⚡ Weekly Recap: APT Campaigns, Browser Hijacks, AI Malware, Cloud Breaches and Critical CVEsThe Hacker News·May 26, 13:00 UTC · May 26, 2025MalwareCVE-2025-4427CVE-2025-4428CVE-2025-34025+7 CVEs60
⚡ Weekly Recap: Windows 0-Day, VPN Exploits, Weaponized AI, Hijacked Antivirus and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-29824CVE-2024-11859CVE-2025-3102+17 CVEs60
Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active ExploitationThe Hacker News·Feb 12, 10:28 UTC · Feb 12, 2025Vulnerability in the wildCVE-2025-21391CVE-2025-21418CVE-2024-38193+4 CVEs60
Malicious Go Package Exploits Module Mirror Caching for Persistent Remote AccessThe Hacker News·Feb 6, 03:47 UTC · Feb 6, 2025Vulnerability42
Two ransomware groups abuse Microsoft’s Office 365 platform to gain access to target organizationsSecurity Affairs·Jan 22, 20:49 UTC · Jan 22, 2025Ransomware157
U.S. Charges Chinese Hacker for Exploiting ZeroThe Hacker News·Jan 7, 09:22 UTC · Jan 7, 2025Ransomware in the wildCVE-2020-12271CVE-2022-1040CVE-2022-129260
Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039)Help Net Security·Nov 26, 13:25 UTC · Nov 26, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-43639+3 CVEs60
Google OSS-Fuzz Harnesses AI to Expose 26 Security VulnerabilitiesInfosecurity Magazine·Nov 21, 14:45 UTC · Nov 21, 2024VulnerabilityCVE-2024-914335
Oracle Linux 9 Update 5 brings security updates, OpenJDK 17, .NET 9.0Help Net Security·Nov 20, 00:00 UTC · Nov 20, 2024Vulnerability55
Google Researchers Claim First Vulnerability Found Using AIInfosecurity Magazine·Nov 4, 15:00 UTC · Nov 4, 2024Vulnerability55
OpenWrt dominates, but vulnerabilities persist in OT/IoT router firmwareHelp Net Security·Aug 7, 00:00 UTC · Aug 7, 2024Vulnerability55
Splunk fixed tens of flaws in Splunk Enterprise and Cloud PlatformSecurity Affairs·Jul 4, 09:06 UTC · Jul 4, 2024Exploit / PoC in the wildCVE-2024-36985CVE-2024-36984CVE-2024-36997+12 CVEs60
Enhancing security through collaboration with the open-source communityHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2024Vulnerability42
Digging Inside Azure Functions: HyperV Is the Last Line of DefensePalo Alto Unit 42·Jun 5, 17:09 UTC · Jun 5, 2024Vulnerability30
Too many ICS assets are exposed to the public internetHelp Net Security·May 17, 00:00 UTC · May 17, 2024Exploit / PoC60
Unpatchable vulnerability in Apple chip leaks secret encryption keysArs Technica · Security·Mar 21, 14:40 UTC · Mar 21, 2024Vulnerability30
Transitioning to memory-safe languages: Challenges and considerationsHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2024Vulnerability155
Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass ExploitationThe Hacker News·Feb 6, 14:36 UTC · Feb 6, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2024-21887CVE-2023-36661+1 CVEs60
New Linux Ransomware Strain BlackSuit Shows Striking Similarities to RoyalThe Hacker News·Jan 24, 04:28 UTC · Jan 24, 2024Ransomware57
Legit Security Legitify detects security and compliance issues across GitHub assetsHelp Net Security·Jan 11, 12:01 UTC · Jan 11, 2024Vulnerability42
Sea Turtle Cyber Espionage Campaign Targets Dutch IT and Telecom CompaniesThe Hacker News·Jan 6, 08:19 UTC · Jan 6, 2024Threat actor57
LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break InThe Hacker News·Nov 22, 11:59 UTC · Nov 22, 2023RansomwareCVE-2023-496660
Vulnerability in code library allows attackers to work out private RSA keysHelp Net Security·Nov 21, 07:43 UTC · Nov 21, 2023VulnerabilityCVE-2017-1536135
Vulnerabilities in cryptographic libraries found through modern fuzzingHelp Net Security·Nov 6, 12:12 UTC · Nov 6, 2023VulnerabilityCVE-2022-43974CVE-2022-4290547
“This vulnerability is now under mass exploitation.” Citrix Bleed bug bites hardArs Technica · Security·Oct 30, 21:39 UTC · Oct 30, 2023Vulnerability in the wild60
Cryptographic Flaw in Libbitcoin Explorer Cryptocurrency WalletSchneier on Security·Aug 15, 00:00 UTC · Aug 15, 2023Malware42
Downfall attacks can gather passwords, encryption keys from Intel processorsHelp Net Security·Aug 9, 00:00 UTC · Aug 9, 2023VulnerabilityCVE-2022-40982CVE-2023-20593CVE-2023-2056935
SandboxAQ launches open-source meta-library of cryptographic algorithmsHelp Net Security·Aug 9, 00:00 UTC · Aug 9, 2023Tools55
Qualys unveils first-party software risk management solutionHelp Net Security·Aug 3, 00:00 UTC · Aug 3, 2023Exploit / PoC60
Taking over Milesight UR32L routers behind a VPN: 22 vulnerabilities and a full chainCisco Talos·Jul 6, 15:38 UTC · Jul 6, 2023VulnerabilityCVE-2023-22319CVE-2023-2390247
Fluhorse: Flutter-Based Android Malware Targets Credit Cards and 2FA CodesThe Hacker News·Jun 29, 13:40 UTC · Jun 29, 2023Malware30
Experts found hundreds of devices within federal networks having internetSecurity Affairs·Jun 27, 14:07 UTC · Jun 27, 2023Vulnerability in the wild60
Tanium strengthens threat identification capabilities and enhances endpoint reachHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2023Exploit / PoC60
If you bought an iPhone after 2017, update it now, CISA saysThe Record·Mar 28, 17:46 UTC · Mar 28, 2023Ransomware in the wildCVE-2023-21715CVE-2023-21823CVE-2023-2337660
China-linked APT likely linked to Fortinet zeroSecurity Affairs·Mar 17, 19:35 UTC · Mar 17, 2023Exploit / PoCCVE-2022-4132860
Amazon Linux 2023: Create and execute cloud-based applications with enhanced securityHelp Net Security·Mar 16, 00:00 UTC · Mar 16, 2023AI tools & infra30