THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
FBI deleted China-linked PlugX malware from +4,200 US computersSecurity Affairs·Jan 14, 21:58 UTC · Jan 14, 2025Malware55
Researchers Discover New PlugX Malware Variant Spreading via Removable USB DevicesThe Hacker News·Feb 7, 06:11 UTC · Feb 7, 2023Malware55
French Authorities Launch Operation to Remove PlugX Malware from Infected SystemsThe Hacker News·Jan 3, 04:54 UTC · Jan 3, 2025Malware55
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
China-Linked TA416 Targets European Governments with PlugX and OAuthThe Hacker News·Apr 3, 17:34 UTC · Apr 3, 2026VulnerabilityCVE-2025-31324CVE-2025-099460
Law enforcement action deletes PlugX malware from thousands of machinesCyberScoop·Jan 14, 17:33 UTC · Jan 14, 2025Malware in the wild60
Chinese Hackers Implant PlugX Variant on Compromised MS Exchange ServersThe Hacker News·Mar 23, 11:47 UTC · Mar 23, 2022Ransomware60
Black Basta Deploys PlugX Malware in USB Devices With New TechniqueInfosecurity Magazine·Jan 27, 17:00 UTC · Jan 27, 2023Malware55
RedDelta Deploys PlugX Malware to Target Mongolia and Taiwan in Espionage CampaignsThe Hacker News·Jan 10, 09:51 UTC · Jan 10, 2025Malware55
Chinese-Linked Hackers Exploit Windows Flaw to Spy on EU DiplomatsInfosecurity Magazine·Oct 31, 12:10 UTC · Oct 31, 2025Vulnerability55
China-Linked Hackers Infiltrate East Asian Firm for 3 Years Using F5 DevicesThe Hacker News·Jun 18, 09:27 UTC · Jun 18, 2024Vulnerability in the wild60
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
Diplomatic entities in Belgium and Hungary hacked in ChinaThe Record·Oct 30, 18:17 UTC · Oct 30, 2025Exploit / PoC60
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621160
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
China-linked UNC6384 exploits Windows zeroSecurity Affairs·Nov 1, 14:11 UTC · Nov 1, 2025Exploit / PoC60
We can try to bridge the cybersecurity skills gap, but that doesn’t necessarily mean more jobs for defendersCisco Talos·Sep 12, 18:00 UTC · Sep 12, 2024Malware55
ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & MoreThe Hacker News·Mar 12, 15:00 UTC · Mar 12, 2026Phishing & fraud in the wild60
Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN CountriesThe Hacker News·Mar 28, 14:27 UTC · Mar 28, 2024Threat actor60
Trend Micro addressed flaw exploited by ChinaSecurity Affairs·May 24, 18:19 UTC · May 24, 2022Malware in the wild60
Research points to a Chinese hacking effort targeting a Russian border unitCyberScoop·Apr 27, 12:00 UTC · Apr 27, 2022Exploit / PoC in the wild60
Suspected Chinese hackers impersonate Catholic news outlets to gather intel about Vatican diplomacyCyberScoop·Nov 25, 13:30 UTC · Nov 25, 2020Exploit / PoC in the wild60
Public disclosure didn't stop suspected Chinese hackers from targeting the VaticanCyberScoop·Sep 15, 21:57 UTC · Sep 15, 2020Exploit / PoC in the wild60
⚡ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and MoreThe Hacker News·Mar 2, 13:26 UTC · Mar 2, 2026Data breach in the wildCVE-2026-20127CVE-2025-40538CVE-2025-40539+27 CVEs60
Unpatched Windows vulnerability continues to be exploited by APTs (CVE-2025-9491)Help Net Security·Dec 5, 09:00 UTC · Dec 5, 2025VulnerabilityCVE-2025-949160
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System AccessThe Hacker News·Nov 30, 09:05 UTC · Nov 30, 2025VulnerabilityCVE-2025-59287160
⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & MoreThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Malware in the wildCVE-2025-55177CVE-2025-43300CVE-2025-907460
Microsoft Targeted by 8 of 10 Top Vulnerabilities in 2018Recorded Future·Aug 11, 00:00 UTC · Aug 11, 2025Vulnerability in the wildCVE-2017-0199CVE-2016-0189CVE-2017-8750+8 CVEs60
NailaoLocker ransomware targets EU healthcareSecurity Affairs·Feb 20, 15:48 UTC · Feb 20, 2025RansomwareCVE-2024-2491960
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [20 January]The Hacker News·Jan 20, 12:04 UTC · Jan 20, 2025RansomwareCVE-2025-21333CVE-2025-21334CVE-2025-21335+36 CVEs60
Week in review: AWS S3 data encrypted without ransomware, data of 15k Fortinet firewalls leakedHelp Net Security·Jan 19, 00:00 UTC · Jan 19, 2025Ransomware in the wildCVE-2024-55591CVE-2025-0282CVE-2024-734460
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [13 January]The Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Ransomware in the wildCVE-2025-0282CVE-2024-52875CVE-2024-8474+15 CVEs60
New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel ImplantsCisco Talos·Sep 19, 12:00 UTC · Sep 19, 2023Malware55
Previously unknown hacking group targets Hong Kong organizations in supply chain cyberattackCyberScoop·Aug 22, 13:14 UTC · Aug 22, 2023Ransomware in the wild60
Hackers use aging malware to attack government agencies, IT firms in multiple Asian countriesThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Malware55