Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026The Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-3462160
Unpublished security flaws (0days) massively exploitedSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Critical Magento 2 flaw exploited within 16 hoursSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Exploit / PoC60
Novel WebRTC skimmer bypasses security controls at $100+ billion car makerSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Data breach in the wild60
Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621)Help Net Security·Apr 13, 00:00 UTC · Apr 13, 2026Exploit / PoC in the wildCVE-2026-3462160
Acrobat Reader zero-day exploited in the wild for many months (CVE-2026-34621)Help Net Security·Apr 12, 14:38 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-3462160
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025The Hacker News·Apr 12, 04:25 UTC · Apr 12, 2026Exploit / PoCCVE-2026-3462160
Malicious PDF reveals active Adobe Reader zeroSecurity Affairs·Apr 9, 19:14 UTC · Apr 9, 2026Data breach60
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting InternetThe Hacker News·Apr 8, 11:44 UTC · Apr 8, 2026Malware in the wild60
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances ExposedThe Hacker News·Apr 7, 05:56 UTC · Apr 7, 2026Vulnerability in the wildCVE-2025-59528CVE-2025-8943CVE-2025-2631960
Attack on axios software developer tool threatens widespread compromisesCyberScoop·Mar 31, 18:24 UTC · Mar 31, 2026Data breach in the wild160
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
Claude Code Security and Magecart: Getting the Threat Model RightThe Hacker News·Mar 18, 11:58 UTC · Mar 18, 2026Data breach60
ClawJacked flaw exposed OpenClaw users to data theftSecurity Affairs·Mar 2, 09:42 UTC · Mar 2, 2026Exploit / PoC60
Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API EnablementThe Hacker News·Feb 28, 17:01 UTC · Feb 28, 2026Exploit / PoC in the wild60
Flaws in Popular IDE Extensions Allow Data ExfiltrationInfosecurity Magazine·Feb 19, 10:45 UTC · Feb 19, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-6571560
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious WorkflowsThe Hacker News·Feb 6, 09:39 UTC · Feb 6, 2026VulnerabilityCVE-2026-25049CVE-2025-68613CVE-2026-21893+10 CVEs160
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code ExecutionThe Hacker News·Jan 29, 06:05 UTC · Jan 29, 2026VulnerabilityCVE-2026-22709CVE-2022-36067CVE-2023-29017+5 CVEs160
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source CodeThe Hacker News·Jan 26, 16:53 UTC · Jan 26, 2026Exploit / PoCCVE-2025-69264CVE-2025-6926360
CISA’s secure-software buying tool had a simple XSS vulnerability of its ownCyberScoop·Jan 15, 22:47 UTC · Jan 15, 2026Vulnerability in the wild160
CodeBuild Flaw Put AWS Console Supply Chain At RiskInfosecurity Magazine·Jan 15, 15:00 UTC · Jan 15, 2026Vulnerability in the wild160
Microsoft Fixes Three ZeroInfosecurity Magazine·Dec 10, 09:45 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62221CVE-2025-54100CVE-2025-64671+4 CVEs60
Unpatched Windows vulnerability continues to be exploited by APTs (CVE-2025-9491)Help Net Security·Dec 5, 09:00 UTC · Dec 5, 2025VulnerabilityCVE-2025-949160
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or UyghursThe Hacker News·Nov 24, 11:08 UTC · Nov 24, 2025Vulnerability55
North Korea’s Fraudulent IT Employment Scheme: A Cybersecurity ThreatRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Phishing & fraud55
Hackers Exploit Milesight Routers to Send Phishing SMS to European UsersThe Hacker News·Oct 2, 06:34 UTC · Oct 2, 2025Phishing & fraud in the wildCVE-2023-4326160
TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel AttacksThe Hacker News·Sep 17, 18:30 UTC · Sep 17, 2025MalwareCVE-2017-019960
⚡ Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-theThe Hacker News·Aug 27, 05:11 UTC · Aug 27, 2025Ransomware in the wildCVE-2018-0171CVE-2025-43300CVE-2025-7353+5 CVEs60
Malware Complexity Jumps 127% in Six MonthsInfosecurity Magazine·Aug 6, 14:00 UTC · Aug 6, 2025Malware55
Cursor AI Code Editor Vulnerability Enables RCE via Malicious MCP File Swaps Post ApprovalThe Hacker News·Aug 5, 13:04 UTC · Aug 5, 2025VulnerabilityCVE-2025-54136160
Phishing campaign targets U.S. Department of Education's G5 portalHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2025Threat actor60
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
AI Cloaking Tools Enable Harder-to-Detect CyberInfosecurity Magazine·Jul 17, 14:00 UTC · Jul 17, 2025Malware55
CVE-2025-6554 marks the fifth actively exploited Chrome ZeroSecurity Affairs·Jul 16, 10:11 UTC · Jul 16, 2025Vulnerability in the wildCVE-2025-6554CVE-2025-6558CVE-2025-7656+4 CVEs60
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 11, 07:47 UTC · Jul 11, 2025Exploit / PoC in the wildCVE-2025-655460
CVE-2025-6554 is the fourth Chrome zeroSecurity Affairs·Jul 2, 08:21 UTC · Jul 2, 2025Vulnerability in the wildCVE-2025-6554CVE-2025-5419CVE-2025-4664+1 CVEs60