How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severityCisco Talos·Feb 21, 13:54 UTC · Feb 21, 2024VulnerabilityCVE-2021-4422860
The Unknown Risks of The Software Supply Chain: A DeepThe Hacker News·Feb 17, 07:04 UTC · Feb 17, 2024Exploit / PoC60
New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP SystemsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2024Exploit / PoC in the wildCVE-2023-51467CVE-2023-49070CVE-2020-9496+2 CVEs60
Experts created a PoC for Apache OFBiz flaw CVE-2023Security Affairs·Jan 12, 12:07 UTC · Jan 12, 2024Exploit / PoCCVE-2023-51467CVE-2023-49070CVE-2020-9496+1 CVEs60
We can't wait for SBOMs to be demanded by regulationHelp Net Security·Jan 8, 14:07 UTC · Jan 8, 2024Policy & legal55
VMware warns of critical vulnerability affecting vCenter Server productThe Record·Oct 26, 21:12 UTC · Oct 26, 2023VulnerabilityCVE-2023-3404860
Balancing budget and system security: Approaches to risk toleranceHelp Net Security·Sep 19, 00:00 UTC · Sep 19, 2023Data breach60
CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho VulnerabilitiesThe Hacker News·Sep 11, 05:58 UTC · Sep 11, 2023VulnerabilityCVE-2022-47966CVE-2022-42475CVE-2021-4422860
Multiple nation-state hackers infiltrate single aviation organizationCyberScoop·Sep 7, 17:07 UTC · Sep 7, 2023Threat actor in the wild60
Major Cybersecurity Agencies Collaborate to Unveil 2022's Most Exploited VulnerabilitiesThe Hacker News·Aug 4, 07:02 UTC · Aug 4, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+9 CVEs160
CISA, FBI, and NSA published the list of 12 most exploited vulnerabilities of 2022Security Affairs·Aug 4, 06:31 UTC · Aug 4, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+8 CVEs60
Fortinet VPN bug tops CISA’s list of most exploited vulnerabilities in 2022The Record·Aug 3, 14:44 UTC · Aug 3, 2023VulnerabilityCVE-2021-44228CVE-2021-40539CVE-2018-13379+8 CVEs60
Vulnerabilities that kept security leaders busy in Q1 2022Help Net Security·Jun 26, 09:19 UTC · Jun 26, 2023Vulnerability55
Iranian Government-Backed Hackers Targeting U.S. Energy and Transit SystemsThe Hacker News·Apr 21, 04:57 UTC · Apr 21, 2023Exploit / PoCCVE-2022-47966CVE-2022-4798660
CISA ’s JCDC Will Focus on Energy SectorSecurity Affairs·Apr 5, 12:15 UTC · Apr 5, 2023Vulnerability55
Rookout's Snapshots: The fourth pillar of observability for more secure applicationsHelp Net Security·Apr 3, 00:00 UTC · Apr 3, 2023Vulnerability55
Experts Spot Half a Million Novel Malware Variants in 2022Infosecurity Magazine·Feb 28, 10:00 UTC · Feb 28, 2023Malware55
North Korea targets US, South Korean hospitals with ransomware to fund further cyber operationsHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2023Ransomware60
CISA’s Joint Cyber Defense Collaborative to tackle energy, water security in 2023The Record·Feb 3, 00:00 UTC · Feb 3, 2023Ransomware60
Understanding your attack surface makes it easier to prioritize technologies and systemsHelp Net Security·Jan 24, 00:00 UTC · Jan 24, 2023Ransomware in the wild60
CISA, Claroty warn of two vulnerabilities affecting industrial Rockwell productsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023VulnerabilityCVE-2022-1161CVE-2022-115960
CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ orgThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Ransomware in the wildCVE-2022-22954CVE-2022-22972CVE-2022-22973+1 CVEs60
CISA urges defenders to update after VMware patches vulnerabilities in multiple productsThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability in the wildCVE-2022-31656CVE-2022-31659CVE-2021-4422860
US and Australian security agencies release list of 2021's 'top' malware strainsThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Malware in the wild60
Google touts ‘fuzzing’ open source tool after discovering TinyGLTF bugThe Record·Jan 11, 00:00 UTC · Jan 11, 2023VulnerabilityCVE-2022-300860
Google announces open source vulnerability reward program after Log4j, Codecov issuesThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Vulnerability55
Insiders worry CISA is too distracted from critical cyber missionCyberScoop·Dec 23, 00:45 UTC · Dec 23, 2022Threat actor160
When Being Attractive Gets Risky - How Does Your Attack Surface Look to an Attacker?The Hacker News·Dec 5, 13:50 UTC · Dec 5, 2022Vulnerability55
Threat Source newsletter (Nov. 3, 2022): Mastodon, evolution, and LiveJournal oh my!Cisco Talos·Nov 3, 20:48 UTC · Nov 3, 2022RansomwareCVE-2022-360260
Google fixes a new actively exploited Chrome zeroSecurity Affairs·Oct 28, 13:01 UTC · Oct 28, 2022Exploit / PoC in the wildCVE-2022-3723CVE-2022-3075CVE-2022-2856+4 CVEs60
BlueBleed: Microsoft confirmed data leak exposing customers’ infoSecurity Affairs·Oct 20, 16:07 UTC · Oct 20, 2022Data breach60
Flaw in the Packagist PHP repository could have allowed a supply chain attackSecurity Affairs·Oct 4, 20:19 UTC · Oct 4, 2022Exploit / PoC in the wildCVE-2022-24828CVE-2021-2947260
Cheerscrypt ransomware is linked to Chinese DEVSecurity Affairs·Oct 4, 07:18 UTC · Oct 4, 2022Ransomware60
Surge in Magento 2 template attacks exploiting CVE-2022Security Affairs·Sep 23, 13:55 UTC · Sep 23, 2022Exploit / PoC in the wildCVE-2022-2408660
Experts warn of critical flaws in Flexlan devices that provide WiFi on airplanesSecurity Affairs·Sep 19, 05:05 UTC · Sep 19, 2022VulnerabilityCVE-2022-36158CVE-2022-3615960