How the Shadowserver Foundation helps network defenders with free intelligence feedsHelp Net Security·Dec 5, 00:00 UTC · Dec 5, 2024Ransomware60
Mirai-like botnet is exploiting recently disclosed Zyxel NAS flawSecurity Affairs·Jun 25, 16:52 UTC · Jun 25, 2024Malware in the wildCVE-2024-29973CVE-2023-2799260
Fortinet FortiWeb flaw CVE-2025Security Affairs·Jul 19, 16:25 UTC · Jul 19, 2025Exploit / PoC in the wildCVE-2025-2525760
CrushFTP Vulnerability Exploited Following Disclosure IssuesInfosecurity Magazine·Apr 3, 16:00 UTC · Apr 3, 2025Vulnerability in the wildCVE-2025-31161CVE-2025-282560
Experts warn of exploit attempt for Ivanti vTM bugSecurity Affairs·Aug 19, 09:35 UTC · Aug 19, 2024RansomwareCVE-2024-759360
+20,000 internet-exposed VMware ESXi instances vulnerable to CVE-2024Security Affairs·Aug 1, 20:28 UTC · Aug 1, 2024Ransomware in the wildCVE-2024-3708560
A botnet exploits e GeoVision zeroSecurity Affairs·Nov 17, 04:53 UTC · Nov 17, 2024MalwareCVE-2024-1112060
U.S. CISA adds GoVision device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 8, 08:04 UTC · May 8, 2025Exploit / PoC in the wildCVE-2024-6047CVE-2024-1112060
Hackers already installed web shells on 581 Citrix servers in CVE-2023Security Affairs·Aug 2, 20:50 UTC · Aug 2, 2023Exploit / PoC in the wildCVE-2023-351960
Tens of thousands of IPs vulnerable to Fortinet flaw dubbed 'must patch' by fedsCyberScoop·Oct 14, 16:22 UTC · Oct 14, 2024Vulnerability in the wild60
New CrushFTP Critical Vulnerability Exploited in the WildInfosecurity Magazine·Jul 21, 14:00 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-54309CVE-2025-3116160
CISA Warns of CrushFTP Vulnerability Exploitation in the WildInfosecurity Magazine·Apr 8, 12:20 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems ExposedSecurity Affairs·Jul 1, 19:49 UTC · Jul 1, 2026Exploit / PoC in the wildCVE-2026-4681760
New MOVEit Transfer critical bug is actively exploitedSecurity Affairs·Jun 26, 19:54 UTC · Jun 26, 2024Vulnerability in the wildCVE-2024-5805CVE-2024-580660
Over 80,000 servers hit as roundcube RCE bug gets rapidly exploitedSecurity Affairs·Jun 11, 11:43 UTC · Jun 11, 2025VulnerabilityCVE-2025-4911360
CISA: Patch Critical GeoServer GeoTools Bug NowInfosecurity Magazine·Jul 17, 09:30 UTC · Jul 17, 2024Vulnerability in the wildCVE-2024-3640160
CVE-2026-10520 Exploited: Ivanti Sentry Gateways Compromised Shortly After Patch ReleaseSecurity Affairs·Jun 12, 18:42 UTC · Jun 12, 2026Vulnerability in the wildCVE-2026-10520CVE-2026-1340CVE-2026-160360
Microsoft Exchange flaw CVE-2024Security Affairs·Feb 21, 07:33 UTC · Feb 21, 2024Ransomware in the wildCVE-2024-2141060
HelloKitty Ransomware Group Exploiting Apache ActiveMQ VulnerabilityThe Hacker News·Nov 4, 04:55 UTC · Nov 4, 2023Ransomware in the wildCVE-2023-4660460
Cozy Bear Hackers Target JetBrains TeamCity Servers in Global CampaignInfosecurity Magazine·Dec 14, 15:30 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
Shadowserver: Get free access to timely, critical Internet security dataHelp Net Security·Jun 1, 12:29 UTC · Jun 1, 2023Industry55
Week in review: Veeam Service Provider Console flaws fixed, Patch Tuesday forecastHelp Net Security·Dec 8, 00:00 UTC · Dec 8, 2024VulnerabilityCVE-2024-42448CVE-2024-42449CVE-2024-41713+1 CVEs60
SAP Flaw Exploited by Ransomware Groups and ChineseInfosecurity Magazine·May 15, 15:15 UTC · May 15, 2025Ransomware in the wildCVE-2025-31324CVE-2025-4299960
No, I Did Not Hack Your MS Exchange ServerKrebs on Security·Mar 28, 18:16 UTC · Mar 28, 2021Exploit / PoC in the wild60
FIN8-linked actor targets Citrix NetScaler systemsSecurity Affairs·Aug 29, 15:14 UTC · Aug 29, 2023RansomwareCVE-2023-351960
Operation Endgame targets malware networks in global crackdownCyberScoop·Nov 13, 14:49 UTC · Nov 13, 2025Malware in the wild60
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger ImpactThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-25015CVE-2025-22224CVE-2025-22225+18 CVEs60
Over 28,000 Citrix instances remain exposed to critical RCE flaw CVE-2025Security Affairs·Aug 27, 19:05 UTC · Aug 27, 2025Vulnerability in the wildCVE-2025-7775CVE-2025-7776CVE-2025-842460
Over 840k Cisco systems affected by Equation Group flaw CVE-2016Security Affairs·Sep 21, 12:37 UTC · Sep 21, 2016Exploit / PoCCVE-2016-641560
Hundreds of Citrix Endpoints Compromised With WebshellsInfosecurity Magazine·Aug 3, 10:00 UTC · Aug 3, 2023Exploit / PoCCVE-2023-3519CVE-2023-3466CVE-2023-346760
Hundreds of Citrix NetScaler ADC and Gateway Servers Hacked in Major Cyber AttackThe Hacker News·Aug 8, 03:59 UTC · Aug 8, 2023Data breachCVE-2023-3519CVE-2023-2448960
Researchers track dozens of organizations affected by React2Shell compromises tied to China’s MSSThe Record·Dec 8, 16:31 UTC · Dec 8, 2025Exploit / PoC in the wildCVE-2025-5518260
Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack CampaignThe Hacker News·Nov 23, 06:38 UTC · Nov 23, 2024Threat actor in the wildCVE-2024-0012CVE-2024-947460
Cops in several countries bust Avalanche, biggest ever botnet businessCyberScoop·Dec 1, 22:24 UTC · Dec 1, 2016Malware in the wild60
Citrix Patches Three Zero Days as One Sees Active ExploitationInfosecurity Magazine·Aug 27, 11:10 UTC · Aug 27, 2025Vulnerability in the wildCVE-2025-7775CVE-2025-7776CVE-2025-8424+1 CVEs60
Attackers Exploit RCE Flaw as 14,000 F5 BIGSecurity Affairs·Apr 6, 13:08 UTC · Apr 6, 2026Vulnerability in the wildCVE-2025-5352160
Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed onlineSecurity Affairs·Jan 27, 15:28 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2026-2376060
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 20, 13:38 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-2525760
CrushFTP CVE-2025Security Affairs·Apr 1, 14:09 UTC · Apr 1, 2025Ransomware in the wildCVE-2025-282560
PHP addressed critical RCE potentially impacting millions of serversSecurity Affairs·Jun 9, 13:27 UTC · Jun 9, 2024VulnerabilityCVE-2024-4577CVE-2012-182360