Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197160
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI FrameworksThe Hacker News·Mar 27, 08:07 UTC · Mar 27, 2026Vulnerability in the wildCVE-2026-34070CVE-2025-68664CVE-2025-67644+2 CVEs160
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCEThe Hacker News·Mar 17, 16:39 UTC · Mar 17, 2026Vulnerability in the wildCVE-2026-25750CVE-2026-3059CVE-2026-3060+1 CVEs60
Week in review: AiTM phishing kit used to hijack AWS accounts, year-long malware campaign targets HRHelp Net Security·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-21262CVE-2026-26127160
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor BackdoorThe Hacker News·Mar 9, 06:40 UTC · Mar 9, 2026Malware in the wildCVE-2017-7921CVE-2023-6895CVE-2021-36260+2 CVEs60
Henry IV, Hotspur, Hal, and hallucinationsCisco Talos·Feb 26, 19:00 UTC · Feb 26, 2026Ransomware in the wildCVE-2026-2012760
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
AI-powered campaign compromises 600 FortiGate systems worldwideSecurity Affairs·Feb 23, 10:39 UTC · Feb 23, 2026Threat actor in the wildCVE-2019-7192CVE-2023-27532CVE-2024-40711160
⚡ Weekly Recap: Fortinet Exploits, RedLine Clipjack, NTLM Crack, Copilot Attack & MoreThe Hacker News·Jan 20, 07:01 UTC · Jan 20, 2026Exploit / PoC in the wildCVE-2025-6415560
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)Help Net Security·Jan 16, 00:00 UTC · Jan 16, 2026Exploit / PoC in the wildCVE-2025-2039360
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & MoreThe Hacker News·Dec 31, 05:07 UTC · Dec 31, 2025Malware in the wildCVE-2025-14847CVE-2020-12812CVE-2025-68664+7 CVEs260
Cisco Warns of Active Attacks Exploiting Unpatched 0The Hacker News·Dec 20, 12:11 UTC · Dec 20, 2025Vulnerability in the wildCVE-2025-2039360
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Hackers target AI and crypto as software supply chain risks growHelp Net Security·Dec 3, 14:29 UTC · Dec 3, 2025Vulnerability in the wild60
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Hackers turn open-source AI framework into global cryptojacking operationCyberScoop·Nov 19, 15:29 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2023-48022160
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Leaked Oracle EBS exploit scripts expected to drive new wave of attacks (CVE-2025-61882)Help Net Security·Oct 9, 16:24 UTC · Oct 9, 2025Vulnerability in the wildCVE-2025-6188260
⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 BitThe Hacker News·Sep 22, 15:16 UTC · Sep 22, 2025Ransomware in the wildCVE-2025-10585CVE-2025-55241CVE-2025-10035+14 CVEs160
Chinese AI Villager Pen Testing Tool Hits 11,000 PyPI DownloadsInfosecurity Magazine·Sep 16, 16:00 UTC · Sep 16, 2025Malware in the wild57
Security Affairs newsletter Round 541 by Pierluigi PaganiniSecurity Affairs·Sep 14, 12:09 UTC · Sep 14, 2025Ransomware in the wildCVE-2025-5313660
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active ExploitationThe Hacker News·Sep 8, 14:09 UTC · Sep 8, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-30406CVE-2025-393560
Hundreds of Salesforce customers impacted by attack spree linked to thirdCyberScoop·Aug 27, 01:22 UTC · Aug 27, 2025Exploit / PoC in the wild60
Security Affairs newsletter Round 536 by Pierluigi PaganiniSecurity Affairs·Aug 9, 23:48 UTC · Aug 9, 2025Ransomware in the wildCVE-2025-2331960
Researchers flag flaw in Google’s AI coding assistant that allowed for ‘silent’ code exfiltrationCyberScoop·Jul 28, 20:26 UTC · Jul 28, 2025Exploit / PoC in the wild160
⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and MoreThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Malware in the wildCVE-2025-49706CVE-2025-49704CVE-2025-20281+27 CVEs60
Week in review: Microsoft fixes wormable RCE bug on Windows, check for CitrixBleed 2 exploitationHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2025Vulnerability in the wildCVE-2025-47981CVE-2025-49719CVE-2025-5777160
Oligo Security strives to fill applicationCyberScoop·Jul 8, 15:40 UTC · Jul 8, 2025Exploit / PoC in the wild60
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS AttacksThe Hacker News·Jun 21, 09:10 UTC · Jun 21, 2025Vulnerability in the wildCVE-2025-324860
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 12, 09:17 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-24016CVE-2025-3305360
Mirai botnets exploit Wazuh RCE, Akamai warnedSecurity Affairs·Jun 10, 10:27 UTC · Jun 10, 2025Vulnerability in the wildCVE-2025-24016CVE-2024-3721160
Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps ServerThe Hacker News·May 15, 00:00 UTC · May 15, 2025Vulnerability in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+10 CVEs160
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation EvidenceThe Hacker News·May 8, 13:52 UTC · May 8, 2025Exploit / PoC in the wildCVE-2025-324860
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February]The Hacker News·May 6, 07:05 UTC · May 6, 2025Ransomware in the wildCVE-2024-57726CVE-2024-57727CVE-2024-57728+18 CVEs60
⚡ Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Malware in the wildCVE-2025-24054CVE-2024-43451CVE-2025-31200+7 CVEs60
RCE flaw in tool for building AI agents exploited by attackers (CVE-2025-3248)Help Net Security·May 6, 00:00 UTC · May 6, 2025Vulnerability in the wildCVE-2025-324860
Security Affairs newsletter Round 520 by Pierluigi PaganiniSecurity Affairs·Apr 20, 16:14 UTC · Apr 20, 2025Exploit / PoC in the wildCVE-2025-30406CVE-2025-24054CVE-2021-2003560
Week in review: Microsoft patches exploited Windows CLFS 0-day, WinRAR MotW bypass flaw fixedHelp Net Security·Apr 13, 00:00 UTC · Apr 13, 2025Vulnerability in the wildCVE-2025-29824CVE-2025-31334CVE-2024-48887+2 CVEs160