Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active AttacksThe Hacker News·Jan 13, 07:05 UTC · Jan 13, 2026Exploit / PoC in the wildCVE-2025-8110CVE-2024-5594760
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT MalwareThe Hacker News·Dec 10, 07:33 UTC · Dec 10, 2025MalwareCVE-2025-5518260
The Bug That Won't Die: 10 Years of the Same MistakeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Exploit / PoCCVE-2025-55182CVE-2025-66478CVE-2015-485260
Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT TechniquesRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Threat actor60
North Korea’s Fraudulent IT Employment Scheme: A Cybersecurity ThreatRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Phishing & fraud55
Iranian Hackers’ Rising Interest in Targeting Android Systems With DroidJack, AndroRATRecorded Future·Aug 12, 00:00 UTC · Aug 12, 2025Malware55
Log4Shell: How It’s Exploited and Mitigating DamageRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Exploit / PoC in the wildCVE-2021-4422860
Explosive Growth of Non-Human Identities Creating Massive Security Blind SpotsThe Hacker News·Apr 9, 10:30 UTC · Apr 9, 2025Threat actor60
70% Of Leaked Secrets Remain Active Two Years LaterHelp Net Security·Mar 20, 00:00 UTC · Mar 20, 2025Exploit / PoC60
Lazarus Group deceives developers with 6 new malicious npm packagesCyberScoop·Mar 12, 22:31 UTC · Mar 12, 2025Threat actor in the wild160
This Windows PowerShell Phish Has Scary PotentialKrebs on Security·Sep 19, 20:18 UTC · Sep 19, 2024Vulnerability55
Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROIHelp Net Security·Jul 28, 00:00 UTC · Jul 28, 2024Exploit / PoCCVE-2024-6327CVE-2024-4111060
Polyfill, Cloudflare trade barbs after reports of supply chain attack threatening 100,000 websitesThe Record·Jun 27, 00:00 UTC · Jun 27, 2024Vulnerability55
What we know about the xz Utils backdoor that almost infected the worldArs Technica · Security·Apr 1, 06:55 UTC · Apr 1, 2024Malware55
Week in review: Public MS Word RCE PoC, API exploitation, Patch Tuesday forecastHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2023Exploit / PoCCVE-2023-27532CVE-2023-25610CVE-2023-21716160
The Secret Vulnerability Finance Execs are MissingThe Hacker News·Feb 23, 14:40 UTC · Feb 23, 2023Vulnerability55
Infosec products of the month: October 2022Help Net Security·Nov 1, 00:00 UTC · Nov 1, 2022Policy & legal55
FTC holds alcohol delivery app Drizly and its CEO liable for lax data security before 2020 hackCyberScoop·Oct 25, 00:35 UTC · Oct 25, 2022Policy & legal in the wild160
New infosec products of the week: October 7, 2022Help Net Security·Oct 7, 00:00 UTC · Oct 7, 2022Policy & legal55
Critical RCE bug in GitLab patched, update ASAP! (CVE-2022-2884)Help Net Security·Aug 24, 00:00 UTC · Aug 24, 2022Vulnerability in the wildCVE-2022-2884160
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
Critical RCE Bug Found in Homebrew Package Manager for macOS and LinuxThe Hacker News·Apr 26, 07:33 UTC · Apr 26, 2021Vulnerability55
Hackers breached a the PHP 's Git Server and inserted a backdoor in the codeSecurity Affairs·Mar 29, 14:22 UTC · Mar 29, 2021Data breach160
Hackers Are Targeting Microsoft Exchange Servers With RansomwareThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Ransomware in the wild60
Expert publishes PoC exploit code for Microsoft Exchange flawsSecurity Affairs·Mar 11, 21:33 UTC · Mar 11, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Wormable Gitpaste-12 Botnet Returns to Target Linux Servers, IoT DevicesThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2020MalwareCVE-2020-5902CVE-2020-8816CVE-2020-10987+2 CVEs60
New Open Source Security Foundation wants to improve open source software securityHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2020Advisory55
Git Project addresses a critical arbitrary code execution vulnerability in GitSecurity Affairs·Oct 8, 06:32 UTC · Oct 8, 2018VulnerabilityCVE-2018-17456160
Critical code execution flaw in Electron framework impacts popular Desktop apps such as Skype and SignalSecurity Affairs·Jan 24, 21:15 UTC · Jan 24, 2018VulnerabilityCVE-2018-100000660
Massive botnet responsible for wave of DDoS attacksCyberScoop·Oct 21, 13:35 UTC · Oct 21, 2016Malware in the wild60
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News·Jul 30, 07:40 UTC · Jul 30, 2026Data breachCVE-2026-42897CVE-2025-6637660
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breachedHelp Net Security·Jul 26, 00:00 UTC · Jul 26, 2026Data breach in the wildCVE-2026-6875CVE-2026-15409CVE-2026-15410+4 CVEs60
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security·Jun 21, 00:00 UTC · Jun 21, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-48558CVE-2026-39813+3 CVEs160
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated WindowsThe Hacker News·Jun 10, 17:30 UTC · Jun 10, 2026Exploit / PoC in the wildCVE-2026-33825CVE-2026-45498CVE-2026-41091160
Microsoft Calls the Zero-Day Dumps Irresponsible. The Researcher Says Microsoft Started It.Security Affairs·May 29, 10:51 UTC · May 29, 2026Exploit / PoC in the wildCVE-2026-45585160
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60