Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)Help Net Security·Sep 23, 00:00 UTC · Sep 23, 2022Vulnerability in the wildCVE-2022-3540560
Patch critical flaw in Atlassian Bitbucket Server and Data Center! (CVE-2022-36804)Help Net Security·Sep 21, 09:09 UTC · Sep 21, 2022VulnerabilityCVE-2022-3680460
Chinese hackers zero in on Australian manufacturers, wind turbine operatorsCyberScoop·Aug 30, 11:32 UTC · Aug 30, 2022Exploit / PoC in the wild60
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
Researchers uncover potential ransomware network with U.S. connectionsCyberScoop·Jul 21, 22:15 UTC · Jul 21, 2022Ransomware in the wild60
CISA and NPower offer free entry-level cybersecurity trainingHelp Net Security·Jul 6, 00:00 UTC · Jul 6, 2022Exploit / PoC60
CISA adds Zyxel Firewalls flaw to Known Exploited Vulnerabilities CatalogSecurity Affairs·May 17, 07:11 UTC · May 17, 2022Exploit / PoC in the wildCVE-2022-30525CVE-2022-2294760
Zyxel fixed firewall unauthenticated remote command injection issueSecurity Affairs·May 17, 06:47 UTC · May 17, 2022Exploit / PoCCVE-2022-30525CVE-2022-26413CVE-2022-26414+1 CVEs60
Week in review: F5 BIG-IP RCE exploitation, URL spoofing flaws in Zoom, Google DocsHelp Net Security·May 15, 00:00 UTC · May 15, 2022Vulnerability in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs60
Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-dayHelp Net Security·Apr 17, 00:00 UTC · Apr 17, 2022Exploit / PoC in the wildCVE-2022-24521CVE-2022-26904CVE-2022-26809+1 CVEs60
April Records First Patch Tuesday of 2022 to Top 100 CVEsInfosecurity Magazine·Apr 13, 09:00 UTC · Apr 13, 2022Vulnerability in the wildCVE-2022-24521CVE-2022-26904CVE-2022-24491+1 CVEs160
Tens of thousands unpatched GitLab servers under attack via CVE-2021-22205Help Net Security·Nov 4, 00:00 UTC · Nov 4, 2021Vulnerability in the wildCVE-2021-2220560
Organizations can no longer afford to overlook encrypted trafficHelp Net Security·Apr 27, 00:00 UTC · Apr 27, 2021Ransomware60
Threat Source Newsletter (April 22, 2021)Cisco Talos·Apr 22, 18:00 UTC · Apr 22, 2021Ransomware in the wild60
Cybersecurity Firm FireEye Got Hacked; RedThe Hacker News·Dec 10, 16:36 UTC · Dec 10, 2020Ransomware in the wild60
FireEye breach: State-sponsored attackers stole hacking toolsHelp Net Security·Dec 9, 00:00 UTC · Dec 9, 2020Threat actor60
Foreign spies use front companies to disguise their hacking, borrowing an old camouflage tacticCyberScoop·Oct 5, 17:48 UTC · Oct 5, 2020Data breach in the wild60
Thinking of a Cybersecurity Career? Read ThisKrebs on Security·Jul 29, 17:36 UTC · Jul 29, 2020Exploit / PoC60
Cyber Command backs 'urgent' patch for F5 security vulnerabilityCyberScoop·Jul 6, 17:12 UTC · Jul 6, 2020Vulnerability in the wildCVE-2020-590260
How COVID-19 changed Cyber Command's 'Cyber Flag' exerciseCyberScoop·Jun 25, 21:51 UTC · Jun 25, 2020Exploit / PoC in the wild60
Magnitude exploit kitKaspersky Securelist·Jun 24, 10:00 UTC · Jun 24, 2020Ransomware in the wildCVE-2018-8174CVE-2018-8653CVE-2019-1367+3 CVEs60
Researcher Discloses 4 Zero-Day Bugs in IBM's Enterprise Security SoftwareThe Hacker News·Jun 10, 14:41 UTC · Jun 10, 2020Exploit / PoC60
Offensive Security releases major update to its Penetration Testing with Kali Linux training courseHelp Net Security·Mar 2, 10:33 UTC · Mar 2, 2020Exploit / PoC60
Trickbot gang and Lazarus APT, hidden link behind an epochal phenomenaSecurity Affairs·Dec 12, 11:56 UTC · Dec 12, 2019Threat actor60
First Cyber Attack 'Mass Exploiting' BlueKeep RDP Flaw Spotted in the WildThe Hacker News·Nov 3, 11:34 UTC · Nov 3, 2019RansomwareCVE-2019-070860
Week in review: Insider threat essentials, tracing IP hijackers, cryptojacking worm hits Docker hostsHelp Net Security·Oct 20, 00:00 UTC · Oct 20, 2019Data breachCVE-2019-221560
Cisco warns about public exploit code for critical flaws in its 220 Series smart switchesHelp Net Security·Sep 3, 07:36 UTC · Sep 3, 2019Exploit / PoC in the wildCVE-2019-1938CVE-2019-1935CVE-2019-1974+4 CVEs60
Financial hacking teams FIN7, Cobalt Group update tactics to haunt banks and retailCyberScoop·Aug 14, 15:18 UTC · Aug 14, 2019Exploit / PoC in the wild60
StrongPity APT - Waterhole attacks against Italian and Belgian usersSecurity Affairs·Jul 18, 13:42 UTC · Jul 18, 2019Exploit / PoCCVE-2011-061160
If you haven't yet patched the BlueKeep RDP vulnerability, do so nowHelp Net Security·Jun 7, 11:33 UTC · Jun 7, 2019VulnerabilityCVE-2019-070860
Recent Watering Hole Attacks Attributed to APT Group “th3bug” Using Poison IvyPalo Alto Unit 42·Nov 1, 09:36 UTC · Nov 1, 2018Threat actor60
Russian Government-owned research institute linked to Triton attacksSecurity Affairs·Oct 24, 05:23 UTC · Oct 24, 2018Exploit / PoC60
Critical Samba code execution hole plugged, patch ASAP!Help Net Security·Oct 15, 09:22 UTC · Oct 15, 2018VulnerabilityCVE-2017-749460
Asia's hackers are finding a home on the dark webCyberScoop·Aug 8, 16:45 UTC · Aug 8, 2018Exploit / PoC in the wild60
APT Trends Report Q2 2018Kaspersky Securelist·Jul 10, 10:00 UTC · Jul 10, 2018Exploit / PoCCVE-2018-4878CVE-2018-8174CVE-2016-4171+1 CVEs60
HP iLO servers running outdated firmware could be remotely hackedSecurity Affairs·Jul 9, 11:10 UTC · Jul 9, 2018Exploit / PoCCVE-2017-1254260
Analysis of the evolution of exploit kits in the threat landscapeSecurity Affairs·Jun 14, 07:06 UTC · Jun 14, 2018RansomwareCVE-2018-8174CVE-2016-0189CVE-2018-4878+1 CVEs60
Crooks included the code for CVE-2018-8174 IE ZeroSecurity Affairs·Jun 3, 07:32 UTC · Jun 3, 2018Vulnerability in the wildCVE-2018-8174CVE-2016-018960