QuaDream surveillance firm's spyware targeted iPhones with zeroSecurity Affairs·Apr 12, 18:20 UTC · Apr 12, 2023Malware55
Silk Typhoon shifted to specifically targeting IT management companiesCyberScoop·Mar 6, 14:54 UTC · Mar 6, 2025Exploit / PoC in the wildCVE-2025-028260
Turkey-Aligned Hackers Targeted Iraq-Based Kurds with ZeroInfosecurity Magazine·May 13, 17:00 UTC · May 13, 2025Exploit / PoC in the wildCVE-2025-27920CVE-2025-2792160
Microsoft patches four exploited zero-days, but lags with fixes for a fifth (CVE-2023-36884)Help Net Security·Aug 4, 09:09 UTC · Aug 4, 2023Exploit / PoC in the wildCVE-2023-36884CVE-2023-32049CVE-2023-35311+2 CVEs160
Iran-linked APT groups started exploiting Papercut flawSecurity Affairs·May 9, 07:00 UTC · May 9, 2023Threat actor in the wildCVE-2023-2735060
Microsoft blames Clop gang for 'MOVEit Transfer' attacksSecurity Affairs·Jun 5, 15:07 UTC · Jun 5, 2023Ransomware in the wildCVE-2023-3436260
Subgroup of Russia’s Sandworm compromising US and European organizations, Microsoft saysThe Record·Feb 12, 18:22 UTC · Feb 12, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Microsoft: Iran is refining its cyber operationsCyberScoop·Feb 7, 05:00 UTC · Feb 7, 2024Ransomware in the wild60
Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026Help Net Security·Feb 11, 00:00 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-21513CVE-2026-21514CVE-2026-21510+3 CVEs160
New Russian state-sponsored APT quickly gains global reach, hitting expansive targetsCyberScoop·May 27, 19:57 UTC · May 27, 2025Threat actor60
CISA warns of potential critical threats following attacks against UkraineSecurity Affairs·Jan 19, 15:46 UTC · Jan 19, 2022Advisory in the wildCVE-2021-3264860
SharePoint ‘ToolShell’ Vulnerabilities Exploited by Chinese HackersInfosecurity Magazine·Jul 22, 15:40 UTC · Jul 22, 2025VulnerabilityCVE-2025-53770CVE-2025-5377160
Microsoft uncovers new variant of XCSSET macOS malware in targeted attacksSecurity Affairs·Sep 26, 19:45 UTC · Sep 26, 2025Malware55
Feds quash widespread Russia-backed espionage network spanning 18,000 devicesCyberScoop·Apr 7, 23:46 UTC · Apr 7, 2026Threat actor in the wild60
Russia-linked APT28 group spotted exploiting Outlook flaw to hijack MS Exchange accountsSecurity Affairs·Dec 5, 14:19 UTC · Dec 5, 2023Threat actorCVE-2023-23397CVE-2023-38831CVE-2021-40444+4 CVEs60
Microsoft SharePoint zero-day attacks pinned on ChinaCyberScoop·Jul 22, 15:54 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
Prestige ransomware targets organizations in Ukraine and PolandSecurity Affairs·Oct 16, 23:22 UTC · Oct 16, 2022Ransomware60
Microsoft patches zero-day actively exploited in string of ransomware attacksCyberScoop·Apr 8, 21:22 UTC · Apr 8, 2025Ransomware in the wildCVE-2025-29824CVE-2025-29792CVE-2025-29793+3 CVEs160
Microsoft seizes RedVDS infrastructure, disrupts fastCyberScoop·Jan 14, 15:00 UTC · Jan 14, 2026Exploit / PoC in the wild60
Microsoft and DOJ seized the attack infrastructure used by RussiaSecurity Affairs·Oct 4, 07:04 UTC · Oct 4, 2024Threat actor60
Sysrv-K, a new variant of the sysrv botnet includes new exploitsSecurity Affairs·May 15, 11:25 UTC · May 15, 2022MalwareCVE-2022-2294760
Microsoft identifies new hacking unit within Russian military intelligenceCyberScoop·Jun 14, 16:06 UTC · Jun 14, 2023Ransomware in the wild60
Microsoft: An organization without a response plan will be hit harder by a security incidentCyberScoop·Aug 8, 16:06 UTC · Aug 8, 2025Exploit / PoC60
US Thwarts DNS Hijacking Network Controlled by Russian APT28 HackersInfosecurity Magazine·Apr 8, 10:03 UTC · Apr 8, 2026Threat actor60
Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation TacticsThe Hacker News·Mar 12, 06:55 UTC · Mar 12, 2025MalwareCVE-2021-3071360
Ransomware Actor Deletes Data and Backups PostInfosecurity Magazine·Aug 28, 09:05 UTC · Aug 28, 2025Ransomware60
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246)Help Net Security·Nov 9, 00:00 UTC · Nov 9, 2023Exploit / PoCCVE-2023-47246CVE-2023-3436260
HITRUST updates Cyber Threat Adaptive engine to address emerging cyber threatsHelp Net Security·May 2, 00:00 UTC · May 2, 2024Vulnerability55
Microsoft opens up coronavirus threat data to the publicCyberScoop·May 14, 22:25 UTC · May 14, 2020Exploit / PoC in the wild160
Threat researchers spot ‘device code’ phishing attacks targeting Microsoft accountsCyberScoop·Feb 14, 21:32 UTC · Feb 14, 2025Phishing & fraud155
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch TuesdayThe Hacker News·Mar 2, 10:36 UTC · Mar 2, 2026VulnerabilityCVE-2026-21513CVE-2026-21509160
Microsoft’s head of threat intelligence leaves to join DragosCyberScoop·Jan 4, 12:43 UTC · Jan 4, 2017Exploit / PoC in the wild60
URGENT — 4 Actively Exploited 0The Hacker News·Mar 3, 07:56 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Storm-2603 spotted deploying ransomware on exploited SharePoint serversHelp Net Security·Aug 4, 12:44 UTC · Aug 4, 2025Ransomware in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+2 CVEs160
Microsoft patches zero-days used by state-sponsored and ransomware threat actors (CVE-2023-23397, CVE-2023-24880)Help Net Security·Mar 14, 00:00 UTC · Mar 14, 2023Ransomware in the wildCVE-2023-23397CVE-2023-24880CVE-2022-44698+3 CVEs60
China Poised to Disrupt US Critical Infrastructure with CyberInfosecurity Magazine·Oct 5, 14:00 UTC · Oct 5, 2023Ransomware60
November 2023 Patch Tuesday forecast: Year 21 beginsHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2023VulnerabilityCVE-2023-22515CVE-2023-2251860
Microsoft pins GoAnywhere zero-day attacks to ransomware affiliate StormCyberScoop·Oct 7, 20:44 UTC · Oct 7, 2025Ransomware in the wildCVE-2025-1003560