Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft's Disclosure ProcessSecurity Affairs·Jun 4, 09:13 UTC · Jun 4, 2026Exploit / PoC in the wild160
GitHub Internal Repositories Breached via Malicious Nx Console VS Code ExtensionThe Hacker News·May 28, 05:34 UTC · May 28, 2026Data breach in the wildCVE-2026-45321CVE-2026-4802760
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploitedHelp Net Security·May 24, 00:00 UTC · May 24, 2026Data breach in the wildCVE-2026-42945CVE-2026-45585CVE-2026-41091+1 CVEs60
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AIThe Hacker News·Jun 2, 03:39 UTC · Jun 2, 2026Ransomware in the wildCVE-2026-0257CVE-2026-8732CVE-2026-27771+31 CVEs60
All gas, no brakes: Time to come to AI churchCisco Talos·Feb 5, 19:00 UTC · Feb 5, 2026Ransomware in the wild60
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
⚡ Weekly Recap: Chrome 0-Day, Ivanti Exploits, MacOS Stealers, Crypto Heists and MoreThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Malware in the wildCVE-2025-32462CVE-2025-32463CVE-2025-20309+23 CVEs60
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security·Feb 15, 00:00 UTC · Feb 15, 2026Vulnerability in the wildCVE-2026-1731CVE-2024-12356CVE-2026-1281+2 CVEs60
Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)Help Net Security·Oct 8, 00:00 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-38112+3 CVEs60
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs160
Microsoft Patches Record 622 Flaws, Including Two ZeroThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2026-56164CVE-2026-56155CVE-2026-50661+6 CVEs60
Mimecast confirms SolarWinds attackers breached security certificate, 'potentially exfiltrated' credentialsCyberScoop·Jan 26, 20:15 UTC · Jan 26, 2021Data breach in the wild60
CodeBuild Flaw Put AWS Console Supply Chain At RiskInfosecurity Magazine·Jan 15, 15:00 UTC · Jan 15, 2026Vulnerability in the wild160
Attackers abuse SolarWinds Web Help Desk to install Zoho agents and VelociraptorSecurity Affairs·Feb 9, 12:28 UTC · Feb 9, 2026Exploit / PoC in the wildCVE-2025-40551CVE-2025-26399CVE-2025-4053660
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Security Affairs newsletter Round 564 by Pierluigi PaganiniSecurity Affairs·Feb 22, 14:14 UTC · Feb 22, 2026Ransomware in the wildCVE-2026-1670CVE-2026-244160
Ransomware attacks and how victims respondCisco Talos·Oct 16, 18:00 UTC · Oct 16, 2025Ransomware in the wild60
Check Point Warns of ZeroThe Hacker News·Jun 6, 04:42 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2024-2491960
DNS attacks on the rise, says surveyCyberScoop·Aug 31, 16:00 UTC · Aug 31, 2016Ransomware in the wild60
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Week in review: Google fixes exploited Chrome zero-day, Patch Tuesday forecastHelp Net Security·Jun 8, 00:00 UTC · Jun 8, 2025Exploit / PoC in the wildCVE-2025-541960
APT Expands Attack on ManageEngine With Active Campaign Against ServiceDesk PlusPalo Alto Unit 42·Jun 6, 01:25 UTC · Jun 6, 2024Threat actor in the wildCVE-2021-44077CVE-2021-3361760
Resolving Availability vs. Security, a Constant Conflict in ITThe Hacker News·Aug 5, 10:39 UTC · Aug 5, 2022Vulnerability in the wildCVE-2022-3162660
U.S. CISA adds Linux kernel flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 5, 21:00 UTC · Feb 5, 2025Exploit / PoC in the wildCVE-2024-5310460
Google fixed actively exploited kernel zeroSecurity Affairs·Feb 4, 00:31 UTC · Feb 4, 2025Exploit / PoC in the wildCVE-2024-53104CVE-2024-45569CVE-2024-43047+1 CVEs60
Week in review: IE zero-day, S3 bucket security, rise of RDP as a target vectorHelp Net Security·Sep 29, 00:00 UTC · Sep 29, 2019Exploit / PoC in the wildCVE-2019-1675960
Google Patches 47 Android Security Flaws, Including Actively Exploited CVE-2024The Hacker News·Feb 6, 03:49 UTC · Feb 6, 2025Vulnerability in the wildCVE-2024-53104CVE-2024-4556960
Security Affairs newsletter Round 527 by Pierluigi PaganiniSecurity Affairs·Jun 8, 11:20 UTC · Jun 8, 2025Ransomware in the wildCVE-2025-2018860
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-dayHelp Net Security·Aug 24, 00:00 UTC · Aug 24, 2025Exploit / PoC in the wildCVE-2025-43300CVE-2018-0171CVE-2025-31324+1 CVEs60
Patch Responsibility Remains Up for Grabs as AI Unearth Flaws At ScaleInfosecurity Magazine·Jun 3, 09:00 UTC · Jun 3, 2026Vulnerability in the wild60
Shadow Brokers return to taunt U.S. government after ransomware spreadCyberScoop·May 16, 15:45 UTC · May 16, 2017Ransomware in the wild60
Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widensHelp Net Security·Dec 3, 00:00 UTC · Dec 3, 2023Exploit / PoC in the wildCVE-2023-46214CVE-2023-49103CVE-2023-41998+5 CVEs260
Peanut butter and ProtonMail: US charges underscore evolution of espionage in digital ageCyberScoop·Oct 11, 19:59 UTC · Oct 11, 2021Threat actor in the wild60
Mitre shared 2022 CWE Top 25 most dangerous software weaknessesSecurity Affairs·Jun 29, 10:40 UTC · Jun 29, 2022Exploit / PoC in the wild60
Attackers are hijacking Jupyter notebooks to host illegal Champions League streamsCyberScoop·Nov 19, 14:00 UTC · Nov 19, 2024Exploit / PoC in the wild160
Court rules encrypted email provider Tutanota must monitor messages in blackmail caseCyberScoop·May 24, 21:16 UTC · May 24, 2021Policy & legal in the wild60