Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP RequestsThe Hacker News·Jun 23, 11:30 UTC · Jun 23, 2026Exploit / PoC in the wildCVE-2026-47729CVE-2026-50012160
Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecastHelp Net Security·Jan 11, 00:00 UTC · Jan 11, 2026Exploit / PoC in the wildCVE-2025-69258CVE-2025-3716460
Urgent: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux DistrosThe Hacker News·Apr 2, 04:39 UTC · Apr 2, 2024Malware in the wildCVE-2024-309460
CISA adds Looney Tunables Linux bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:35 UTC · Nov 22, 2023Exploit / PoC in the wildCVE-2023-4911CVE-2017-984160
Microsoft discovers ‘several’ vulnerabilities affecting Linux desktop endpointsThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Vulnerability in the wildCVE-2022-29799CVE-2022-2980060
New Go-based Redigo malware targets Redis serversSecurity Affairs·Dec 1, 22:39 UTC · Dec 1, 2022Malware in the wildCVE-2022-054360
CISA adds Chrome, Redis bugs to Known Exploited Vulnerabilities CatalogSecurity Affairs·Mar 29, 07:56 UTC · Mar 29, 2022Exploit / PoC in the wildCVE-2022-1096CVE-2022-0543CVE-2022-21999+1 CVEs60
$45,000 bounty offered for Linux zero daysCyberScoop·Feb 8, 17:37 UTC · Feb 8, 2018Exploit / PoC in the wild60
Linux Kernel Gets Patch For YearsThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2017Vulnerability in the wildCVE-2017-263660
Dirty COW — Critical Linux Kernel Flaw Being Exploited in the WildThe Hacker News·Oct 25, 15:07 UTC · Oct 25, 2016Exploit / PoC in the wildCVE-2016-519560
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape ContainersThe Hacker News·Aug 7, 11:10 UTC · Aug 7, 2026Exploit / PoC in the wildCVE-2026-6456460
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsThe Hacker News·Aug 6, 17:58 UTC · Aug 6, 2026Exploit / PoC in the wildCVE-2026-64561CVE-2026-53359CVE-2026-4631660
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News·Jul 31, 11:17 UTC · Jul 31, 2026Exploit / PoC in the wildCVE-2026-66066CVE-2025-24293160
Researcher Says AI Helped Develop Linux TrafficThe Hacker News·Jul 28, 08:04 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-5326460
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News·Jun 29, 14:42 UTC · Jun 29, 2026Malware in the wildCVE-2026-43503CVE-2026-12569CVE-2026-47729+19 CVEs60
Public PoC Released for Critical libssh2 CVE-2026-55200 ClientThe Hacker News·Jun 29, 07:06 UTC · Jun 29, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2019-3855CVE-2026-55199+1 CVEs160
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, OpenThe Hacker News·Jun 9, 11:59 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-39987CVE-2026-31431CVE-2026-43284+1 CVEs160
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain ChaosThe Hacker News·May 26, 04:39 UTC · May 26, 2026Malware in the wildCVE-2026-46333CVE-2026-41091CVE-2026-45498+31 CVEs60
PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting ArchSecurity Affairs·May 20, 20:32 UTC · May 20, 2026Vulnerability in the wild60
DirtyDecrypt: PoC Released for yet another Linux flawSecurity Affairs·May 20, 07:36 UTC · May 20, 2026Exploit / PoC in the wildCVE-2026-31635CVE-2026-31431CVE-2026-43284+4 CVEs60
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-4630060
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-31431CVE-2022-27666CVE-2026-43284+1 CVEs60
Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)Help Net Security·May 11, 11:22 UTC · May 11, 2026Vulnerability in the wildCVE-2026-3143160
Dirty Frag: Unpatched Linux vulnerability delivers root accessHelp Net Security·May 11, 09:48 UTC · May 11, 2026Vulnerability in the wildCVE-2026-43284CVE-2026-43500CVE-2026-3143160
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-27681CVE-2026-34621CVE-2026-34619+7 CVEs60
Product showcase: Cross-platform and third-party endpoint patching with Action1Help Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Ransomware in the wild60
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 27, 14:54 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2018-14634CVE-2025-52691CVE-2026-21509+2 CVEs60
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-65046CVE-2026-0628CVE-2026-20805+5 CVEs160
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & MoreThe Hacker News·Dec 31, 05:07 UTC · Dec 31, 2025Malware in the wildCVE-2025-14847CVE-2020-12812CVE-2025-68664+7 CVEs260
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
⚡ Weekly Recap: NFC Fraud, Curly COMrades, NThe Hacker News·Nov 20, 10:46 UTC · Nov 20, 2025Phishing & fraud in the wildCVE-2025-8875CVE-2025-8876CVE-2025-26633+36 CVEs60
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Old Linux Kernel flaw CVE-2024Security Affairs·Oct 31, 18:17 UTC · Oct 31, 2025Ransomware in the wildCVE-2024-108660
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever ShippedThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-24990CVE-2025-59230CVE-2025-47827+5 CVEs160
Sudo local privilege escalation vulnerabilities fixed (CVE-2025-32462, CVE-2025-32463)Help Net Security·Sep 30, 09:28 UTC · Sep 30, 2025Vulnerability in the wildCVE-2025-32462CVE-2025-3246360
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 BugsThe Hacker News·Sep 11, 08:56 UTC · Sep 11, 2025Vulnerability in the wildCVE-2025-53791CVE-2025-55234CVE-2025-54914+9 CVEs60
Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL ServerThe Hacker News·Jul 10, 07:02 UTC · Jul 10, 2025Vulnerability in the wildCVE-2025-49719CVE-2025-47981CVE-2025-49735+9 CVEs60