Palo Alto Networks’ Koi acquisition is all about keeping AI agents in checkCyberScoop·Feb 17, 16:55 UTC · Feb 17, 2026Exploit / PoC in the wild60
Hackers Actively Exploiting WidelyThe Hacker News·Apr 23, 19:23 UTC · Apr 23, 2019Exploit / PoC in the wildCVE-2019-997860
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress SitesThe Hacker News·May 8, 14:05 UTC · May 8, 2024Vulnerability in the wildCVE-2023-4000060
WordPress Social Warfare plugin zeroSecurity Affairs·Mar 24, 11:01 UTC · Mar 24, 2019Exploit / PoC in the wild60
New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to CyberattacksThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-30777CVE-2023-30177CVE-2023-31144+1 CVEs60
Flaws in Social Warfare plugin actively exploited in the wildSecurity Affairs·Apr 25, 18:35 UTC · Apr 25, 2019Exploit / PoC in the wildCVE-2019-997860
Attackers exploit Funnel Builder bug to inject e-skimmers into eSecurity Affairs·May 17, 12:25 UTC · May 17, 2026Vulnerability in the wild60
Researchers Uncover Active Exploitation of WordPress Plugin VulnerabilitiesThe Hacker News·May 30, 13:49 UTC · May 30, 2024Vulnerability in the wildCVE-2023-6961CVE-2023-40000CVE-2024-219460
Drupal Releases Core CMS Updates to Patch Several VulnerabilitiesThe Hacker News·Apr 17, 21:51 UTC · Apr 17, 2019Vulnerability in the wildCVE-2019-10909CVE-2019-10910CVE-2019-109160
Over 800K WordPress sites are at risk due to a flaw in Ninja Forms pluginSecurity Affairs·May 1, 08:38 UTC · May 1, 2020Exploit / PoC in the wild60
LiteSpeed cPanel Plugin CVE-2026The Hacker News·May 27, 09:52 UTC · May 27, 2026Ransomware in the wildCVE-2026-48172CVE-2026-4194060
Funnel Builder Flaw Exploited to Enable WooCommerce Checkout SkimmingThe Hacker News·Jun 1, 11:32 UTC · Jun 1, 2026Exploit / PoC in the wild60
Crooks are attempting to take over tens of thousands of WordPress sitesSecurity Affairs·Feb 29, 16:15 UTC · Feb 29, 2020Exploit / PoC in the wild60
Zero-day in popular Yuzo Related Posts WordPress Plugin exploited in the wildSecurity Affairs·Apr 12, 09:35 UTC · Apr 12, 2019Exploit / PoC in the wild60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and GatewayThe Hacker News·Jul 22, 03:57 UTC · Jul 22, 2023Exploit / PoC in the wildCVE-2023-3519CVE-2023-3466CVE-2023-3467+3 CVEs60
Magecart group compromises customer ratings tool, affecting 'hundreds' of online storesCyberScoop·Oct 9, 13:36 UTC · Oct 9, 2018Data breach in the wild60
Using a WordPress flaw to leverage zerologon vulnerability and attack companies’ Domain ControllersSecurity Affairs·Oct 7, 06:03 UTC · Oct 7, 2020Vulnerability in the wildCVE-2020-25213CVE-2020-147260
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a PasswordSecurity Affairs·Jun 1, 11:36 UTC · Jun 1, 2026Vulnerability in the wildCVE-2026-873260
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AICyberScoop·May 8, 13:14 UTC · May 8, 2026Exploit / PoC in the wild60
Microsoft Security Updates January 2016Kaspersky Securelist·Jan 12, 19:08 UTC · Jan 12, 2016Vulnerability in the wildCVE-2016-003460
Broadcom Patches VMware Aria FlawsThe Hacker News·Jan 31, 05:49 UTC · Jan 31, 2025Vulnerability in the wildCVE-2025-22218CVE-2025-22219CVE-2025-22220+5 CVEs60
Barracuda Warns of Zero-Day Exploited to Breach Email Security Gateway AppliancesThe Hacker News·May 27, 07:08 UTC · May 27, 2023Exploit / PoC in the wildCVE-2023-286860
Serious flaw found and patched in WordPress, but it might lurk in pluginsCyberScoop·Feb 19, 20:38 UTC · Feb 19, 2019Vulnerability in the wild60
Critical WP Maps Pro Flaw Actively Exploited to Create Admin AccountsThe Hacker News·Jun 1, 08:45 UTC · Jun 1, 2026Vulnerability in the wildCVE-2026-873260
Critical JetBrains TeamCity Flaw Could Expose Source Code and Build Pipelines to AttackersThe Hacker News·Oct 2, 11:09 UTC · Oct 2, 2023Ransomware in the wildCVE-2023-42793CVE-2023-36618CVE-2023-36619160
Flaw in WordPress plugin allowed unauthorized admin access, backdoorsCyberScoop·Nov 12, 16:01 UTC · Nov 12, 2018Malware in the wild60
Flaws in Popup Builder WordPress plugin expose 100K+ websites to hackSecurity Affairs·Mar 13, 11:42 UTC · Mar 13, 2020Exploit / PoC in the wildCVE-2020-10196CVE-2020-1019560
⚡ Weekly Recap: VPN 0-Day, Encryption Backdoor, AI Malware, macOS Flaw, ATM Hack & MoreThe Hacker News·Aug 5, 04:38 UTC · Aug 5, 2025Malware in the wildCVE-2025-40596CVE-2025-40597CVE-2025-40598+8 CVEs60
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & VibeThe Hacker News·Mar 9, 18:22 UTC · Mar 9, 2026Data breach in the wildCVE-2026-21385CVE-2026-2796CVE-2026-2256+13 CVEs60
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
Alert: Juniper Firewalls, Openfire, and Apache RocketMQ Under Attack from New ExploitsThe Hacker News·Sep 6, 07:46 UTC · Sep 6, 2023Ransomware in the wildCVE-2023-36844CVE-2023-36845CVE-2023-36846+3 CVEs60
New Flaw in WordPress Plugin Used by Over a Million Sites Under Active ExploitationThe Hacker News·May 20, 04:02 UTC · May 20, 2023Exploit / PoC in the wildCVE-2023-3224360
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
Network Security Trends: AugustPalo Alto Unit 42·Jun 6, 00:57 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-40438CVE-2021-34473CVE-2021-38647+9 CVEs60
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
U.S. CISA adds LiteSpeed cPanel Plugin flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 28, 09:41 UTC · May 28, 2026Exploit / PoC in the wildCVE-2026-4817260
ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaignCyberScoop·Nov 20, 22:14 UTC · Nov 20, 2018Threat actor in the wild60