UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial FirmsSecurity Affairs·Jun 8, 10:46 UTC · Jun 8, 2026Phishing & fraud55
Silent Ransom Group (SRG): Switching To DNS Fast Flux InfrastructureSecurity Affairs·Jun 6, 21:52 UTC · Jun 6, 2026Ransomware45
Sansec adds support for Sylius 1 & 2Sansec (Magento / e-commerce security)·Jun 1, 13:10 UTC · Jun 1, 2026Policy & legalCVE-2026-31822CVE-2024-34349CVE-2024-2937660
ThreatsDay Bulletin: Cisco 0-Days, AI Bug Bounties, Crypto Heists, StateThe Hacker News·May 27, 15:52 UTC · May 27, 2026Data breach60
U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 22, 09:13 UTC · May 22, 2026Exploit / PoC in the wildCVE-2025-34291CVE-2026-3492660
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEVThe Hacker News·May 22, 08:30 UTC · May 22, 2026Exploit / PoC in the wildCVE-2025-34291CVE-2026-3492660
Lyrie: Open-source autonomous pentesting agentHelp Net Security·May 18, 00:00 UTC · May 18, 2026Exploit / PoC45
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing HistoryThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Malware30
Brutus: Open-source credential testing tool for offensive securityHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2026Malware42
Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious InvitesThe Hacker News·Jan 20, 07:00 UTC · Jan 20, 2026AI safety & securityCVE-2026-0612CVE-2026-0613CVE-2026-0615+2 CVEs35
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Strix: Open-source AI agents for penetration testingHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2025Exploit / PoC45
⚡ Weekly Recap: VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & MoreThe Hacker News·Aug 5, 04:38 UTC · Aug 5, 2025Malware in the wildCVE-2025-40596CVE-2025-40597CVE-2025-40598+8 CVEs60
CISA Warns of Exploited Vulnerabilities in Cisco ProductsInfosecurity Magazine·Jul 29, 13:15 UTC · Jul 29, 2025Vulnerability in the wildCVE-2025-20281CVE-2025-20337CVE-2023-253360
Secure Vibe Coding: The Complete New GuideThe Hacker News·Jun 19, 11:25 UTC · Jun 19, 2025Vulnerability55
RCE Vulnerability Found in RomethemeKit For Elementor PluginInfosecurity Magazine·May 19, 16:00 UTC · May 19, 2025VulnerabilityCVE-2025-3091160
⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain BackdoorsThe Hacker News·May 6, 05:03 UTC · May 6, 2025MalwareCVE-2025-3928CVE-2025-1976CVE-2025-46271+33 CVEs60
U.S. CISA adds Sitecore CMS and XP, and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 27, 12:31 UTC · Mar 27, 2025Exploit / PoC in the wildCVE-2019-9875CVE-2019-9874CVE-2025-3015460
89% of AI-powered APIs rely on insecure authentication mechanismsHelp Net Security·Jan 30, 00:00 UTC · Jan 30, 2025Exploit / PoC60
Cybersecurity jobs available right now: October 23, 2024Help Net Security·Dec 16, 08:58 UTC · Dec 16, 2024Exploit / PoC60
THN Recap: Top Cybersecurity Threats, Tools, and Practices (Nov 18The Hacker News·Nov 25, 11:31 UTC · Nov 25, 2024RansomwareCVE-2024-0012CVE-2024-9474CVE-2024-44308+15 CVEs60
CWE top 25 most dangerous software weaknessesHelp Net Security·Nov 21, 00:00 UTC · Nov 21, 2024Vulnerability55
Critical Jenkins RCE flaw exploited in the wild. Patch now! (CVE-2024-23897)Help Net Security·Aug 14, 08:33 UTC · Aug 14, 2024Exploit / PoC in the wildCVE-2024-23897CVE-2024-2389860
"0.0.0.0-Day" vulnerability affects Chrome, Safari and FirefoxHelp Net Security·Aug 9, 00:00 UTC · Aug 9, 2024Vulnerability42
How MFA Failures are Fueling a 500% Surge in Ransomware LossesThe Hacker News·Jul 3, 16:20 UTC · Jul 3, 2024Ransomware57
GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 OthersThe Hacker News·Jun 28, 14:18 UTC · Jun 28, 2024Vulnerability in the wildCVE-2024-5655CVE-2024-4901CVE-2024-4994+2 CVEs60
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, CrossPalo Alto Unit 42·Jun 5, 20:05 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-22954CVE-2022-22963CVE-2022-22965+20 CVEs60
An XSS flaw in GitLab allows attackers to take over accountsSecurity Affairs·May 24, 20:39 UTC · May 24, 2024Vulnerability in the wildCVE-2024-4835CVE-2023-7028160
CISA Warns of Actively Exploited D-Link Router VulnerabilitiesThe Hacker News·May 17, 11:23 UTC · May 17, 2024Vulnerability in the wildCVE-2014-100005CVE-2021-40655CVE-2024-22026+2 CVEs60
CISA adds D-Link DIR router flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 17, 10:20 UTC · May 17, 2024Exploit / PoC in the wildCVE-2014-100005CVE-2021-4065560
CISA Alerts on Active Exploitation of Flaws in Fortinet, Ivanti, and Nice ProductsThe Hacker News·Mar 28, 04:45 UTC · Mar 28, 2024Ransomware in the wildCVE-2023-48788CVE-2021-44529CVE-2019-7256+1 CVEs60
AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session HijackingThe Hacker News·Mar 22, 13:45 UTC · Mar 22, 2024Vulnerability55
Three Tips to Protect Your Secrets from AI AccidentsThe Hacker News·Feb 26, 10:29 UTC · Feb 26, 2024Vulnerability42
Adobe Patch Tuesday fixed critical vulnerabilities in Magento, Acrobat and ReaderSecurity Affairs·Feb 14, 09:25 UTC · Feb 14, 2024Vulnerability in the wildCVE-2024-20726CVE-2024-20727CVE-2024-20728+15 CVEs60
Critical Jenkins Vulnerability Exposes Servers to RCE AttacksThe Hacker News·Jan 29, 03:45 UTC · Jan 29, 2024VulnerabilityCVE-2024-23897CVE-2023-27898CVE-2023-2790560
Watch out, experts warn of a critical flaw in JenkinsSecurity Affairs·Jan 26, 17:51 UTC · Jan 26, 2024VulnerabilityCVE-2024-2389760
Hackers can infect networkArs Technica · Security·Jan 9, 14:00 UTC · Jan 9, 2024VulnerabilityCVE-2023-48252CVE-2023-48253CVE-2023-48243+22 CVEs35