Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engineHelp Net Security·Dec 1, 00:00 UTC · Dec 1, 2024MalwareCVE-2024-5921CVE-2024-29014CVE-2024-9680+1 CVEs60
Critical Golden dMSA Attack in Windows Server 2025 Enables CrossThe Hacker News·Jul 21, 06:31 UTC · Jul 21, 2025Exploit / PoC60
Russia-linked APT28 compromised Ubiquiti EdgeRouters to facilitate cyber operationsSecurity Affairs·Feb 28, 11:43 UTC · Feb 28, 2024Threat actorCVE-2021-36260CVE-2022-46169CVE-2021-35394+1 CVEs160
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking CampaignThe Hacker News·Apr 8, 16:11 UTC · Apr 8, 2026Threat actorCVE-2023-50224160
Commvault strengthens Microsoft Active Directory protectionHelp Net Security·Jan 16, 09:24 UTC · Jan 16, 2025Ransomware60
Russian hackers' custom tool exploits old Windows Print Spooler flaw (CVE-2022-38028)Help Net Security·Apr 23, 00:00 UTC · Apr 23, 2024VulnerabilityCVE-2022-38028CVE-2023-2339760
Russia's APT8 exploited Outlook 0day to target EU NATO membersSecurity Affairs·Dec 8, 00:07 UTC · Dec 8, 2023Threat actorCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60
Microsoft, OpenAI Confirm NationInfosecurity Magazine·Feb 15, 11:43 UTC · Feb 15, 2024Vulnerability55
Senator urges Meta CEO to maintain election research partnershipsCyberScoop·Oct 29, 20:04 UTC · Oct 29, 2024Exploit / PoC in the wild160
Russian hackers use old Outlook vulnerability to target Polish orgs (CVE-2023-23397)Help Net Security·Dec 5, 00:00 UTC · Dec 5, 2023VulnerabilityCVE-2023-23397CVE-2023-38831CVE-2021-4044460
Russia-linked APT28 group spotted exploiting Outlook flaw to hijack MS Exchange accountsSecurity Affairs·Dec 5, 14:19 UTC · Dec 5, 2023Threat actorCVE-2023-23397CVE-2023-38831CVE-2021-40444+4 CVEs60
Week in review: Two Cisco ASA zero-days exploited, MITRE breach, GISEC Global 2024Help Net Security·Apr 28, 00:00 UTC · Apr 28, 2024Policy & legalCVE-2024-20353CVE-2024-20359CVE-2023-46805+4 CVEs60
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Russian Espionage Operation Targets Organizations Tied to Ukraine WarInfosecurity Magazine·May 16, 11:15 UTC · May 16, 2025Threat actorCVE-2024-11182CVE-2023-4377060
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621260
Ukraine's CERT Thwarts APT28's Cyberattack on Critical Energy InfrastructureThe Hacker News·Sep 6, 08:02 UTC · Sep 6, 2023Threat actorCVE-2023-3883160
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2026Threat actor in the wildCVE-2026-2023060
New “LameHug” Malware Deploys AIInfosecurity Magazine·Jul 18, 13:00 UTC · Jul 18, 2025MalwareCVE-2024-1118260
Darktrace brings real-time cloud detection and response to Microsoft Azure customersHelp Net Security·Oct 3, 00:00 UTC · Oct 3, 2024Vulnerability55
Beware: Experts Reveal New Details on ZeroThe Hacker News·Dec 19, 04:44 UTC · Dec 19, 2023VulnerabilityCVE-2023-35384CVE-2023-36710CVE-2023-23397+1 CVEs60
Microsoft: Iranian espionage campaign targeted satellite and defense sectorsCyberScoop·Sep 14, 16:30 UTC · Sep 14, 2023Threat actor in the wild60
New cyber reality: With great interdependence comes great liabilityCyberScoop·Mar 2, 20:24 UTC · Mar 2, 2023Vulnerability55
How Mirel Sehic relies on simplicity to focus on product securityHelp Net Security·Aug 16, 14:01 UTC · Aug 16, 2023Ransomware60
Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook VulnerabilityThe Hacker News·Dec 8, 08:55 UTC · Dec 8, 2023VulnerabilityCVE-2023-23397CVE-2023-3883160
China Poised to Disrupt US Critical Infrastructure with CyberInfosecurity Magazine·Oct 5, 14:00 UTC · Oct 5, 2023Ransomware60
APT28 Targets Ukrainian Government Entities with Fake "Windows Update" EmailsThe Hacker News·May 2, 11:27 UTC · May 2, 2023Threat actorCVE-2023-2339760
Friday Squid Blogging: Evolution of the Vampire SquidSchneier on Security·Jul 29, 21:19 UTC · Jul 29, 2022Malware55
Microsoft Warns of Widescale Credential Stealing Attacks by Russian HackersThe Hacker News·Jun 27, 14:11 UTC · Jun 27, 2023Exploit / PoCCVE-2020-12641CVE-2020-35730CVE-2021-44026+1 CVEs60
Slack + Snapchat = AppSec? Breaking down the complexity of messaging appsHelp Net Security·Jun 19, 00:00 UTC · Jun 19, 2019Policy & legal55
Russian Hackers Made 'Tainted Leaks' a Thing — Phishing to PropagandaThe Hacker News·May 29, 17:04 UTC · May 29, 2017Phishing & fraud55
Russian APT28 Hackers Targeting 13 Nations in Ongoing Cyber Espionage CampaignThe Hacker News·May 31, 10:02 UTC · May 31, 2024Threat actorCVE-2023-38831CVE-2023-2339760
Feds quash widespread Russia-backed espionage network spanning 18,000 devicesCyberScoop·Apr 7, 23:46 UTC · Apr 7, 2026Threat actor in the wild60
How machine learning helps us hunt threatsKaspersky Securelist·Oct 3, 13:39 UTC · Oct 3, 2024Vulnerability55
How Powell's and Podesta's E-mail Accounts Were HackedSchneier on Security·Jan 27, 14:13 UTC · Jan 27, 2020Threat actor60
U.S. Government Disrupts RussiaThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Data breachCVE-2023-2339760
Google TAG Warns of Russian Hackers Conducting Phishing Attacks in UkraineThe Hacker News·Apr 21, 04:54 UTC · Apr 21, 2023Phishing & fraud55
U.S. authorities disrupt Russian intelligence's botnetHelp Net Security·Dec 24, 13:27 UTC · Dec 24, 2024Malware55
NATO and the EU formally condemned APT28 cyber espionageSecurity Affairs·May 12, 16:39 UTC · May 12, 2024Threat actorCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60