Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure EntitiesThe Hacker News·Feb 7, 11:03 UTC · Feb 7, 2026Exploit / PoC60
Security Affairs newsletter Round 561 by Pierluigi PaganiniSecurity Affairs·Feb 2, 09:39 UTC · Feb 2, 2026Data breach in the wildCVE-2026-24858CVE-2025-40551CVE-2025-808860
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
ShadowRay 2.0 Exploits Unpatched Ray Flaw to Build SelfThe Hacker News·Nov 21, 06:45 UTC · Nov 21, 2025VulnerabilityCVE-2023-48022160
Sprout: Open-source bootloader built for speed and securityHelp Net Security·Nov 13, 00:00 UTC · Nov 13, 2025Malware55
Week in review: Cisco fixes critical UCCX flaws, November 2025 Patch Tuesday forecastHelp Net Security·Nov 9, 00:00 UTC · Nov 9, 2025Vulnerability in the wildCVE-2025-48703CVE-2025-11371CVE-2025-20358+1 CVEs60
Google fixes actively exploited Android vulnerabilities (CVE-2025-48543, CVE-2025-38352)Help Net Security·Sep 4, 00:00 UTC · Sep 4, 2025Vulnerability in the wildCVE-2025-48543CVE-2025-38352CVE-2025-4853960
Google addressed two Android flaws actively exploited in targeted attacksSecurity Affairs·Sep 3, 17:38 UTC · Sep 3, 2025Vulnerability in the wildCVE-2025-38352CVE-2025-48543CVE-2025-4853960
Google patches two Android zero-days, 120 defects total in September security updateCyberScoop·Sep 3, 15:45 UTC · Sep 3, 2025Vulnerability in the wildCVE-2025-38352CVE-2025-48543CVE-2025-48539+3 CVEs60
Open-source server management platform Proxmox VE 9.0 releasedHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2025Industry55
⚡ Weekly Recap: Scattered Spider Arrests, Car Exploits, macOS Malware, Fortinet RCE and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025RansomwareCVE-2025-25257CVE-2025-25251CVE-2025-31365+36 CVEs160
Security Affairs newsletter Round 529 by Pierluigi PaganiniSecurity Affairs·Jun 22, 15:07 UTC · Jun 22, 2025Ransomware in the wildCVE-2025-3248CVE-2023-28771CVE-2025-2312160
⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreThe Hacker News·May 7, 10:33 UTC · May 7, 2025MalwareCVE-2025-29927CVE-2025-23120CVE-2024-56346+13 CVEs60
⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain BackdoorsThe Hacker News·May 6, 05:03 UTC · May 6, 2025MalwareCVE-2025-3928CVE-2025-1976CVE-2025-46271+33 CVEs60
DARPA believes AI Cyber Challenge could upend patching as the industry knows itCyberScoop·Apr 30, 05:29 UTC · Apr 30, 2025Exploit / PoC in the wild60
U.S. CISA adds SonicWall SMA100 Appliance flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 17, 08:30 UTC · Apr 17, 2025Exploit / PoC in the wildCVE-2021-20035CVE-2024-53197CVE-2024-53150+2 CVEs60
Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)Help Net Security·Apr 11, 10:14 UTC · Apr 11, 2025Vulnerability in the wildCVE-2025-22457CVE-2025-0282CVE-2023-46805+2 CVEs60
Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE MalwareThe Hacker News·Apr 7, 06:39 UTC · Apr 7, 2025Malware in the wildCVE-2025-22457CVE-2024-38657CVE-2025-22467+2 CVEs60
Chinese State Hackers Exploiting Newly Disclosed Ivanti FlawInfosecurity Magazine·Apr 4, 11:04 UTC · Apr 4, 2025Exploit / PoC in the wildCVE-2025-2245760
