RussianTA488 Returns With Persistent Outlook Web Access AttackInfosecurity Magazine·Jul 29, 15:10 UTC · Jul 29, 2026Exploit / PoCCVE-2026-4289760
U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 16, 17:31 UTC · May 16, 2026Exploit / PoC in the wildCVE-2026-4289760
CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zeroSecurity Affairs·May 15, 14:04 UTC · May 15, 2026Vulnerability in the wildCVE-2026-42897CVE-2023-21529160
⚡ Weekly Recap: iPhone Spyware, Microsoft 0-Day, TokenBreak Hack, AI Data Leaks and MoreThe Hacker News·Oct 28, 08:29 UTC · Oct 28, 2025Malware in the wildCVE-2025-43200CVE-2025-32711CVE-2025-33053+24 CVEs260
Microsoft Patch TuesdayCisco Talos·Mar 14, 21:26 UTC · Mar 14, 2017Vulnerability in the wildCVE-2017-0149CVE-2017-0012CVE-2017-0037+1 CVEs60
Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthSecurity Affairs·Jul 14, 21:33 UTC · Jul 14, 2026Vulnerability in the wildCVE-2026-56155CVE-2026-56164CVE-2026-57092+5 CVEs60
Microsoft Patch TuesdayCisco Talos·Sep 8, 11:17 UTC · Sep 8, 2015VulnerabilityCVE-2015-2542CVE-2015-2513CVE-2015-2514+19 CVEs60
Discovering Exchange Servers: Leveling the Field Using Attack Surface IntelligenceRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025VulnerabilityCVE-2021-2685560
A Deep Dive on the Recent Widespread DNS Hijacking AttacksKrebs on Security·Feb 18, 14:50 UTC · Feb 18, 2019Threat actor60
At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email SoftwareKrebs on Security·Mar 29, 08:27 UTC · Mar 29, 2021Exploit / PoC60
SolarWinds hackers' capabilities include bypassing MFAHelp Net Security·Dec 16, 00:00 UTC · Dec 16, 2020Data breach60
⚡ Weekly Recap: Airline Hacks, Citrix 0-Day, Outlook Malware, Banking Trojans and moreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Malware in the wildCVE-2025-6543CVE-2025-5777CVE-2025-49825+23 CVEs60
⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & MoreThe Hacker News·Oct 6, 11:38 UTC · Oct 6, 2025RansomwareCVE-2025-61882CVE-2025-27915CVE-2025-4008+16 CVEs60
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking CampaignThe Hacker News·Apr 8, 16:11 UTC · Apr 8, 2026Threat actorCVE-2023-50224160
China’s PLA Unit 61419 Purchasing Foreign Antivirus Products, Likely for ExploitationRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Data breach60
Microsoft Patch TuesdayCisco Talos·Jan 12, 21:17 UTC · Jan 12, 2016VulnerabilityCVE-2016-0002CVE-2016-0005CVE-2016-0003+17 CVEs60
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News·Jul 30, 07:40 UTC · Jul 30, 2026Data breachCVE-2026-42897CVE-2025-6637660
No, I Did Not Hack Your MS Exchange ServerKrebs on Security·Mar 28, 18:16 UTC · Mar 28, 2021Exploit / PoC in the wild60
Qualys brings web application security automation to a new levelHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2017Vulnerability55
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persistCisco Talos·Apr 22, 10:00 UTC · Apr 22, 2026Phishing & fraud55
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ CountriesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Sandworm APT's initial access subgroup hits organizations accross the globeHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2025Threat actorCVE-2021-34473CVE-2022-41352CVE-2023-32315+4 CVEs160
Microsoft Bug Allowed Hackers to Breach Over Two Dozen Organizations via Forged Azure AD TokensThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2023Exploit / PoC in the wild160
Laundry Bear's new Microsoft Exchange attack triggers on email open (CVE-2026-42897)Help Net Security·Jul 30, 00:00 UTC · Jul 30, 2026VulnerabilityCVE-2026-4289760
A Basic Timeline of the Exchange Mass-HackKrebs on Security·Mar 8, 16:45 UTC · Mar 8, 2021Ransomware60
Microsoft Exchange ProxyToken flaw can allow attackers to read your emailsSecurity Affairs·Aug 31, 10:16 UTC · Aug 31, 2021Exploit / PoCCVE-2021-3376660
Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverageCisco Talos·Oct 9, 18:38 UTC · Oct 9, 2018VulnerabilityCVE-2018-8491CVE-2018-8460CVE-2018-8509+26 CVEs60
Microsoft Patch Tuesday, March 2021 EditionKrebs on Security·Mar 10, 05:36 UTC · Mar 10, 2021Vulnerability in the wildCVE-2021-2641160
Microsoft recalls Exchange patch in the last Tuesday UpdateSecurity Affairs·Dec 13, 13:55 UTC · Dec 13, 2014Vulnerability55
Microsoft Patch TuesdayCisco Talos·Dec 12, 23:32 UTC · Dec 12, 2017Vulnerability in the wildCVE-2017-11886CVE-2017-11888CVE-2017-11889+31 CVEs60
Threat actors scan Internet for Vulnerable Microsoft Exchange ServersSecurity Affairs·Feb 27, 08:05 UTC · Feb 27, 2020Threat actorCVE-2020-068860
Most organizations have yet to fix CVE-2020Security Affairs·Mar 16, 20:00 UTC · Mar 16, 2020Exploit / PoCCVE-2020-068860
WARNING: New Unpatched Microsoft Exchange ZeroThe Hacker News·Oct 3, 08:22 UTC · Oct 3, 2022Vulnerability in the wild160
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621260
Chinese hackers forged authentication tokens to breach government emailsHelp Net Security·Jul 14, 19:08 UTC · Jul 14, 2023Exploit / PoC in the wild60
August 2019 Patch Tuesday: Microsoft plugs critical wormable RDP holesHelp Net Security·Aug 14, 00:00 UTC · Aug 14, 2019VulnerabilityCVE-2019-1181CVE-2019-1182CVE-2019-1222+10 CVEs60
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, WaterThe Hacker News·Aug 3, 14:03 UTC · Aug 3, 2026Data breachCVE-2026-42897CVE-2026-6606660