Week in review: Actively exploited Windows SMB flaw, trusted OAuth apps turned into cloud backdoorsHelp Net Security·Oct 26, 00:00 UTC · Oct 26, 2025Malware in the wildCVE-2025-59287CVE-2025-61932CVE-2025-54236+2 CVEs60
Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerabilityHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2024Vulnerability in the wildCVE-2024-10443CVE-2024-43093CVE-2024-43047+2 CVEs60
Engineer took U.S. locomotive manufacturer’s source code to China, prosecutors sayCyberScoop·Jul 11, 16:59 UTC · Jul 11, 2019Data breach in the wild60
Week in review: CDK Global cyberattack, critical vCenter Server RCE fixedHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2024Vulnerability in the wildCVE-2024-0762CVE-2024-37079CVE-2024-3708060
Google engineers keep pushing on email encryption as E2EMail goes open sourceCyberScoop·Feb 27, 18:15 UTC · Feb 27, 2017Exploit / PoC in the wild60
Apple fixed a zero-day exploited in attacks against Google Chrome usersSecurity Affairs·Jul 30, 18:09 UTC · Jul 30, 2025Exploit / PoC in the wildCVE-2025-655860
NSA’s reverse engineering tool Ghidra impacted by a bug — but there's no need to panicCyberScoop·Oct 1, 21:13 UTC · Oct 1, 2019Exploit / PoC in the wildCVE-2019-1694160
Open-source security spat leads companies to join forces for new toolCyberScoop·Jan 27, 15:29 UTC · Jan 27, 2025Exploit / PoC in the wild60
How an NSA researcher plans to allow everyone to guard against firmware attacksCyberScoop·Aug 23, 21:17 UTC · Aug 23, 2019Exploit / PoC in the wild60
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched ServersThe Hacker News·Sep 2, 04:43 UTC · Sep 2, 2025Vulnerability in the wildCVE-2025-54309CVE-2025-31161CVE-2024-404060
Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers ActThe Hacker News·Jul 20, 15:49 UTC · Jul 20, 2025Vulnerability in the wildCVE-2025-696560
Google uses large language model to discover realThe Record·Nov 4, 01:37 UTC · Nov 4, 2024Vulnerability in the wild60
North Korea-linked threat actors target cybersecurity experts with a zeroSecurity Affairs·Sep 8, 19:51 UTC · Sep 8, 2023Threat actor in the wild60
Google fixes two actively exploited Chrome zero-days (CVE-2020-16009, CVE-2020-16010)Help Net Security·Nov 4, 00:00 UTC · Nov 4, 2020Exploit / PoC in the wildCVE-2020-16009CVE-2020-16010CVE-2020-15999+1 CVEs60
Google fixes Chrome zeroSecurity Affairs·Feb 25, 13:53 UTC · Feb 25, 2020Exploit / PoC in the wildCVE-2020-6418CVE-2019-5786CVE-2019-1372060
U.S. CISA adds a Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 21:12 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-1322360
Google fixed the seventh Chrome zeroSecurity Affairs·Nov 18, 08:59 UTC · Nov 18, 2025Exploit / PoC in the wildCVE-2025-13223CVE-2025-13224CVE-2025-10585+5 CVEs60
When is One Vulnerability Scanner Not Enough?The Hacker News·May 2, 10:25 UTC · May 2, 2024Vulnerability in the wild60
Week in review: Microsoft fixes two actively exploited 0-days, PAN-OS auth bypass hole pluggedHelp Net Security·Feb 16, 00:00 UTC · Feb 16, 2025Ransomware in the wildCVE-2025-21418CVE-2025-21391CVE-2025-0108+1 CVEs60
Week in review: Rackspace outage, Kali Linux 2022.4 released, Patch Tuesday forecastHelp Net Security·Dec 11, 00:00 UTC · Dec 11, 2022Vulnerability in the wildCVE-2022-426260
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529)Help Net Security·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-4352960
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecastHelp Net Security·Apr 12, 00:00 UTC · Apr 12, 2026Exploit / PoC in the wildCVE-2026-34197160
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AIThe Hacker News·Jun 30, 11:32 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-43707CVE-2026-43716CVE-2026-43745+6 CVEs160
January 2026 Patch Tuesday forecast: And so it continuesHelp Net Security·Jan 13, 21:29 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-14174CVE-2025-4352960
Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPadsCyberScoop·Nov 4, 20:28 UTC · Nov 4, 2025Vulnerability in the wild60
Update Your Chrome Browser to Patch New Zero‑Day Bug Exploited in the WildThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2021Exploit / PoC in the wildCVE-2021-30563CVE-2021-21148CVE-2021-21166+6 CVEs60
New Chrome 0-Day Bug Under Active AttacksThe Hacker News·Jun 10, 10:25 UTC · Jun 10, 2021Exploit / PoC in the wildCVE-2021-30551CVE-2021-33742CVE-2021-21148+5 CVEs160
Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploitedHelp Net Security·Aug 25, 00:00 UTC · Aug 25, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-6800CVE-2024-28987+2 CVEs60
Google fixes actively exploited Chrome zero-day (CVE-2024-0519)Help Net Security·Jan 17, 00:00 UTC · Jan 17, 2024Exploit / PoC in the wildCVE-2024-0519CVE-2024-0517CVE-2024-051860
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023Help Net Security·Mar 1, 00:00 UTC · Mar 1, 2026Malware in the wildCVE-2026-25108CVE-2026-20127160
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-dayHelp Net Security·Aug 24, 00:00 UTC · Aug 24, 2025Exploit / PoC in the wildCVE-2025-43300CVE-2018-0171CVE-2025-31324+1 CVEs60
New Chrome zero-day actively exploited, patch quickly! (CVE-2024-7971)Help Net Security·Sep 19, 11:32 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-7971CVE-2024-796560
Microsoft seizes domain used by Vietnamese group to sell fake accounts, servicesCyberScoop·Jul 31, 23:58 UTC · Jul 31, 2024Ransomware in the wild60
Five brutal hours for TikTok: CEO raked over coals amid privacy, security concernsCyberScoop·Mar 23, 21:41 UTC · Mar 23, 2023Exploit / PoC in the wild60
A malicious Tor browser is helping scammers steal bitcoin, researchers sayCyberScoop·Oct 18, 18:26 UTC · Oct 18, 2019Phishing & fraud in the wild160
NSA's reverse-engineering malware tool, Ghidra, to get new features to save time, boost accuracyCyberScoop·Aug 8, 19:27 UTC · Aug 8, 2019Malware in the wild60
The npm incident frightened everyone, but ended up being nothing to fret aboutCyberScoop·Sep 10, 14:35 UTC · Sep 10, 2025Exploit / PoC in the wild60
Low-Skilled Cybercriminals Use AI to Perform “Vibe Extortion” AttacksInfosecurity Magazine·Feb 17, 13:45 UTC · Feb 17, 2026Ransomware in the wild160