Attacks on web applications spike in third quarter, new Talos IR data showsCisco Talos·Oct 24, 12:00 UTC · Oct 24, 2023Ransomware60
Crypto flaw in Oracle Access Manager can let attackers pass throughHelp Net Security·May 3, 00:00 UTC · May 3, 2018VulnerabilityCVE-2018-287935
Space and defense tech maker Exail Technologies exposes database accessSecurity Affairs·Sep 21, 13:24 UTC · Sep 21, 2023Vulnerability55
Hackers hosted tools on a Stanford University website for monthsHelp Net Security·Jun 26, 21:22 UTC · Jun 26, 2018Malware30
Infostealers increasingly impact global securityHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2024MalwareCVE-2010-4598CVE-2011-2474CVE-2014-0130+15 CVEs60
Threat actors breached US govt systems by exploiting Adobe ColdFusion flawSecurity Affairs·Dec 6, 00:56 UTC · Dec 6, 2023Data breach in the wildCVE-2023-2636060
Cisco Wireless Residential Gateway Remote Code Execution flawSecurity Affairs·Jul 17, 16:33 UTC · Jul 17, 2014Vulnerability55
RSA Authentication SDK affected by two critical vulnerabilities, patch it now!Security Affairs·Dec 4, 08:15 UTC · Dec 4, 2017VulnerabilityCVE-2017-14377CVE-2017-1437860
Flaws in Siemens Building Automation Controllers open to hack. Fix them asapSecurity Affairs·Oct 15, 15:53 UTC · Oct 15, 2017VulnerabilityCVE-2017-9946CVE-2017-994747
Hezbollah Hacker Group Targeted Telecoms, Hosting, ISPs WorldwideThe Hacker News·Jan 29, 10:08 UTC · Jan 29, 2021VulnerabilityCVE-2019-3396CVE-2019-11581CVE-2012-315235
You're deploying it wrong! TeamCity, Subversion & Web Deploy part 3: Publishing with Web DeployTroy Hunt·Nov 24, 00:00 UTC · Nov 24, 2010Industry30
Crypto Me0wing attacks: Kitty cashes in on MoneroHelp Net Security·Jun 26, 21:20 UTC · Jun 26, 2018Exploit / PoCCVE-2018-760060
Ebury Botnet Malware Compromises 400,000 Linux Servers Over Past 14 YearsThe Hacker News·May 15, 00:00 UTC · May 15, 2024MalwareCVE-2021-4546747
Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency ServersThe Hacker News·Dec 9, 05:09 UTC · Dec 9, 2023Vulnerability in the wildCVE-2023-2636060
Lousy IoT SecuritySchneier on Security·Dec 19, 06:31 UTC · Dec 19, 2019VulnerabilityCVE-2019-16270CVE-2019-16274CVE-2019-16271+2 CVEs35
Prometei botnet improves modules and exhibits new capabilities in recent updatesCisco Talos·Mar 9, 13:02 UTC · Mar 9, 2023MalwareCVE-2019-0708147
The serpent’s tongue: Luring the Python out of its denCisco Talos·Jul 14, 10:00 UTC · Jul 14, 2026Malware155
Kaspersky SOC analyzes an incident involving a web shell used as a backdoorKaspersky Securelist·Feb 28, 04:00 UTC · Feb 28, 2025Malware42
Remotely controlled EV home chargersKaspersky Securelist·Dec 13, 10:00 UTC · Dec 13, 2018Vulnerability30
BRICKSTORM backdoor exposed: CISA warns of advanced ChinaSecurity Affairs·Dec 5, 11:03 UTC · Dec 5, 2025Malware55
Researchers Demonstrate New Way to Detect MitM Phishing Kits in the WildThe Hacker News·Nov 18, 07:23 UTC · Nov 18, 2021Phishing & fraud30
New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60
CISA Reports PRC Hackers Using BRICKSTORM for LongThe Hacker News·Dec 5, 09:15 UTC · Dec 5, 2025Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-38812+3 CVEs160
Crooks leverages .htaccess injector on Joomla and WordPress sites for malicious redirectsSecurity Affairs·May 27, 12:39 UTC · May 27, 2019Exploit / PoCCVE-2018-920660
Scanning for Flaws, Scoring for SecurityKrebs on Security·Dec 12, 20:12 UTC · Dec 12, 2018Data breach57
Blue Mockingbird MoneroSecurity Affairs·May 10, 20:17 UTC · May 10, 2020VulnerabilityCVE-2019-1893547
Unpatched Wordpress Flaw Could Allow Hackers To Reset Admin PasswordThe Hacker News·May 4, 18:50 UTC · May 4, 2017VulnerabilityCVE-2017-829560
Legit tools, illicit uses: Velociraptor, Nezha turned against victimsHelp Net Security·Oct 15, 11:50 UTC · Oct 15, 2025RansomwareCVE-2025-626460
F5 Networks Acquires NGINX For $670 MillionThe Hacker News·Mar 12, 07:17 UTC · Mar 12, 2019AI tools & infra30
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
Researcher Demonstrates 4 New Variants of HTTP Request Smuggling AttackThe Hacker News·Aug 5, 18:57 UTC · Aug 5, 2020Vulnerability30
A flaw in Concrete5 CMS could have allowed website takeoverSecurity Affairs·Aug 19, 06:35 UTC · Aug 19, 2020Vulnerability42
Hackers target Drupal servers chaining several flaws, including Drupalgeddon2 and DirtyCOWSecurity Affairs·Nov 20, 20:23 UTC · Nov 20, 2018VulnerabilityCVE-2018-760035
DNS Rebinding Attack: How Malicious Websites Exploit Private NetworksPalo Alto Unit 42·Jun 6, 01:33 UTC · Jun 6, 2024Data breach60
Adversaries increasingly using vendor and contractor accounts to infiltrate networksCisco Talos·Jun 6, 12:01 UTC · Jun 6, 2023Ransomware57
FreeMilk: A Highly Targeted Spear Phishing CampaignPalo Alto Unit 42·Oct 5, 12:00 UTC · Oct 5, 2017Threat actorCVE-2017-019960
China-linked APT41 group targets USSecurity Affairs·Aug 21, 17:26 UTC · Aug 21, 2019Threat actorCVE-2019-339660
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux ServersThe Hacker News·Apr 3, 15:32 UTC · Apr 3, 2026Vulnerability142
Hackers breached a server of National Games of China before the eventSecurity Affairs·Feb 7, 12:55 UTC · Feb 7, 2022Data breach45