BlackLotus UEFI bootkit disables Windows security mechanismsHelp Net Security·Apr 17, 10:14 UTC · Apr 17, 2023Vulnerability in the wildCVE-2022-2189460
BlackLotus Becomes First UEFI Bootkit Malware to Bypass Secure Boot on Windows 11The Hacker News·Jun 23, 08:42 UTC · Jun 23, 2023Malware in the wildCVE-2022-21894160
Diplomats Attacked with Firmware BootkitInfosecurity Magazine·Oct 5, 19:11 UTC · Oct 5, 2020Malware in the wild57
BlackLotus Malware Hijacks Windows Secure Boot ProcessSchneier on Security·Mar 15, 00:00 UTC · Mar 15, 2023Malware in the wildCVE-2022-2189460
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
Microsoft fixes two actively exploited bugs, one used by BlackLotus bootkit (CVE-2023-29336, CVE-2023-24932)Help Net Security·May 9, 00:00 UTC · May 9, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2022-21882+10 CVEs160
Microsoft’s Secure Boot has been broken for a decade and no one noticed until nowArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2015-5381160
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER MalwareThe Hacker News·Sep 27, 12:13 UTC · Sep 27, 2025Exploit / PoC in the wildCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware ExploitThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2023Ransomware in the wildCVE-2023-28252CVE-2022-24521CVE-2022-37969+6 CVEs60
Advanced threat predictions for 2023Kaspersky Securelist·Nov 14, 08:00 UTC · Nov 14, 2022Ransomware in the wild60
TrickBoot feature allows TrickBot bot to run UEFI attacksSecurity Affairs·Dec 3, 14:32 UTC · Dec 3, 2020Ransomware in the wild60
Patch Tuesday, January 2026 EditionKrebs on Security·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2026-20805CVE-2026-20952CVE-2026-20953+6 CVEs160
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
Chinese national charged for hacking thousands of Sophos firewallsSecurity Affairs·Dec 11, 10:20 UTC · Dec 11, 2024Policy & legal in the wildCVE-2020-1227160
Microsoft Patch Tuesday, May 2023 EditionKrebs on Security·May 10, 07:06 UTC · May 10, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2023-24941+2 CVEs60
Sneaky malware BlackLotus can bypass important Windows boot functionsThe Record·Mar 10, 14:17 UTC · Mar 10, 2023Malware in the wild57
Japanese businesses are the latest victims of attacks disguised as ransomwareCyberScoop·Nov 3, 18:51 UTC · Nov 3, 2017Ransomware in the wild60
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
Cisco became aware of a new attack variant against Secure Firewall ASA and FTD devicesSecurity Affairs·Nov 6, 18:26 UTC · Nov 6, 2025Data breach in the wildCVE-2025-20333CVE-2025-2036260
Chrome Zero-Day Exploited to Deliver Italian Memento Labs' LeetAgent SpywareThe Hacker News·Nov 3, 17:57 UTC · Nov 3, 2025Exploit / PoC in the wildCVE-2025-2783160
Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053)Help Net Security·Jun 16, 13:26 UTC · Jun 16, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-33073CVE-2025-33070+6 CVEs60
CISA warns of RESURGE malware exploiting Ivanti flawSecurity Affairs·Mar 30, 23:13 UTC · Mar 30, 2025Malware in the wildCVE-2025-0282CVE-2025-028360
Sophos mounted counter-offensive operation to foil Chinese attackersHelp Net Security·Oct 31, 00:00 UTC · Oct 31, 2024Exploit / PoC in the wildCVE-2022-104060
April’s Patch Tuesday Brings Record Number of FixesKrebs on Security·Apr 9, 20:55 UTC · Apr 9, 2024Vulnerability in the wildCVE-2024-20670CVE-2024-29063CVE-2024-29988+2 CVEs160
Microsoft patches two actively exploited zero-days (CVE-2024-29988, CVE-2024-26234)Help Net Security·Apr 9, 00:00 UTC · Apr 9, 2024Exploit / PoC in the wildCVE-2024-29988CVE-2024-26234CVE-2024-21412+9 CVEs60
Microsoft's May Patch Tuesday Fixes 38 Flaws, Including 2 Exploited ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-29325CVE-2023-24932+1 CVEs60
Week in review: Microsoft fixes two actively exploited bugs, MSI private code signing keys leakedHelp Net Security·May 14, 00:00 UTC · May 14, 2023Ransomware in the wildCVE-2023-29324CVE-2023-29336CVE-2023-24932160
Microsoft Patch Tuesday for May 2023 fixed 2 zeroSecurity Affairs·May 10, 05:25 UTC · May 10, 2023Vulnerability in the wildCVE-2023-29336CVE-2023-24932CVE-2023-24941+2 CVEs60
The anatomy of the MyKings botnet, and why it matters for securityCyberScoop·Dec 19, 14:41 UTC · Dec 19, 2019Malware in the wild60