Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code ExecutionThe Hacker News·May 7, 13:06 UTC · May 7, 2026VulnerabilityCVE-2026-26268160
Apiiro CLI turns AI coding assistants into full-stack security engineersHelp Net Security·Apr 10, 00:00 UTC · Apr 10, 2026Vulnerability55
U.S. CISA adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 6, 09:22 UTC · Feb 6, 2026Exploit / PoC in the wildCVE-2025-11953CVE-2026-2442360
Hackers abused React Native CLI flaw to deploy Rust malware before public disclosureSecurity Affairs·Feb 3, 15:41 UTC · Feb 3, 2026Malware in the wildCVE-2025-11953160
CISA adds Jenkins Command Line Interface (CLI) bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 19, 19:46 UTC · Aug 19, 2024Exploit / PoC in the wildCVE-2024-2389760
CI Fuzz CLI: Open-source tool to test Java apps for unexpected behaviorsHelp Net Security·Dec 2, 00:00 UTC · Dec 2, 2022Exploit / PoC60
CVE-2020-3446 default credentials bug exposes Cisco ENCS, CSP Appliances to hackSecurity Affairs·Aug 20, 16:04 UTC · Aug 20, 2020VulnerabilityCVE-2020-344660
How to find container-based threats in hostKaspersky Securelist·Jun 3, 10:00 UTC · Jun 3, 2025Industry55
Researchers flag flaw in Google’s AI coding assistant that allowed for ‘silent’ code exfiltrationCyberScoop·Jul 28, 20:26 UTC · Jul 28, 2025Exploit / PoC in the wild60
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm PackageThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-11953160
Critical React Native CLI Flaw Exposed Millions of Developers to Remote AttacksThe Hacker News·Nov 4, 14:24 UTC · Nov 4, 2025VulnerabilityCVE-2025-1195360
China-linked APT Velvet Ant exploited zeroSecurity Affairs·Aug 23, 07:21 UTC · Aug 23, 2024Exploit / PoC in the wildCVE-2024-2039960
Watch out, experts warn of a critical flaw in JenkinsSecurity Affairs·Jan 26, 17:51 UTC · Jan 26, 2024VulnerabilityCVE-2024-2389760
Cisco Catalyst SD-WAN Manager CVE-2026The Hacker News·Jun 25, 05:31 UTC · Jun 25, 2026Exploit / PoC in the wildCVE-2026-20245CVE-2026-20182CVE-2026-20127+5 CVEs60
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER MalwareThe Hacker News·Sep 27, 12:13 UTC · Sep 27, 2025Exploit / PoC in the wildCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Critical Jenkins Vulnerability Exposes Servers to RCE AttacksThe Hacker News·Jan 29, 03:45 UTC · Jan 29, 2024VulnerabilityCVE-2024-23897CVE-2023-27898CVE-2023-2790560
Alert: Microsoft Releases Patch Updates for 5 New ZeroThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2023Vulnerability in the wildCVE-2023-36025CVE-2023-36033CVE-2023-36036+9 CVEs60
Critical flaws patched in ISP Advanced Digital Broadcast Broadband devicesSecurity Affairs·Jul 7, 16:45 UTC · Jul 7, 2018VulnerabilityCVE-2018-13108CVE-2018-13109CVE-2018-1311060
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent ImportsThe Hacker News·Aug 5, 15:14 UTC · Aug 5, 2026Exploit / PoC in the wildCVE-2026-41679160
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security PatchesThe Hacker News·Apr 25, 08:20 UTC · Apr 25, 2026VulnerabilityCVE-2025-20333CVE-2025-2036260
Surge in Magento 2 template attacksSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Hewlett Packard Enterprise fixes critical authentication bypass in Aruba AOSSecurity Affairs·Mar 11, 11:28 UTC · Mar 11, 2026VulnerabilityCVE-2026-23813CVE-2026-23814CVE-2026-23815+3 CVEs60
Active exploitation of Cisco Catalyst SD-WAN by UATCisco Talos·Feb 25, 16:13 UTC · Feb 25, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2022-2077560
DockerDash Exposes AI Supply Chain Weakness In Docker's Ask GordonInfosecurity Magazine·Feb 3, 15:15 UTC · Feb 3, 2026Vulnerability155
ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware WavesThe Hacker News·Nov 21, 06:45 UTC · Nov 21, 2025MalwareCVE-2025-61757CVE-2025-1124360
Cisco ASA zero-day vulnerabilities exploited in sophisticated attacksHelp Net Security·Nov 13, 13:30 UTC · Nov 13, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Jenkins patched a critical RCE flaw in its open source automation serverSecurity Affairs·Oct 4, 15:37 UTC · Oct 4, 2025VulnerabilityCVE-2017-1000353CVE-2017-1000354CVE-2017-100035560
UK NCSC warns that attackers exploited Cisco firewall zero-days to deploy RayInitiator and LINE VIPER malwareSecurity Affairs·Sep 26, 11:49 UTC · Sep 26, 2025Exploit / PoCCVE-2025-20362CVE-2025-20333CVE-2025-2036360
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI CredentialsThe Hacker News·Sep 6, 11:31 UTC · Sep 6, 2025Malware55
HPE Issues Critical Security Patches for Aruba Access Point VulnerabilitiesThe Hacker News·Nov 11, 09:57 UTC · Nov 11, 2024Vulnerability in the wildCVE-2024-42509CVE-2024-47460CVE-2024-47461+3 CVEs60
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
CISA adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 8, 07:16 UTC · Jul 8, 2024Exploit / PoC in the wildCVE-2024-2039960
China-linked APT exploited Cisco NX-OS zeroSecurity Affairs·Jul 2, 07:25 UTC · Jul 2, 2024Exploit / PoC in the wildCVE-2024-2039960
LeakyCLI Flaw Exposes AWS and Google Cloud CredentialsInfosecurity Magazine·Apr 16, 14:15 UTC · Apr 16, 2024VulnerabilityCVE-2023-3605260
Multiple PoC exploits released for Jenkins flaw CVE-2024Security Affairs·Jan 28, 18:25 UTC · Jan 28, 2024Exploit / PoCCVE-2024-2389760
Comprehensive analysis of initial attack samples exploiting CVE-2023Kaspersky Securelist·Jul 19, 12:00 UTC · Jul 19, 2023Exploit / PoCCVE-2023-23397CVE-2023-2932460
Surge in Magento 2 template attacks exploiting CVE-2022Security Affairs·Sep 23, 13:55 UTC · Sep 23, 2022Exploit / PoC in the wildCVE-2022-2408660
Zyxel addressed a critical RCE flaw in its NAS devicesSecurity Affairs·Sep 7, 08:53 UTC · Sep 7, 2022VulnerabilityCVE-2022-34747CVE-2022-26532CVE-2022-0734+2 CVEs60
Orca Security unveils Shift Left Security capabilities to prevent cloud application issuesHelp Net Security·May 12, 00:00 UTC · May 12, 2022Vulnerability55