Hackers Used AI to Develop First Known ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC160
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal CredentialsThe Hacker News·May 1, 16:27 UTC · May 1, 2026Ransomware57
Anti-DDoS Firm Heaped Attacks on Brazilian ISPsKrebs on Security·Apr 30, 15:36 UTC · Apr 30, 2026VulnerabilityCVE-2023-138935
Attackers use MS Teams, fake mailbox repair utility to breach organizationsHelp Net Security·Apr 27, 00:00 UTC · Apr 27, 2026Vulnerability55
25 Open-Source Cybersecurity Tools That Don’T Care About Your BudgetHelp Net Security·Apr 27, 00:00 UTC · Apr 27, 2026Vulnerability30
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer TokensThe Hacker News·Apr 24, 17:03 UTC · Apr 24, 2026Data breach157
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container EscapeThe Hacker News·Apr 22, 07:16 UTC · Apr 22, 2026VulnerabilityCVE-2026-5752160
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain IncidentThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026RansomwareCVE-2026-3363460
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsThe Hacker News·Apr 6, 06:40 UTC · Apr 6, 2026Vulnerability142
TeamPCP Explores Ways to Exploit Stolen Supply Chain SecretsInfosecurity Magazine·Mar 31, 12:15 UTC · Mar 31, 2026Ransomware57
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of DisclosureThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
Malicious LiteLLM versions linked to TeamPCP supply chain attackSecurity Affairs·Mar 25, 08:50 UTC · Mar 25, 2026Data breach57
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious WorkflowsThe Hacker News·Feb 6, 09:39 UTC · Feb 6, 2026VulnerabilityCVE-2026-25049CVE-2025-68613CVE-2026-21893+10 CVEs160
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux HostsThe Hacker News·Jan 24, 08:06 UTC · Jan 24, 2026Malware42
Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL SideloadingThe Hacker News·Jan 20, 13:46 UTC · Jan 20, 2026Malware55
Transparent Tribe Launches New RAT Attacks Against Indian Government and AcademiaThe Hacker News·Jan 6, 05:33 UTC · Jan 6, 2026Malware42
VVS Stealer Uses Advanced Obfuscation to Target Discord UsersInfosecurity Magazine·Jan 5, 16:00 UTC · Jan 5, 2026Malware42
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web ManagerCisco Talos·Dec 17, 16:55 UTC · Dec 17, 2025Malware42
Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware PayloadsThe Hacker News·Dec 12, 18:50 UTC · Dec 12, 2025Malware30
Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government TargetsThe Hacker News·Dec 2, 05:34 UTC · Dec 2, 2025Malware42
ThreatsDay Bulletin: $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & MoreThe Hacker News·Oct 23, 14:22 UTC · Oct 23, 2025Ransomware57
ShadowV2 Botnet Exposes Rise of DDoS-as-aInfosecurity Magazine·Sep 24, 16:00 UTC · Sep 24, 2025Malware30
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 20, 13:38 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-2525760
Fortinet FortiWeb flaw CVE-2025Security Affairs·Jul 19, 16:25 UTC · Jul 19, 2025Exploit / PoC in the wildCVE-2025-2525760
Patch immediately: CVE-2025-25257 PoC enables remote code execution on Fortinet FortiWebSecurity Affairs·Jul 13, 18:10 UTC · Jul 13, 2025Exploit / PoC in the wildCVE-2025-2525760
New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing ChainsThe Hacker News·Jun 19, 16:44 UTC · Jun 19, 2025Malware30
News Flodrix botnet targets vulnerable Langflow serversSecurity Affairs·Jun 18, 10:43 UTC · Jun 18, 2025Malware in the wildCVE-2025-324860
Cryptojacking Campaign Exploits DevOps APIs Using Off-theThe Hacker News·Jun 3, 07:04 UTC · Jun 3, 2025Threat actorCVE-2020-14144160
Duping Cloud Functions: An emerging serverless attack vectorCisco Talos·May 20, 10:00 UTC · May 20, 2025Vulnerability30
New Malware on PyPI Poses Threat to OpenInfosecurity Magazine·May 19, 16:45 UTC · May 19, 2025Malware42
⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and MoreThe Hacker News·May 19, 14:35 UTC · May 19, 2025Exploit / PoC in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+22 CVEs60
Hugging Face platform continues to be plagued by vulnerable ‘pickles’CyberScoop·Feb 6, 16:34 UTC · Feb 6, 2025Exploit / PoC in the wild60
Cross-Platform JavaScript Stealer Targets Crypto Wallets in New Lazarus Group CampaignThe Hacker News·Feb 6, 04:40 UTC · Feb 6, 2025Malware42
Kali Linux 2024.4 released! 14 new shiny tools addedHelp Net Security·Dec 17, 00:00 UTC · Dec 17, 2024Vulnerability30
NodeStealer Malware Targets Facebook Ad Accounts, Harvesting Credit Card DataThe Hacker News·Nov 22, 04:34 UTC · Nov 22, 2024Malware30
North Korea Hackers Leverage Flutter to Deliver macOS MalwareInfosecurity Magazine·Nov 12, 13:00 UTC · Nov 12, 2024Malware30
Cyberattackers Exploit Google Sheets for Malware Control in Likely Espionage CampaignThe Hacker News·Oct 25, 05:16 UTC · Oct 25, 2024Malware42
Detecting vulnerable code in software dependencies is more complex than it seemsHelp Net Security·Sep 18, 00:00 UTC · Sep 18, 2024Vulnerability30