Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, TelecomsThe Hacker News·Jul 3, 09:25 UTC · Jul 3, 2025Exploit / PoC in the wildCVE-2024-8963CVE-2024-9380CVE-2024-819060
Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh serversHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-24016CVE-2025-43200+1 CVEs60
CISA warns of SimpleHelp ransomware compromises after string of retail attacksThe Record·Jun 13, 14:12 UTC · Jun 13, 2025RansomwareCVE-2024-5772760
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 12, 09:17 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-24016CVE-2025-3305360
Security Affairs newsletter Round 526 by Pierluigi PaganiniSecurity Affairs·Jun 8, 11:24 UTC · Jun 8, 2025Data breachCVE-2025-5054CVE-2025-4598CVE-2025-442860
Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global RegionsThe Hacker News·Jun 2, 10:08 UTC · Jun 2, 2025VulnerabilityCVE-2017-1188235
Initial Access Brokers Target Brazil Execs via NFThe Hacker News·May 9, 11:40 UTC · May 9, 2025VulnerabilityCVE-2017-1188247
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
⚡ Weekly Recap: Critical SAP Exploit, AI-Powered Phishing, Major Breaches, New CVEs & MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Phishing & fraudCVE-2025-31324CVE-2024-58136CVE-2025-32432+16 CVEs60
RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed ControlThe Hacker News·May 1, 10:52 UTC · May 1, 2025Ransomware60
IR Trends Q1 2025: Phishing soars as identityCisco Talos·Apr 28, 10:00 UTC · Apr 28, 2025Phishing & fraud42
Iranian Hackers Deploy New BugSleep Backdoor in Middle East Cyber AttacksThe Hacker News·Apr 17, 11:00 UTC · Apr 17, 2025Malware42
Network Edge Devices the Biggest Entry Point for Attacks on SMBsInfosecurity Magazine·Apr 17, 09:30 UTC · Apr 17, 2025Ransomware57
Phishing Campaigns Use Real-Time Checks to Validate Victim Emails Before Credential TheftThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2025Threat actor57
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell ToolThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2025MalwareCVE-2024-8963CVE-2024-9380CVE-2024-8190+2 CVEs160
RansomHub affiliate leverages multi-function Betruger backdoorHelp Net Security·Apr 2, 08:48 UTC · Apr 2, 2025RansomwareCVE-2022-24521CVE-2023-2753260
RansomHub affiliate uses custom backdoor BetrugerSecurity Affairs·Mar 21, 11:25 UTC · Mar 21, 2025RansomwareCVE-2022-24521CVE-2023-2753260
Medusa Ransomware Hits 40+ Victims in 2025, Demands $100KThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025RansomwareCVE-2024-1709CVE-2023-4878860
CISA, FBI Warn of Medusa Ransomware Impacting Critical InfrastructureInfosecurity Magazine·Mar 13, 16:30 UTC · Mar 13, 2025RansomwareCVE-2024-1709CVE-2023-4878860
Medusa ransomware hit over 300 critical infrastructure organizations until February 2025Security Affairs·Mar 13, 08:49 UTC · Mar 13, 2025RansomwareCVE-2024-1709CVE-2023-4878860
CISA: More than 300 critical infrastructure orgs attacked by Medusa ransomwareThe Record·Mar 12, 20:06 UTC · Mar 12, 2025RansomwareCVE-2024-1709CVE-2023-4878860
Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal ConflictsThe Hacker News·Feb 27, 05:08 UTC · Feb 27, 2025Ransomware in the wildCVE-2024-50623CVE-2009-3960CVE-2010-2861+8 CVEs60
Russian Seashell Blizzard Enlists Specialist Initial Access Subgroup tInfosecurity Magazine·Feb 13, 12:00 UTC · Feb 13, 2025Vulnerability55
Sandworm APT's initial access subgroup hits organizations accross the globeHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2025Threat actorCVE-2021-34473CVE-2022-41352CVE-2023-32315+4 CVEs160
Hackers Exploiting SimpleHelp RMM Flaws for Persistent Access and RansomwareThe Hacker News·Feb 7, 05:20 UTC · Feb 7, 2025RansomwareCVE-2024-57726CVE-2024-57727CVE-2024-5772860
Black Basta Ransomware Evolves with Email Bombing, QR Codes, and Social EngineeringThe Hacker News·Dec 9, 17:44 UTC · Dec 9, 2024Ransomware57
RansomHub Overtakes LockBit as Most Prolific Ransomware GroupInfosecurity Magazine·Oct 17, 11:00 UTC · Oct 17, 2024Ransomware57
A new variant of Cicada ransomware targets VMware ESXi systemsSecurity Affairs·Sep 2, 07:06 UTC · Sep 2, 2024Ransomware57
Security Affairs Malware NewsletterSecurity Affairs·Jul 14, 16:54 UTC · Jul 14, 2024MalwareCVE-2021-4044447
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPsCisco Talos·Jul 10, 10:00 UTC · Jul 10, 2024Ransomware60
Edge services are extremely attractive targets to attackersHelp Net Security·Jun 18, 00:00 UTC · Jun 18, 2024Ransomware in the wild60
WithSecure Reveals Mass Exploitation of Edge SoftwareInfosecurity Magazine·Jun 12, 16:30 UTC · Jun 12, 2024Ransomware in the wild60
NextGen Healthcare Mirth Connect Under AttackThe Hacker News·May 21, 16:00 UTC · May 21, 2024Exploit / PoC in the wildCVE-2023-43208CVE-2023-37679CVE-2024-1709+5 CVEs60
Windows Quick Assist Exploited in Ransomware AttacksInfosecurity Magazine·May 16, 17:15 UTC · May 16, 2024Ransomware57
Black Basta Ransomware Strikes 500+ Entities Across North America, Europe, and AustraliaThe Hacker News·May 15, 00:00 UTC · May 15, 2024RansomwareCVE-2020-1472CVE-2021-42278CVE-2021-42287+2 CVEs160
Ongoing Campaign Bombards Enterprises with Spam Emails and Phone CallsThe Hacker News·May 15, 00:00 UTC · May 15, 2024Threat actor157
Black Basta ransomware group is imperiling critical infrastructure, groups warnArs Technica · Security·May 15, 00:00 UTC · May 15, 2024RansomwareCVE-2020-1472CVE-2021-42278CVE-2021-42287+1 CVEs60
After Ascension ransomware attack, feds issue alert on Black Basta groupThe Record·May 10, 22:32 UTC · May 10, 2024RansomwareCVE-2024-170960
Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing AttacksThe Hacker News·Mar 26, 03:55 UTC · Mar 26, 2024Phishing & fraud42