U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
Large-scale cryptocurrency miner campaign targets Russian users with SilentCryptoMinerSecurity Affairs·Mar 10, 10:08 UTC · Mar 10, 2025Malware in the wild60
Over 4,000 ISP IPs Targeted in Brute-Force Attacks to Deploy Info Stealers and CryptominersThe Hacker News·Mar 4, 09:56 UTC · Mar 4, 2025Malware in the wild60
U.S. CISA adds Cleo Harmony, VLTrader, and LexiCom flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 16, 15:09 UTC · Jan 16, 2025Exploit / PoC in the wildCVE-2024-50623160
Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect Secure and Policy SecureThe Hacker News·Jan 11, 06:31 UTC · Jan 11, 2025Vulnerability in the wildCVE-2025-0282CVE-2025-028360
Vulnerability Exploit Assessment Tool EPSS Exposed to Adversarial AttaInfosecurity Magazine·Dec 19, 10:30 UTC · Dec 19, 2024Vulnerability in the wildCVE-2017-123560
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and TipsThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2024Ransomware in the wildCVE-2024-50623CVE-2020-12271CVE-2024-11639+24 CVEs60
Attackers are hijacking Jupyter notebooks to host illegal Champions League streamsCyberScoop·Nov 19, 14:00 UTC · Nov 19, 2024Exploit / PoC in the wild160
North Korean-linked hackers were caught experimenting with new macOS malwareCyberScoop·Nov 12, 14:10 UTC · Nov 12, 2024Malware in the wild60
THN Cybersecurity Recap: Top Threats, Tools and News (Oct 14The Hacker News·Oct 21, 12:11 UTC · Oct 21, 2024Data breach in the wildCVE-2024-38178CVE-2024-9486CVE-2024-44133+7 CVEs60
What I’ve learned in my first 7Cisco Talos·Oct 17, 18:00 UTC · Oct 17, 2024Ransomware in the wildCVE-2024-4304760
Security Affairs newsletter Round 492 by Pierluigi PaganiniSecurity Affairs·Oct 6, 12:05 UTC · Oct 6, 2024Ransomware in the wildCVE-2024-4551960
Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android usersHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2024Exploit / PoC in the wildCVE-2023-45249CVE-2024-3708560
VMware ESXi Flaw Exploited by Ransomware Groups for Admin AccessThe Hacker News·Jul 31, 04:04 UTC · Jul 31, 2024Ransomware in the wildCVE-2024-37085CVE-2023-28252160
Low-level cybercriminals are pouncing on CrowdStrikeCyberScoop·Jul 23, 22:05 UTC · Jul 23, 2024Exploit / PoC in the wild60
Critical Splunk flaw can be exploited to grab passwords (CVE-2024-36991)Help Net Security·Jul 18, 00:00 UTC · Jul 18, 2024Vulnerability in the wildCVE-2024-3699160
Palo Alto Networks Outlines Remediation for Critical PANThe Hacker News·May 1, 06:14 UTC · May 1, 2024Exploit / PoC in the wildCVE-2024-340060
Critical Update: CrushFTP ZeroThe Hacker News·Apr 27, 05:01 UTC · Apr 27, 2024Exploit / PoC in the wildCVE-2024-404060
Palo Alto Networks Releases Urgent Fixes for Exploited PANThe Hacker News·Apr 17, 12:08 UTC · Apr 17, 2024Exploit / PoC in the wildCVE-2024-340060
Palo Alto Networks ZeroInfosecurity Magazine·Apr 15, 15:30 UTC · Apr 15, 2024Exploit / PoC in the wildCVE-2024-340060
Palo Alto Networks warns of zeroThe Record·Apr 12, 14:52 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
Critical Unpatched Ray AI Platform Vulnerability Exploited for Cryptocurrency MiningThe Hacker News·Mar 28, 04:46 UTC · Mar 28, 2024Vulnerability in the wildCVE-2023-4802260
Thousands of companies using Ray framework exposed to cyberattacks, researchers sayThe Record·Mar 26, 18:47 UTC · Mar 26, 2024Ransomware in the wildCVE-2023-48022160
Week in review: Attackers use phishing emails to steal NTLM hashes, Patch Tuesday forecastHelp Net Security·Mar 10, 00:00 UTC · Mar 10, 2024Vulnerability in the wildCVE-2024-20337CVE-2024-23225CVE-2024-23296+6 CVEs60
White House: Use memory-safe programming languages to protect the nationHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2024Exploit / PoC in the wild60
Ivanti Pulse Secure Found Using 11-YearThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21893+1 CVEs60
CISA orders federal agencies to disconnect Ivanti VPN instances by February 2Security Affairs·Feb 1, 19:46 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Multiple malware used in attacks exploiting Ivanti VPN flawsSecurity Affairs·Feb 1, 10:53 UTC · Feb 1, 2024Malware in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
US Government Urges Action to Mitigate Androxgh0st Malware ThreatInfosecurity Magazine·Jan 17, 11:05 UTC · Jan 17, 2024Malware in the wildCVE-2017-9841CVE-2018-15133CVE-2021-4177360
Nation-State Actors Weaponize Ivanti VPN ZeroThe Hacker News·Jan 17, 01:56 UTC · Jan 17, 2024Threat actor in the wildCVE-2023-46805CVE-2024-21887160
CISA adds Apache Superset bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 9, 18:33 UTC · Jan 9, 2024Exploit / PoC in the wildCVE-2023-27524CVE-2023-38203CVE-2023-29300+3 CVEs160
CISA adds Looney Tunables Linux bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:35 UTC · Nov 22, 2023Exploit / PoC in the wildCVE-2023-4911CVE-2017-984160
Kinsing Actors Exploiting Recent Linux Flaw to Breach Cloud EnvironmentsThe Hacker News·Nov 4, 09:18 UTC · Nov 4, 2023Vulnerability in the wildCVE-2023-4911CVE-2023-32315CVE-2017-9841160
NodeStealer Malware Hijacking Facebook Business Accounts for Malicious AdsThe Hacker News·Nov 3, 12:12 UTC · Nov 3, 2023Malware in the wild60
Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129)Help Net Security·Sep 29, 10:48 UTC · Sep 29, 2023Exploit / PoC in the wildCVE-2023-5129CVE-2023-4863CVE-2023-4106460
Vulnerability in popular ‘libwebp’ code more widespread than expectedThe Record·Sep 27, 18:08 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-4863CVE-2023-5129CVE-2023-4106460
Watch out! CVE-2023-5129 in libwebp library affects millions appsSecurity Affairs·Sep 27, 13:35 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-5129CVE-2023-4863CVE-2023-41064+1 CVEs160
How the Cult of the Dead Cow plans to save the internetCyberScoop·Sep 25, 15:52 UTC · Sep 25, 2023Exploit / PoC in the wild60
Hackers Exploit MinIO Storage System Vulnerabilities to Compromise ServersThe Hacker News·Sep 5, 02:55 UTC · Sep 5, 2023Vulnerability in the wildCVE-2023-28432CVE-2023-2843460
Evil_MinIO exploit used in attacks on MinIO Storage SystemsSecurity Affairs·Sep 4, 16:15 UTC · Sep 4, 2023Exploit / PoC in the wildCVE-2023-28434CVE-2023-2843260