T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
Kaspersky found multiple memory corruptions in Suricata and FreeRDPKaspersky Securelist·Aug 22, 12:50 UTC · Aug 22, 2024VulnerabilityCVE-2024-32041CVE-2024-32039CVE-2024-32040+4 CVEs60
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark CyberattacksThe Hacker News·Jun 27, 12:06 UTC · Jun 27, 2026MalwareCVE-2021-26855CVE-2023-32315CVE-2024-36401+10 CVEs60
FamousSparrow targets Azerbaijani energy sector in multiSecurity Affairs·May 14, 08:17 UTC · May 14, 2026Vulnerability55
Coruna framework: an exploit kit and ties to Operation TriangulationKaspersky Securelist·Mar 26, 08:00 UTC · Mar 26, 2026Exploit / PoCCVE-2023-32434CVE-2023-3860660
ThreatsDay Bulletin: OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & MoreThe Hacker News·Mar 12, 15:00 UTC · Mar 12, 2026Phishing & fraud in the wild60
UAT-9244 targets South American telecommunication providers with three new malware implantsCisco Talos·Mar 5, 11:00 UTC · Mar 5, 2026Malware55
Keenadu the tablet conqueror and the links between major Android botnetsKaspersky Securelist·Feb 17, 09:00 UTC · Feb 17, 2026Malware55
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update AttacksRecorded Future·Jul 4, 00:00 UTC · Jul 4, 2024Malware55
New Vulnerability Affecting Container Engines CRI-O and Podman (CVE-2021Palo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024VulnerabilityCVE-2021-20291160
PoCs for critical Arcserve UDP vulnerabilities releasedHelp Net Security·Nov 29, 00:00 UTC · Nov 29, 2023VulnerabilityCVE-2023-41998CVE-2023-41999CVE-2023-4200060
Lockbit leak, research opportunities on tools leaked from TAsKaspersky Securelist·Aug 25, 10:00 UTC · Aug 25, 2023Ransomware60
SMBleed: A New Critical Vulnerability Affects Windows SMB ProtocolThe Hacker News·Jun 10, 03:44 UTC · Jun 10, 2020VulnerabilityCVE-2020-1206CVE-2020-079660
Sextortion profits decline despite higher volume, new techniquesCisco Talos·Apr 11, 17:37 UTC · Apr 11, 2019Ransomware60
System restore: How stressed security bosses unwind from the daily grindCyberScoop·Jan 16, 14:00 UTC · Jan 16, 2019Exploit / PoC in the wild60
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZSecurity Affairs·Jul 20, 10:58 UTC · Jul 20, 2026Vulnerability in the wildCVE-2025-1100160
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, DeviceThe Hacker News·Jun 18, 15:29 UTC · Jun 18, 2026Exploit / PoCCVE-2026-2012760
China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom AttacksThe Hacker News·Mar 6, 08:22 UTC · Mar 6, 2026Malware55
Wormable XMRig campaign leverages BYOVD and timed kill switch for stealthSecurity Affairs·Feb 23, 18:36 UTC · Feb 23, 2026Threat actor60
U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 30, 08:33 UTC · Dec 30, 2025Exploit / PoC in the wildCVE-2025-1484760
MongoBleed flaw actively exploited in attacks in the wildSecurity Affairs·Dec 29, 23:21 UTC · Dec 29, 2025Exploit / PoC in the wildCVE-2025-1484760
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More StoriesThe Hacker News·Dec 4, 16:05 UTC · Dec 4, 2025Phishing & fraud55
August 2025 CVE LandscapeRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware in the wildCVE-2025-8088CVE-2025-7775CVE-2025-57819+5 CVEs60
Wordfence blocks 8.7M attacks exploiting old GutenKit and Hunk Companion flawsSecurity Affairs·Oct 27, 08:40 UTC · Oct 27, 2025VulnerabilityCVE-2024-9234CVE-2024-9707CVE-2024-1197260
SonicWall fixed critical flaw in SMA 100 devices exploited in Overstep malware attacksSecurity Affairs·Jul 24, 13:01 UTC · Jul 24, 2025MalwareCVE-2025-40599CVE-2024-3847560
UNC6148 deploys Overstep malware on SonicWall devices, possibly for ransomware operationsSecurity Affairs·Jul 17, 07:47 UTC · Jul 17, 2025RansomwareCVE-2024-3847560
LapDogs: China-nexus hackers Hijack 1,000+ SOHO devices for espionageSecurity Affairs·Jun 28, 13:29 UTC · Jun 28, 2025Threat actorCVE-2015-1548CVE-2017-1766360
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilitiesCisco Talos·Jun 11, 14:03 UTC · Jun 11, 2025Exploit / PoCCVE-2024-48877CVE-2024-52035CVE-2024-54028+6 CVEs60
Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation ConfirmedThe Hacker News·May 10, 06:43 UTC · May 10, 2025Exploit / PoC in the wildCVE-2025-34028CVE-2025-392860
New Bootkit “Bootkitty” Targets Linux Systems via UEFIInfosecurity Magazine·Nov 27, 16:30 UTC · Nov 27, 2024Exploit / PoC60
Previously unseen Msupedge backdoor targeted a university in TaiwanSecurity Affairs·Aug 20, 17:27 UTC · Aug 20, 2024MalwareCVE-2024-457760
Why CISOs need to build cyber fault tolerance into their businessHelp Net Security·Jun 10, 00:00 UTC · Jun 10, 2024Tools55
#Infosec2024: Experts Share How CISOs Can Manage ChangeInfosecurity Magazine·Jun 6, 14:30 UTC · Jun 6, 2024Policy & legal55
Banking Trojan Techniques: How Financially Motivated Malware Became InfrastructurePalo Alto Unit 42·Jun 5, 17:45 UTC · Jun 5, 2024Malware55