ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & MoreThe Hacker News·Mar 12, 15:00 UTC · Mar 12, 2026Phishing & fraud in the wild60
Black Basta Ransomware May Have Exploited MS Windows ZeroThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2024Ransomware in the wildCVE-2024-2616960
Ransomware groups pose as fake tech support over TeamsCyberScoop·Jan 21, 22:52 UTC · Jan 21, 2025Ransomware in the wild60
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AIThe Hacker News·Jun 2, 03:39 UTC · Jun 2, 2026Ransomware in the wildCVE-2026-0257CVE-2026-8732CVE-2026-27771+31 CVEs60
Suppliers, logins, and AI tools are all becoming attack pathsHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2026Exploit / PoC in the wild160
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & MoreThe Hacker News·Mar 19, 14:25 UTC · Mar 19, 2026Ransomware in the wildCVE-2024-55591CVE-2025-71257CVE-2025-71258+4 CVEs60
SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware HackersThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Ransomware in the wildCVE-2024-4076660
⚡ Weekly Recap: BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & MoreThe Hacker News·Aug 12, 04:40 UTC · Aug 12, 2025Ransomware in the wildCVE-2025-54948CVE-2025-54987CVE-2025-8088+30 CVEs60
Security Affairs newsletter Round 525 by Pierluigi PaganiniSecurity Affairs·May 31, 21:54 UTC · May 31, 2025Ransomware in the wild60
PoC exploit for critical Erlang/OTP SSH bug is public (CVE-2025-32433)Help Net Security·Aug 14, 09:20 UTC · Aug 14, 2025Exploit / PoC in the wildCVE-2025-3243360
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News·Jul 22, 03:59 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs60
DOJ arrests three Ukrainians allegedly tied to FIN7 hacking gangCyberScoop·Aug 1, 18:12 UTC · Aug 1, 2018Exploit / PoC in the wild60
By gutting its cyber staff, State Department ignores congressional directivesCyberScoop·Aug 18, 14:31 UTC · Aug 18, 2025Policy & legal in the wild60
CISA's new KEV nomination form opens reporting to vendors and researchersHelp Net Security·Jun 19, 12:14 UTC · Jun 19, 2026Exploit / PoC in the wild60
CISA to allow researchers to report vulnerabilities to exploited bugs catalogThe Record·May 22, 01:25 UTC · May 22, 2026Vulnerability in the wild60
Months-long Interpol crackdown nets more than 1,000 online fraud arrestsCyberScoop·Nov 29, 15:06 UTC · Nov 29, 2021Phishing & fraud in the wild60
How Amazon Web Services uses AI to be a security ‘force multiplier’CyberScoop·Jun 11, 18:31 UTC · Jun 11, 2025Exploit / PoC in the wild60
CISA releases 2024 priorities for the Joint Cyber Defense CollaborativeCyberScoop·Feb 12, 18:33 UTC · Feb 12, 2024Advisory in the wild60
Major cyber incident reporting requirement, CISA budget hike on precipice of becoming lawCyberScoop·Mar 11, 17:00 UTC · Mar 11, 2022Ransomware in the wild60
Atlassian Confluence data-wiping vulnerability exploitedHelp Net Security·Nov 9, 09:50 UTC · Nov 9, 2023Vulnerability in the wildCVE-2023-2251860
Mass attack spree hits Microsoft SharePoint zeroCyberScoop·Jul 21, 13:44 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706160
Trump pauses on grants, aid leaves federal cyber programs in state of confusionCyberScoop·Jan 28, 22:14 UTC · Jan 28, 2025Exploit / PoC in the wild60
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breachedHelp Net Security·Jul 26, 00:00 UTC · Jul 26, 2026Data breach in the wildCVE-2026-6875CVE-2026-15409CVE-2026-15410+4 CVEs60
DHS’s cyber division has stepped up protections for coronavirus research, official saysCyberScoop·May 22, 19:35 UTC · May 22, 2020Ransomware in the wild60
FCC takes $200 million bite out of wireless carriers for sharing location dataCyberScoop·Apr 29, 22:29 UTC · Apr 29, 2024Policy & legal in the wild60
Unauthenticated remote code execution in JTL ShopSansec (Magento / e-commerce security)·Jun 18, 19:31 UTC · Jun 18, 2026Vulnerability in the wildCVE-2026-5439060
Verizon DBIR: Vulnerability exploitation is the dominant initial access vectorHelp Net Security·May 20, 00:00 UTC · May 20, 2026Vulnerability in the wild60
Conti ransomware group member pleads guilty, faces up to 20 years in prisonCyberScoop·Jun 12, 17:44 UTC · Jun 12, 2026Ransomware in the wild60
Microsoft seizes RedVDS infrastructure, disrupts fastCyberScoop·Jan 14, 15:00 UTC · Jan 14, 2026Exploit / PoC in the wild60
Cyber Storm 2020 could be DHS's most rigorous drill for critical infrastructure yetCyberScoop·Sep 30, 13:24 UTC · Sep 30, 2019Exploit / PoC in the wild60
CISA issues emergency directive for federal agencies to patch Ivanti VPN vulnerabilitiesCyberScoop·Jan 19, 22:13 UTC · Jan 19, 2024Vulnerability in the wild60
White House releases federal cybersecurity workforce strategyCyberScoop·Jul 12, 09:27 UTC · Jul 12, 2016Exploit / PoC in the wild60
CISA's Goldstein wants to ditch 'patch faster, fix faster' modelCyberScoop·Dec 1, 18:49 UTC · Dec 1, 2023Vulnerability in the wild60
Spanish court will extradite Russian cybercriminal suspect to U.S.CyberScoop·Oct 3, 17:18 UTC · Oct 3, 2017Policy & legal in the wild60
Lumma infostealer infected about 10 million systems before global disruptionCyberScoop·May 21, 20:22 UTC · May 21, 2025Malware in the wild60
AI can help track an ever-growing body of vulnerabilities, CISA official saysCyberScoop·Sep 4, 17:42 UTC · Sep 4, 2025Vulnerability in the wild60
DOJ moves to topple Kelihos, one of the world's largest botnetsCyberScoop·Apr 10, 20:29 UTC · Apr 10, 2017Malware in the wild60
When trust turns toxic: Lessons from the Salesloft Drift incidentCyberScoop·Nov 24, 11:00 UTC · Nov 24, 2025Exploit / PoC in the wild60
Judge rules Capital One must hand over Mandiant's forensic data breach reportCyberScoop·May 29, 13:13 UTC · May 29, 2020Data breach in the wild60
Found fast, fixed slow: The gap the AI clearinghouse must closeCyberScoop·Jul 8, 09:00 UTC · Jul 8, 2026Exploit / PoC in the wild60