New Research Reveals Spectre Vulnerability Persists in Latest AMD and Intel ProcessorsThe Hacker News·Oct 29, 05:53 UTC · Oct 29, 2024VulnerabilityCVE-2017-5715CVE-2023-38575CVE-2022-2382460
Nation-state actor exploited three Ivanti CSA zeroSecurity Affairs·Oct 14, 16:58 UTC · Oct 14, 2024Threat actorCVE-2024-9380CVE-2024-8190CVE-2024-8963160
U.S. CISA adds Microsoft Windows MSHTML Platform and Progress WhatsUp Gold bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 17, 09:39 UTC · Sep 17, 2024Exploit / PoC in the wildCVE-2024-43461CVE-2024-6670CVE-2024-38112160
Binarly Transparency Platform 2.5 identifies critical vulnerabilities before they can be exploitedHelp Net Security·Sep 5, 00:00 UTC · Sep 5, 2024Vulnerability55
Security Affairs newsletter Round 486 by Pierluigi PaganiniSecurity Affairs·Aug 25, 07:19 UTC · Aug 25, 2024Ransomware in the wild60
DARPA awards $14 million to semifinal winners of AI code review competitionThe Record·Aug 14, 01:43 UTC · Aug 14, 2024Vulnerability55
DARPA Awards $14m to Seven Teams in AI Cyber ChallengeInfosecurity Magazine·Aug 12, 15:05 UTC · Aug 12, 2024Vulnerability55
Security Affairs newsletter Round 484 by Pierluigi PaganiniSecurity Affairs·Aug 11, 08:18 UTC · Aug 11, 2024Ransomware in the wild60
Sonos Speaker Flaws Could Have Let Remote Hackers Eavesdrop on UsersThe Hacker News·Aug 10, 07:14 UTC · Aug 10, 2024VulnerabilityCVE-2023-50809CVE-2023-50810CVE-2024-2001860
Google says Android zeroThe Record·Aug 6, 17:22 UTC · Aug 6, 2024Exploit / PoC in the wildCVE-2024-3697160
Week in review: CDK Global cyberattack, critical vCenter Server RCE fixedHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2024Vulnerability in the wildCVE-2024-0762CVE-2024-37079CVE-2024-3708060
Federal agency warns critical Linux vulnerability being actively exploitedArs Technica · Security·May 31, 17:38 UTC · May 31, 2024Vulnerability in the wildCVE-2024-108660
China-Linked Group Breaches Networks via Connectwise, F5 Software FlawsThe Hacker News·Mar 23, 05:40 UTC · Mar 23, 2024Exploit / PoCCVE-2023-22518CVE-2024-1709CVE-2023-46747+2 CVEs60
Ivanti Pulse Secure Found Using 11-YearThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21893+1 CVEs60
Featured talks at the upcoming Hack In The Box Security ConferenceHelp Net Security·Nov 20, 13:37 UTC · Nov 20, 2023Exploit / PoC60
SentinelOne integrates with Snyk for end-to-end app securityHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2023RansomwareCVE-2022-049260
Gigamon Precryption technology reveals concealed threat activity in the cloudHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2023Vulnerability55
Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spywareCisco Talos·May 25, 12:02 UTC · May 25, 2023MalwareCVE-2021-37973CVE-2021-37976CVE-2021-38000+2 CVEs60
Critical FortiOS pre-auth RCE vulnerability exploited by attackers (CVE-2022-42475)Help Net Security·Dec 13, 00:00 UTC · Dec 13, 2022Vulnerability in the wildCVE-2022-4247560
Microsoft Patch Tuesday updates fix 6 actively exploited zeroSecurity Affairs·Nov 9, 11:54 UTC · Nov 9, 2022Vulnerability in the wildCVE-2022-41028CVE-2022-41040CVE-2022-41128+4 CVEs60
Your OT Is No Longer Isolated: Act Fast to Protect ItThe Hacker News·Nov 4, 13:12 UTC · Nov 4, 2022Ransomware60