Sep 12, 12:08 UTC · Sep 12, 2025Vulnerability in the wildCVE-2025-508660
Microsoft Patch Tuesday for August 2025 — Snort rules and prominent vulnerabilitiesCisco Talos·Aug 12, 19:39 UTC · Aug 12, 2025Vulnerability in the wildCVE-2025-50176CVE-2025-50177CVE-2025-53778+10 CVEs60
ToolShell: a story of five vulnerabilities in Microsoft SharePointKaspersky Securelist·Jul 25, 07:00 UTC · Jul 25, 2025Vulnerability in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs160
U.S. CISA urges FCEB agencies to fix two Microsoft SharePoint flaws immediately and added them to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 23, 21:59 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-49704CVE-2025-49706CVE-2025-5377060
SharePoint under fire: new ToolShell attacks target enterprisesSecurity Affairs·Jul 22, 16:13 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-4970660
Citrix Bleed 2 Flaw Enables Token Theft; SAP GUI Flaws Risk Sensitive Data ExposureThe Hacker News·Jun 27, 10:45 UTC · Jun 27, 2025Ransomware in the wildCVE-2025-0055CVE-2025-0056CVE-2025-0059+2 CVEs60
Attackers target Zyxel RCE vulnerability CVE-2023Security Affairs·Jun 17, 10:34 UTC · Jun 17, 2025Vulnerability in the wildCVE-2023-2877160
Chinese Hackers Exploit Cityworks Flaw to Target US Local GovernmentsInfosecurity Magazine·May 26, 12:00 UTC · May 26, 2025Ransomware in the wildCVE-2025-0994160
Chinese threat actors exploited Trimble Cityworks Flaw to breach U.S. local government networksSecurity Affairs·May 23, 06:27 UTC · May 23, 2025Threat actor in the wildCVE-2025-0994CVE-2025-094460
Quantum computer threat spurring quiet overhaul of internet securityCyberScoop·May 1, 20:51 UTC · May 1, 2025Exploit / PoC in the wild60
JPCERT warns of DslogdRAT malware deployed in Ivanti Connect SecureSecurity Affairs·Apr 25, 17:56 UTC · Apr 25, 2025Malware in the wildCVE-2025-028260
Mass exploitation campaign hit 4,000+ ISP networks to deploy info stealers and crypto minersSecurity Affairs·Mar 4, 11:51 UTC · Mar 4, 2025Malware in the wild60
Palo Alto Networks warns that CVE-2025-0111 flaw is actively exploited in attacksSecurity Affairs·Feb 20, 06:32 UTC · Feb 20, 2025Vulnerability in the wildCVE-2025-0111CVE-2025-0108CVE-2024-947460
U.S. CISA adds SonicWall SonicOS and Palo Alto PAN-OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 19, 22:32 UTC · Feb 19, 2025Exploit / PoC in the wildCVE-2025-0108CVE-2024-5370460
Attackers exploit recently disclosed Palo Alto Networks PANSecurity Affairs·Feb 15, 15:27 UTC · Feb 15, 2025Exploit / PoC in the wildCVE-2025-010860
Security Affairs newsletter Round 506 by Pierluigi PaganiniSecurity Affairs·Jan 12, 18:03 UTC · Jan 12, 2025Data breach in the wildCVE-2024-43405CVE-2025-028260
Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect Secure and Policy SecureThe Hacker News·Jan 11, 06:31 UTC · Jan 11, 2025Vulnerability in the wildCVE-2025-0282CVE-2025-028360
Apache MINA CVE-2024-52046: CVSS 10.0 Flaw Enables RCE via Unsafe SerializationThe Hacker News·Dec 27, 06:46 UTC · Dec 27, 2024Vulnerability in the wildCVE-2024-52046CVE-2024-56337CVE-2024-45387+2 CVEs160
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and TipsThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2024Ransomware in the wildCVE-2024-50623CVE-2020-12271CVE-2024-11639+24 CVEs60
Leveraging Wazuh for Zero Trust securityThe Hacker News·Nov 5, 11:00 UTC · Nov 5, 2024Data breach in the wildCVE-2024-309460
U.S. CISA adds Cisco ASA and FTD, and RoundCube Webmail bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 25, 07:40 UTC · Oct 25, 2024Exploit / PoC in the wildCVE-2024-20481CVE-2024-3738360
THN Cybersecurity Recap: Top Threats, Tools and News (Oct 14The Hacker News·Oct 21, 12:11 UTC · Oct 21, 2024Data breach in the wildCVE-2024-38178CVE-2024-9486CVE-2024-44133+7 CVEs60
U.S. CISA adds Synacor Zimbra Collaboration flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 7, 05:24 UTC · Oct 7, 2024Exploit / PoC in the wildCVE-2024-4551960
Researchers Warn of Ongoing Attacks Exploiting Critical Zimbra Postjournal FlawThe Hacker News·Oct 4, 06:25 UTC · Oct 4, 2024Exploit / PoC in the wildCVE-2024-4551960
Critical Zimbra Postjournal flaw CVE-2024-45519 actively exploited in the wild. Patch it now!Security Affairs·Oct 2, 09:21 UTC · Oct 2, 2024Exploit / PoC in the wildCVE-2024-4551960