New Flaw in WordPress Plugin Used by Over a Million Sites Under Active ExploitationThe Hacker News·May 20, 04:02 UTC · May 20, 2023Exploit / PoC in the wildCVE-2023-3224360
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
9 vulnerabilities found in VPN software, including 1 critical issue that could lead to remote code executionCisco Talos·Oct 25, 16:00 UTC · Oct 25, 2023VulnerabilityCVE-2023-22325CVE-2023-23581CVE-2023-22308+16 CVEs60
GootLoader uses malformed ZIP files to bypass security controlsSecurity Affairs·Jan 18, 18:22 UTC · Jan 18, 2026Malware55
Chinese Hackers Exploit Zero-Day Flaws in Ivanti Connect Secure and Policy SecureThe Hacker News·Jan 11, 05:29 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760
Kaspersky Security Bulletin: Review of the Year 2017Kaspersky Securelist·Dec 5, 10:00 UTC · Dec 5, 2017Advisory55
Cryptomining attacks against Apple devices increase sharplyHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2018RansomwareCVE-2017-7269CVE-2017-5638CVE-2016-630960
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" PackageThe Hacker News·Jan 19, 07:42 UTC · Jan 19, 2024Malware55
VS Code extensions with 125M+ installs expose users to cyberattacksSecurity Affairs·Feb 18, 15:14 UTC · Feb 18, 2026VulnerabilityCVE-2025-65715CVE-2025-65716CVE-2025-65717160
AI-assisted Slopoly malware powers Hive0163’s ransomware campaignsSecurity Affairs·Mar 13, 11:36 UTC · Mar 13, 2026Ransomware60
Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency ServersThe Hacker News·Dec 9, 05:09 UTC · Dec 9, 2023Vulnerability in the wildCVE-2023-2636060
Microsoft Updates September 2014Kaspersky Securelist·Sep 11, 01:54 UTC · Sep 11, 2014Exploit / PoCCVE-2013-733160
Attackers exploit cPanel CVE-2026Security Affairs·May 12, 11:41 UTC · May 12, 2026Ransomware in the wildCVE-2026-41940160
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
node-ipc NPM Package sabotage to protest Ukraine invasionSecurity Affairs·Mar 18, 00:16 UTC · Mar 18, 2022VulnerabilityCVE-2022-2381260
Kaspersky researchers warns Linkedin from potential spear phishingKaspersky Securelist·Jul 23, 11:59 UTC · Jul 23, 2015Phishing & fraud55
Microsoft releases patch for .wmf vulnerabilityKaspersky Securelist·Jan 6, 13:27 UTC · Jan 6, 2006Vulnerability55
Firefox Blocks Inline and Eval JavaScript on Internal Pages to Prevent Injection AttacksThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2019Vulnerability55
New EtherRAT backdoor surfaces in React2Shell attacks tied to North KoreaSecurity Affairs·Dec 10, 14:45 UTC · Dec 10, 2025MalwareCVE-2025-5518260
SAP-Related npm Packages Compromised in CredentialThe Hacker News·Apr 30, 16:39 UTC · Apr 30, 2026Data breach60
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660
Take a walk on the client side: The importance of front-end JavaScript security assessmentsHelp Net Security·Mar 9, 20:14 UTC · Mar 9, 2023Data breach60
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware CampaignsThe Hacker News·Jul 3, 09:00 UTC · Jul 3, 2025Malware55
Banking Trojan attacks increase, large scale Ramnit campaign impacts organizations worldwideHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2018MalwareCVE-2017-7269CVE-2017-5638CVE-2014-0160+1 CVEs60
EtherRAT Distribution Spoofing Administrative Tools via GitHub FacadesThe Hacker News·Jun 7, 15:47 UTC · Jun 7, 2026Malware155
JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple StealersThe Hacker News·Dec 2, 05:40 UTC · Dec 2, 2025Malware55
10 Credential Stealing Python Libraries Found on PyPI RepositoryThe Hacker News·Aug 10, 05:22 UTC · Aug 10, 2022Malware55
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
IntelOwl: Open-source threat intelligence managementHelp Net Security·Aug 14, 00:00 UTC · Aug 14, 2024Ransomware60
Researchers disclose sandbox escape bug in vm2 sandbox librarySecurity Affairs·Apr 9, 20:34 UTC · Apr 9, 2023Exploit / PoCCVE-2023-29017CVE-2022-3606760
Microsoft Patch TuesdayCisco Talos·Dec 12, 23:32 UTC · Dec 12, 2017Vulnerability in the wildCVE-2017-11886CVE-2017-11888CVE-2017-11889+31 CVEs60
Lazarus Group deceives developers with 6 new malicious npm packagesCyberScoop·Mar 12, 22:31 UTC · Mar 12, 2025Threat actor in the wild160
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt StrikeThe Hacker News·May 26, 05:19 UTC · May 26, 2026Exploit / PoCCVE-2026-542660
U.S. Govt. Apps Bundled Russian Code With Ties to Mobile Malware DeveloperKrebs on Security·Nov 28, 22:54 UTC · Nov 28, 2022Malware55