Reducing abuse of Microsoft 365 Exchange Online’s Direct SendCisco Talos·Oct 21, 10:00 UTC · Oct 21, 2025Exploit / PoC60
Phishing Dominates as Initial Entry Method for CyberInfosecurity Magazine·Jul 28, 13:00 UTC · Jul 28, 2026Phishing & fraud130
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0The Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026VulnerabilityCVE-2026-2084147
Imperva observed a new variant of the Mirai botnet unleashes 54Security Affairs·Mar 30, 05:33 UTC · Mar 30, 2017Malware30
Why good security foundations are better than the best security mitigationHelp Net Security·Jun 19, 11:56 UTC · Jun 19, 2018Exploit / PoC60
Week in review: 2 threat actors exploiting WinRAR 0-day, Microsoft fixes “BadSuccessor” Kerberos flawHelp Net Security·Aug 17, 00:00 UTC · Aug 17, 2025Threat actor in the wildCVE-2025-8088CVE-2025-53779CVE-2025-8875+4 CVEs60
Exfiltration malware takes center stage in cybersecurity concernsHelp Net Security·Jan 9, 11:55 UTC · Jan 9, 2024Malware55
LogoFAIL: UEFI Vulnerabilities Expose Devices to Stealth Malware AttacksThe Hacker News·Dec 7, 07:08 UTC · Dec 7, 2023Vulnerability30
The growing abuse of QR codes in malware and payment scams prompts FTC warningArs Technica · Security·Dec 12, 01:48 UTC · Dec 12, 2023Malware30
Splunk releases Splunk Connected Experiences and Splunk Business FlowHelp Net Security·May 3, 00:00 UTC · May 3, 2019Tools55
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass ChecksThe Hacker News·Jun 30, 09:27 UTC · Jun 30, 2026VulnerabilityCVE-2024-38271CVE-2024-38272CVE-2024-10668135
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
Hackers From China Target Vietnamese Military and GovernmentThe Hacker News·Apr 6, 07:47 UTC · Apr 6, 2021Malware42
Researchers warn of 'vast' new IoT botnetCyberScoop·Oct 20, 21:15 UTC · Oct 20, 2017Malware in the wildCVE-2017-822560
Cursor’s AI coding agent morphed ‘into local shell’ with oneCyberScoop·Aug 1, 19:51 UTC · Aug 1, 2025Exploit / PoC in the wildCVE-2025-5413560
Protecting patient data starts with knowing where it's storedHelp Net Security·Jun 6, 00:00 UTC · Jun 6, 2025Ransomware60
Barracuda thought it drove 0-day hackers out of customers’ networks. It was wrong.Ars Technica · Security·Aug 30, 17:31 UTC · Aug 30, 2023VulnerabilityCVE-2023-286860
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Google Adds New Pixel Security Features to Block 2G Exploits and Baseband AttacksThe Hacker News·Oct 4, 06:25 UTC · Oct 4, 2024Vulnerability55
Mobile privacy audits are getting harderHelp Net Security·Feb 6, 00:00 UTC · Feb 6, 2026Policy & legal30
From Box to Backdoor: Discovering Just How Insecure an ICS Device is in Only 2 WeeksCisco Talos·Apr 10, 16:11 UTC · Apr 10, 2017MalwareCVE-2016-8712CVE-2016-8721CVE-2016-8718+1 CVEs60
Hugging Face, the GitHub of AI, hosted code that backdoored user devicesArs Technica · Security·Mar 1, 18:02 UTC · Mar 1, 2024Malware42
Evolution of Zanubis, a banking Trojan for AndroidKaspersky Securelist·May 28, 10:00 UTC · May 28, 2025Malware30
Philippine military company spied upon with new ChinaThe Record·Sep 12, 19:24 UTC · Sep 12, 2025Malware42
Chrome Limits Websites' Direct Access to Private Networks for Security ReasonsThe Hacker News·Jan 18, 04:53 UTC · Jan 18, 2022Exploit / PoC in the wild60
Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users DownloadedThe Hacker News·Jun 5, 06:40 UTC · Jun 5, 2026Threat actor45
Nimbuspwn Linux Bugs Could Provide Root AccessInfosecurity Magazine·Apr 27, 09:30 UTC · Apr 27, 2022Ransomware in the wildCVE-2022-29799CVE-2022-2980060
Zenly Bugs Exposed Users to Data Loss and Account TakeoverInfosecurity Magazine·Feb 25, 09:45 UTC · Feb 25, 2022Vulnerability30
Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP UpdateThe Hacker News·Nov 27, 15:37 UTC · Nov 27, 2025Vulnerability30
New infosec products of the week: April 17, 2026Help Net Security·Apr 17, 00:00 UTC · Apr 17, 2026Policy & legal55
Today's cars are mobile data centers, and that data needs to be protectedHelp Net Security·Oct 1, 00:00 UTC · Oct 1, 2021Policy & legal55
New TCESB Malware Found in Active Attacks Exploiting ESET Security ScannerThe Hacker News·Apr 9, 14:05 UTC · Apr 9, 2025MalwareCVE-2024-11859CVE-2021-36276CVE-2021-2155135
Cycldek: Bridging the (air) gapKaspersky Securelist·Jun 3, 10:00 UTC · Jun 3, 2020VulnerabilityCVE-2012-0158CVE-2017-11882CVE-2018-0802135
IR Trends Q2 2025: Phishing attacks persist as actors leverage compromised valid accounts to enhance legitimacyCisco Talos·Jul 31, 10:00 UTC · Jul 31, 2025Phishing & fraud42
Microsoft unveils Project Ire: AI that autonomously detects malwareSecurity Affairs·Aug 7, 11:09 UTC · Aug 7, 2025Malware42
New Win-DDoS Flaws Let Attackers Turn Public Domain Controllers into DDoS Botnet via RPC, LDAPThe Hacker News·Aug 17, 08:43 UTC · Aug 17, 2025MalwareCVE-2025-26673CVE-2025-32724CVE-2025-49716+2 CVEs135
China-linked Red Menshen APT deploys stealthy BPFDoor implants in telecom networksSecurity Affairs·Mar 27, 06:16 UTC · Mar 27, 2026Malware55
Research Spotlight: Project FTRCisco Talos·Apr 1, 05:40 UTC · Apr 1, 2015VulnerabilityCVE-2016-040135
Eavesdropping Bugs in MediaTek Chips Affect 37% of All Smartphones and IoT GloballyThe Hacker News·Nov 25, 04:50 UTC · Nov 25, 2021VulnerabilityCVE-2021-0661CVE-2021-0662CVE-2021-0663+1 CVEs35
Friday Squid Blogging: 1874 Giant Squid AttackSchneier on Security·Jan 27, 14:15 UTC · Jan 27, 2020Malware42