APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk PlusPalo Alto Unit 42·Jun 6, 01:25 UTC · Jun 6, 2024Threat actor in the wildCVE-2021-44077CVE-2021-3361760
Social engineering aspect of the XZ incidentKaspersky Securelist·Apr 24, 10:10 UTC · Apr 24, 2024Phishing & fraud42
MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned LibrariesThe Hacker News·Jan 22, 16:48 UTC · Jan 22, 2024Threat actor157
CISA adds Ruckus bug and another six flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 16, 19:39 UTC · May 16, 2023Exploit / PoC in the wildCVE-2023-25717CVE-2021-3560CVE-2014-0196+4 CVEs160
Most attackers lose interest in Log4ShellThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC in the wildCVE-2021-4422860
Spring confirms ‘Spring4Shell’ zeroThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoCCVE-2022-22965CVE-2022-2296360
Researchers Disclose Critical RCE Vulnerability Affecting Quarkus Java FrameworkThe Hacker News·Dec 1, 11:45 UTC · Dec 1, 2022VulnerabilityCVE-2022-411660
Contrast Security partners with GitHub to deliver pipeline-native security to developersHelp Net Security·Feb 3, 00:00 UTC · Feb 3, 2022Vulnerability30
Second Log4j Vulnerability (CVE-2021The Hacker News·Dec 18, 13:56 UTC · Dec 18, 2021Vulnerability in the wildCVE-2021-45046CVE-2021-4422860
Multi-platform Tycoon Ransomware employed in targeted attacksSecurity Affairs·Jun 5, 12:43 UTC · Jun 5, 2020Ransomware57
Microsoft warns about ongoing PonyFinal ransomware attacksSecurity Affairs·May 27, 21:58 UTC · May 27, 2020Ransomware57
Friday Squid Blogging: Planctotuethis SquidSchneier on Security·Jan 29, 08:03 UTC · Jan 29, 2020Vulnerability142
July Patch Tuesday forecast: Rules are changing for companies with custom applicationsHelp Net Security·Jul 11, 09:12 UTC · Jul 11, 2019Vulnerability55
April Patch Tuesday Forecast: Be aware of end-of-service issues and browser exploitsHelp Net Security·Apr 17, 08:45 UTC · Apr 17, 2019Vulnerability55
JackPOS malware presented as a Java Update SchedulerSecurity Affairs·Sep 14, 12:26 UTC · Sep 14, 2017Malware142
Learn How to Code: Get 10 Best Online Training Courses for Just $49The Hacker News·Aug 3, 16:06 UTC · Aug 3, 2017Research30
25% of web apps still vulnerable to eight of the OWASP Top TenHelp Net Security·Feb 14, 00:00 UTC · Feb 14, 2017Vulnerability30
A Cross-platform JavaKaspersky Securelist·Jan 28, 20:18 UTC · Jan 28, 2014VulnerabilityCVE-2013-2465147
Central Tibetan Administration Website CompromisedKaspersky Securelist·Aug 12, 22:14 UTC · Aug 12, 2013VulnerabilityCVE-2012-4681CVE-2013-242347
IT Threat Evolution: Q1 2012Kaspersky Securelist·May 21, 14:00 UTC · May 21, 2012Exploit / PoCCVE-2011-354460
Oracle Critical Patch Update October 2011Kaspersky Securelist·Oct 20, 01:02 UTC · Oct 20, 2011VulnerabilityCVE-2011-3389CVE-2011-353860
Mobile Malware Evolution: An Overview, Part 3Kaspersky Securelist·Sep 29, 17:00 UTC · Sep 29, 2009Malware42
Experts uncover critical flaws in Kigen eSIM affecting billionsSecurity Affairs·Jul 14, 11:09 UTC · Jul 14, 2025Exploit / PoC60
Alert: Exposed JDWP Interfaces Lead to Crypto Mining, Hpingbot Targets SSH for DDoSThe Hacker News·Jul 6, 07:18 UTC · Jul 6, 2025Vulnerability42
Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps ServerThe Hacker News·May 15, 00:00 UTC · May 15, 2025Vulnerability in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+10 CVEs160
Apache Tomcat Vulnerability CVE-2024The Hacker News·Dec 24, 06:06 UTC · Dec 24, 2024VulnerabilityCVE-2024-56337CVE-2024-50379CVE-2024-1282860
How to manage the intersection of Java, security and DevOps at a low complexity costHelp Net Security·Jun 5, 12:36 UTC · Jun 5, 2023Vulnerability30
CISA Issues Warning on Active Exploitation of ZK Java Web Framework VulnerabilityThe Hacker News·Feb 28, 13:28 UTC · Feb 28, 2023Vulnerability in the wildCVE-2022-3653760
Google OAuth client library flaw allowed to deploy malicious payloadsSecurity Affairs·May 23, 19:04 UTC · May 23, 2022VulnerabilityCVE-2021-2257347
Amazon's Hotpatch for Log4j Flaw Found Vulnerable to Privilege Escalation BugThe Hacker News·Apr 23, 05:41 UTC · Apr 23, 2022Vulnerability in the wildCVE-2021-3100CVE-2021-3101CVE-2022-0070+1 CVEs60
Spring4Shell: No need to panic, but mitigations are advisedHelp Net Security·Apr 6, 12:06 UTC · Apr 6, 2022Exploit / PoC in the wildCVE-2022-22963CVE-2010-1622CVE-2022-2296560
'Spring4Shell' bug in framework for Java programming draws widespread warningsCyberScoop·Apr 1, 18:45 UTC · Apr 1, 2022Exploit / PoC in the wild60
NetWitness partners with Datashield to protect customers from Log4j Java security vulnerabilityHelp Net Security·Dec 16, 00:00 UTC · Dec 16, 2021Vulnerability55
Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228)Help Net Security·Dec 13, 12:51 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-4422860
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wildCisco Talos·Dec 10, 19:37 UTC · Dec 10, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
SWEED: Exposing years of Agent Tesla campaignsCisco Talos·Jul 15, 15:04 UTC · Jul 15, 2019Threat actorCVE-2017-8759CVE-2017-11882160
Apache Software Foundation fixes important flaws in Apache TomcatSecurity Affairs·Jul 25, 06:35 UTC · Jul 25, 2018Exploit / PoC in the wildCVE-2018-8037CVE-2018-1336CVE-2018-8034160
Hacking SAP CRM by chaining 2 flaws in SAP NetWeaver AS JavaSecurity Affairs·Mar 16, 05:31 UTC · Mar 16, 2018Vulnerability55
Week in review: Email tracking, DNS exfiltration, and secure coding in JavaHelp Net Security·Oct 8, 00:00 UTC · Oct 8, 2017Data breach157