Global coalition dismantles Tycoon 2FA phishing kitCyberScoop·Mar 5, 00:01 UTC · Mar 5, 2026Phishing & fraud in the wild60
Hackers target 'hundreds' of Middle East activists with fake login pages, 2FA bypass schemesCyberScoop·Dec 19, 18:47 UTC · Dec 19, 2018Exploit / PoC in the wild60
It finally happened: Criminals exploit SS7 vulnerabilities, prompting concerns about 2FACyberScoop·May 8, 18:32 UTC · May 8, 2017Vulnerability in the wild60
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass FlawsThe Hacker News·Jan 21, 15:42 UTC · Jan 21, 2026Vulnerability in the wildCVE-2026-22844CVE-2025-13927CVE-2025-13928+3 CVEs60
Five-year-old Fortinet FortiOS SSL VPN flaw actively exploitedSecurity Affairs·Dec 25, 19:40 UTC · Dec 25, 2025Ransomware in the wildCVE-2020-12812CVE-2018-13379CVE-2019-559160
⚡ Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-theThe Hacker News·Aug 27, 05:11 UTC · Aug 27, 2025Ransomware in the wildCVE-2018-0171CVE-2025-43300CVE-2025-7353+5 CVEs60
Boing Boing says hacker got around 2FA in breaching its content management systemCyberScoop·Jan 13, 21:56 UTC · Jan 13, 2020Exploit / PoC in the wild60
LastPass vulnerability 'beats the entire purpose' of twoCyberScoop·Apr 20, 22:27 UTC · Apr 20, 2017Vulnerability in the wild60
YubiKey anti-phishing device saw 'huge spike' in orders this yearCyberScoop·Nov 30, 23:39 UTC · Nov 30, 2016Phishing & fraud in the wild60
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devicesHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2022Exploit / PoC in the wildCVE-2022-41033CVE-2022-40684CVE-2022-36067+1 CVEs160
Suspicious withdrawals were indeed a 'security incident,' $30M stolen, Crypto.com saysCyberScoop·Jan 20, 16:20 UTC · Jan 20, 2022Exploit / PoC in the wild60
User data and private messages exposed in Reddit breachCyberScoop·Aug 1, 19:24 UTC · Aug 1, 2018Exploit / PoC in the wild60
DNC pushes employees, campaigns to embrace email security habits ahead of midtermsCyberScoop·Jul 3, 15:30 UTC · Jul 3, 2018Threat actor in the wild60
Most Americans have never heard of multiCyberScoop·Nov 7, 14:00 UTC · Nov 7, 2017Data breach in the wild60
Researchers steal bitcoin by exploiting SS7 vulnerabilitiesCyberScoop·Sep 19, 17:50 UTC · Sep 19, 2017Vulnerability in the wild60
You can now use a physical key to log in to FacebookCyberScoop·Jan 26, 18:58 UTC · Jan 26, 2017Exploit / PoC in the wild60
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreThe Hacker News·Jul 28, 05:26 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-16232CVE-2025-66376CVE-2026-54121+52 CVEs60
Update Now: Critical Zimbra Classic Web Client Flaw Could Expose MailboxesSecurity Affairs·Jul 10, 20:42 UTC · Jul 10, 2026Data breach in the wildCVE-2025-68645CVE-2020-7796CVE-2025-6637660
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197260
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025Security Affairs·Mar 19, 14:48 UTC · Mar 19, 2026Vulnerability in the wildCVE-2025-6637660
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & VibeThe Hacker News·Mar 9, 18:22 UTC · Mar 9, 2026Data breach in the wildCVE-2026-21385CVE-2026-2796CVE-2026-2256+13 CVEs60
Week in review: Notepad++ supply chain attack details and targets, Patch Tuesday forecastHelp Net Security·Feb 8, 00:00 UTC · Feb 8, 2026Vulnerability in the wildCVE-2026-21509CVE-2025-22225CVE-2026-2442360
Russia-Linked APT28 Exploited MDaemon ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2025Threat actor in the wildCVE-2020-12641CVE-2020-35730CVE-2021-44026+3 CVEs60
NFT digital art is already attracting hackersCyberScoop·Mar 15, 22:04 UTC · Mar 15, 2021Exploit / PoC in the wild60
RNC, DNC bank on Duo authentication ahead 2020 electionCyberScoop·Dec 10, 16:55 UTC · Dec 10, 2019Data breach in the wild60
Here's all the security features in the new GmailCyberScoop·Apr 25, 16:37 UTC · Apr 25, 2018Exploit / PoC in the wild60
Severe XSS flaw affects fully patched Internet ExplorerSecurity Affairs·Feb 4, 10:39 UTC · Feb 4, 2015Vulnerability in the wild60
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AIThe Hacker News·Jun 2, 03:39 UTC · Jun 2, 2026Ransomware in the wildCVE-2026-0257CVE-2026-8732CVE-2026-27771+31 CVEs60
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco ZeroThe Hacker News·Mar 20, 04:36 UTC · Mar 20, 2026Advisory in the wildCVE-2025-66376CVE-2026-20963CVE-2026-20131+5 CVEs60
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & MoreThe Hacker News·Dec 31, 05:07 UTC · Dec 31, 2025Malware in the wildCVE-2025-14847CVE-2020-12812CVE-2025-68664+7 CVEs260
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Week in review: Salesloft Drift breach investigation results, malicious GitHub Desktop installersHelp Net Security·Sep 14, 00:00 UTC · Sep 14, 2025Ransomware in the wildCVE-2024-4076660
Is healthcare cybersecurity in critical condition?Help Net Security·Apr 15, 11:44 UTC · Apr 15, 2025Ransomware in the wild60
Week in review: Microsoft fixes many zero-days, malicious droppers on Google Play, IRISSCON 2022Help Net Security·Feb 11, 14:56 UTC · Feb 11, 2025Ransomware in the wildCVE-2022-4109160
GitLab Patches Critical SAML Authentication Bypass Flaw in CE and EE EditionsThe Hacker News·Sep 19, 05:07 UTC · Sep 19, 2024Vulnerability in the wildCVE-2024-45409CVE-2024-27348160