Microsoft pins on-prem SharePoint attacks on Chinese threat actorsHelp Net Security·Jul 24, 15:45 UTC · Jul 24, 2025Threat actor in the wildCVE-2025-49706CVE-2025-49704CVE-2025-53770+1 CVEs60
What to know about ToolShell, the SharePoint threat under mass exploitationArs Technica · Security·Jul 23, 20:14 UTC · Jul 23, 2025Vulnerability in the wildCVE-2025-49706CVE-2025-4970460
2,000 Palo Alto Networks devices compromised in latest attacksHelp Net Security·Feb 19, 08:15 UTC · Feb 19, 2025Exploit / PoCCVE-2024-0012CVE-2024-947460
China-linked APT group Winnti targets Japanese organizationsSecurity Affairs·Feb 18, 16:10 UTC · Feb 18, 2025Threat actor57
Chained Vulnerabilities Exploited in Ivanti Cloud Service AppliancesInfosecurity Magazine·Jan 23, 16:30 UTC · Jan 23, 2025VulnerabilityCVE-2024-8963CVE-2024-9379CVE-2024-8190+1 CVEs160
Eagerbee backdoor targets govt entities and ISPs in Middle EastSecurity Affairs·Jan 7, 06:23 UTC · Jan 7, 2025MalwareCVE-2021-2685547
U.S. CISA adds ProjectSend, North Grid Proself, and Zyxel firewalls bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 4, 07:56 UTC · Dec 4, 2024Exploit / PoC in the wildCVE-2023-45727CVE-2024-11680CVE-2024-1166760
China-Based RedJuliett Targets Taiwan in Cyber Espionage CampaignInfosecurity Magazine·Jun 24, 13:00 UTC · Jun 24, 2024Threat actor60
SockDetour – a Silent, Fileless, Socketless BackdoorPalo Alto Unit 42·Jun 5, 23:28 UTC · Jun 5, 2024MalwareCVE-2021-40539CVE-2021-44077CVE-2021-2879947
Ivanti-linked breach of CISA potentially affected more than 100,000 individualsCyberScoop·Mar 29, 20:05 UTC · Mar 29, 2024Data breach in the wild60
Ivanti Releases ZeroInfosecurity Magazine·Feb 1, 09:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Two zero-day bugs in Ivanti Connect Secure actively exploitedSecurity Affairs·Jan 11, 15:03 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760
Two Ivanti ZeroInfosecurity Magazine·Jan 11, 09:30 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2023-35078+1 CVEs60
Attackers are trying to exploit Apache Struts vulnerability (CVE-2023-50164)Help Net Security·Dec 18, 09:23 UTC · Dec 18, 2023Vulnerability in the wildCVE-2023-5016460
Ransomware group exploits Citrix NetScaler systems for initial accessHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2023Ransomware in the wildCVE-2023-351960
CISA, experts warn of Citrix vulnerabilities being exploited by hackersThe Record·Aug 16, 21:19 UTC · Aug 16, 2023VulnerabilityCVE-2023-24489CVE-2023-351947
Approximately 2000 Citrix NetScaler servers were backdoored in massive campaignSecurity Affairs·Aug 16, 07:20 UTC · Aug 16, 2023Malware in the wildCVE-2023-351960
Citrix ADC zero-day exploitation: CISA releases details about attack on CI organization (CVE-2023-3519)Help Net Security·Jul 24, 09:30 UTC · Jul 24, 2023Exploit / PoC in the wildCVE-2023-3519160
Healthcare organizations in the crosshairs of cyberattackersHelp Net Security·Jul 18, 00:00 UTC · Jul 18, 2023RansomwareCVE-2021-44228CVE-2022-2296560
China-linked hackers target telecommunication providers in the Middle EastSecurity Affairs·Mar 24, 21:04 UTC · Mar 24, 2023Malware42
Microsoft Exchange admins advised to expand antivirus scanningHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2023Exploit / PoC60
Fortinet FortiNAC CVE-2022-39952 flaw exploited in the wild hours after release of PoC exploitSecurity Affairs·Feb 23, 19:45 UTC · Feb 23, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-4275660
Critical Microsoft Azure RCE flaw impacted multiple servicesSecurity Affairs·Jan 19, 16:02 UTC · Jan 19, 2023Vulnerability55
CISA orders civilian agencies to patch Zimbra bug after mass exploitationThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-37042CVE-2022-27925CVE-2022-2792460
FBI: Iranian threat actor trying to acquire leaked data on US organizationsThe Record·Dec 19, 00:00 UTC · Dec 19, 2022Data breachCVE-2019-10068CVE-2008-3362CVE-2014-4725+8 CVEs50
Two Microsoft Exchange zero-days exploited by attackers (CVE-2022-41040, CVE-2022-41082)Help Net Security·Oct 3, 10:39 UTC · Oct 3, 2022VulnerabilityCVE-2022-41040CVE-2022-4108260
TAC-040 group used previously undetected Ljl BackdoorSecurity Affairs·Aug 5, 08:52 UTC · Aug 5, 2022MalwareCVE-2022-26134CVE-2022-2296547
Threat actors are actively exploiting CVE-2022-1388 RCE in F5 BIGSecurity Affairs·May 10, 06:42 UTC · May 10, 2022VulnerabilityCVE-2022-138860
Hackers breached a server of National Games of China before the eventSecurity Affairs·Feb 7, 12:55 UTC · Feb 7, 2022Data breach45
Tens of AccessPress WordPress themes compromised as part of a supply chain attackSecurity Affairs·Jan 24, 20:33 UTC · Jan 24, 2022VulnerabilityCVE-2021-2486747
Determined APT is exploiting ManageEngine ServiceDesk Plus vulnerability (CVE-2021-44077)Help Net Security·Dec 3, 00:00 UTC · Dec 3, 2021Vulnerability in the wildCVE-2021-44077CVE-2021-33617160
Zero-Day flaw in FatPipe products actively exploited, FBI warnsSecurity Affairs·Nov 18, 15:34 UTC · Nov 18, 2021Exploit / PoC in the wild60
Nation-state actors target critical sectors by exploiting CVE-2021Security Affairs·Nov 8, 10:37 UTC · Nov 8, 2021Threat actor in the wildCVE-2021-4053960
CISA publishes malware analysis reports on samples targeting Pulse Secure devicesSecurity Affairs·Aug 26, 22:32 UTC · Aug 26, 2021MalwareCVE-2021-22893CVE-2021-22937CVE-2020-826060
WARNING: Microsoft Exchange Under Attack With ProxyShell FlawsThe Hacker News·Aug 23, 13:28 UTC · Aug 23, 2021Ransomware in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Black Kingdom ransomwareKaspersky Securelist·Jun 17, 09:42 UTC · Jun 17, 2021RansomwareCVE-2021-27065CVE-2019-11510CVE-2021-26855+2 CVEs60
APT trends report Q1 2021Kaspersky Securelist·Apr 27, 10:00 UTC · Apr 27, 2021Exploit / PoC in the wild60
China-linked APT used Pulse Secure VPN zero-day to hack US defense contractorsSecurity Affairs·Apr 21, 05:38 UTC · Apr 21, 2021Exploit / PoCCVE-2021-2289360