SesameOp: New backdoor exploits OpenAI API for covert C2Security Affairs·Nov 4, 17:06 UTC · Nov 4, 2025Malware42
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain RisksThe Hacker News·Oct 31, 07:59 UTC · Oct 31, 2025Ransomware60
CISA Flags VMware Zero-Day Exploited by ChinaThe Hacker News·Oct 31, 07:09 UTC · Oct 31, 2025Exploit / PoC in the wildCVE-2025-4124460
U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 30, 23:15 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-24893CVE-2025-4124460
Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under AttackThe Hacker News·Oct 30, 09:41 UTC · Oct 30, 2025Exploit / PoC in the wildCVE-2025-6204CVE-2025-6205CVE-2025-24893+1 CVEs60
Redis patches 13-Year-Old Lua flaw enabling Remote Code ExecutionSecurity Affairs·Oct 8, 09:10 UTC · Oct 8, 2025VulnerabilityCVE-2025-4984460
13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code RemotelyThe Hacker News·Oct 7, 09:30 UTC · Oct 7, 2025Vulnerability in the wildCVE-2025-4984460
Redis patches critical "RediShell" RCE vulnerability, update ASAP! (CVE-2025-49844)Help Net Security·Oct 7, 00:00 UTC · Oct 7, 2025Vulnerability in the wildCVE-2025-4984460
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the WildThe Hacker News·Oct 3, 08:23 UTC · Oct 3, 2025Exploit / PoC in the wildCVE-2025-4008CVE-2025-21043CVE-2017-1000353+2 CVEs60
How threat actors breached U.S. federal civilian agency by exploiting a GeoServer flawSecurity Affairs·Sep 24, 10:16 UTC · Sep 24, 2025Data breach in the wildCVE-2024-3640160
Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus DetectionThe Hacker News·Aug 22, 15:33 UTC · Aug 22, 2025Malware42
⚡ Weekly Recap: VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & MoreThe Hacker News·Aug 5, 04:38 UTC · Aug 5, 2025Malware in the wildCVE-2025-40596CVE-2025-40597CVE-2025-40598+8 CVEs60
Shell No! (Part 2) Introducing Cknife, China Chopper’s SiblingRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Shell No! Adversary Web Shell Trends and Mitigations (Part 1)Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
Free AI coding security rules now available on GitHubHelp Net Security·Jun 17, 00:00 UTC · Jun 17, 2025AI safety & security30
Crypto Developers Targeted by Python Malware Disguised as Coding ChallengesThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2025Malware130
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm PackagesThe Hacker News·Apr 7, 06:39 UTC · Apr 7, 2025Malware42
SideWinder APT attacks in H2 2024Kaspersky Securelist·Mar 10, 10:01 UTC · Mar 10, 2025VulnerabilityCVE-2017-1188247
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Kaspersky SOC analyzes an incident involving a web shell used as a backdoorKaspersky Securelist·Feb 28, 04:00 UTC · Feb 28, 2025Malware42
Decades-Old Security Vulnerabilities Found in Ubuntu's Needrestart PackageThe Hacker News·Nov 20, 10:24 UTC · Nov 20, 2024VulnerabilityCVE-2024-48990CVE-2024-48991CVE-2024-48992+2 CVEs35
Writing a BugSleep C2 server and detecting its traffic with SnortCisco Talos·Oct 30, 10:00 UTC · Oct 30, 2024Malware130
U.S. CISA adds Cisco ASA and FTD, and RoundCube Webmail bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 25, 07:40 UTC · Oct 25, 2024Exploit / PoC in the wildCVE-2024-20481CVE-2024-3738360
Hackers Exploit Roundcube Webmail XSS Vulnerability to Steal Login CredentialsThe Hacker News·Oct 21, 12:12 UTC · Oct 21, 2024VulnerabilityCVE-2024-3738335
Unknown threat actors exploit Roundcube Webmail flaw in phishing campaignSecurity Affairs·Oct 21, 06:28 UTC · Oct 21, 2024Threat actorCVE-2024-3738350
North Korean Hackers Target Developers with Malicious npm PackagesThe Hacker News·Aug 31, 15:12 UTC · Aug 31, 2024Malware42
CISA adds OSGeo GeoServer GeoTools bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 16, 14:57 UTC · Jul 16, 2024Exploit / PoC in the wildCVE-2024-3640160
Hidden between the tags: Insights into spammers’ evasion techniques in HTML SmugglingCisco Talos·Jul 10, 12:00 UTC · Jul 10, 2024Malware42
Threat Brief: CVE-2022Palo Alto Unit 42·Jun 5, 22:35 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-138860
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress SitesThe Hacker News·May 8, 14:05 UTC · May 8, 2024Vulnerability in the wildCVE-2023-4000060
Threat actors are exploiting critical Magento vulnerability CVE-2024-20720 to install a persistent backdoor on eSecurity Affairs·Apr 5, 20:41 UTC · Apr 5, 2024VulnerabilityCVE-2024-2072060
Chinese Groups Deploy New TTPs to Exploit Ivanti VulnerabilitiesInfosecurity Magazine·Apr 5, 15:00 UTC · Apr 5, 2024VulnerabilityCVE-2023-46805CVE-2024-21887CVE-2024-2189347
Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacksSecurity Affairs·Oct 26, 05:20 UTC · Oct 26, 2023Exploit / PoCCVE-2020-35730CVE-2022-27926CVE-2023-563160
$260 Million AI Company Releases Undeletable Chatbot That Gives Detailed Instructions on Murder, Ethnic Cleansing404 Media·Sep 30, 12:50 UTC · Sep 30, 2023Model release50
The many vulnerabilities Talos discovered in SOHO and industrial wireless routers postCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2023Vulnerability30
A Data Exfiltration Attack Scenario: The Porsche ExperienceThe Hacker News·Jul 28, 11:48 UTC · Jul 28, 2023Exploit / PoC60
Quarterly Report: Incident Response Trends in Q1 2023Cisco Talos·Apr 26, 12:00 UTC · Apr 26, 2023Ransomware57
Muhstik Botnet Targeting Redis Servers Using Recently Disclosed VulnerabilitySecurity Affairs·Mar 28, 20:43 UTC · Mar 28, 2022VulnerabilityCVE-2022-0543CVE-2019-2725CVE-2017-10271+1 CVEs47