Windows 11 to Deprecate NTLM, Add AI-Powered App Controls and Security DefensesThe Hacker News·Jun 6, 09:16 UTC · Jun 6, 2024Exploit / PoC60
Critical flaw found in deprecated VMware EAP. Uninstall it nowSecurity Affairs·Feb 21, 11:37 UTC · Feb 21, 2024RansomwareCVE-2024-22245CVE-2024-2225060
Attackers bypass patch in deprecated Windows Server update toolCyberScoop·Oct 27, 20:03 UTC · Oct 27, 2025Vulnerability in the wildCVE-2025-5928760
Google Postpones Third-Party Cookie Deprecation Amid U.K. Regulatory ScrutinyThe Hacker News·Apr 25, 16:11 UTC · Apr 25, 2024Policy & legal55
Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" PackageThe Hacker News·Jan 19, 07:42 UTC · Jan 19, 2024Malware55
NIST wants agencies to move away from SMS authenticationCyberScoop·Jul 31, 19:29 UTC · Jul 31, 2016Exploit / PoC in the wild60
ROBOT Attack: RSA TLS crypto attack worked against Facebook, PayPal, and tens of 100 top domainsSecurity Affairs·Dec 13, 16:19 UTC · Dec 13, 2017Exploit / PoCCVE-2017-6168CVE-2017-17382CVE-2017-17427+6 CVEs60
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2026Malware in the wildCVE-2026-11645CVE-2026-2441CVE-2026-3909+23 CVEs160
Check Point Warns Critical Auth Bypass Bug Exploited in the WildInfosecurity Magazine·Jun 9, 09:30 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-50751CVE-2026-5075260
Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limitsHelp Net Security·Apr 19, 00:00 UTC · Apr 19, 2026Data breach in the wildCVE-2026-34621CVE-2026-39813CVE-2026-3980860
Vendors defeat Magento security patch (+ simple check)Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2022-24086CVE-2022-24087CVE-2026-7565060
Microsoft will finally kill obsolete cipher that has wreaked decades of havocArs Technica · Security·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability55
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild160
Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across TenantsThe Hacker News·Sep 24, 10:50 UTC · Sep 24, 2025Vulnerability in the wildCVE-2025-55241CVE-2025-53786160
Senator Wyden Urges FTC to Probe Microsoft for RansomwareThe Hacker News·Sep 12, 12:00 UTC · Sep 12, 2025Ransomware60
Senator blasts Microsoft for making default Windows vulnerable to “Kerberoasting”Ars Technica · Security·Sep 10, 19:38 UTC · Sep 10, 2025Ransomware60
Secure Vibe Coding: The Complete New GuideThe Hacker News·Jun 19, 11:25 UTC · Jun 19, 2025Vulnerability55
Patch Tuesday, June 2025 EditionKrebs on Security·Jun 11, 02:03 UTC · Jun 11, 2025Vulnerability in the wildCVE-2025-33053CVE-2025-33073CVE-2025-5419+1 CVEs60
Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS VulnerabilityThe Hacker News·Dec 11, 15:01 UTC · Dec 11, 2024Vulnerability in the wildCVE-2024-49138CVE-2022-24521CVE-2022-37969+6 CVEs60
Google’s Heather Adkins on infostealers, two-factor authentication and fixing the security ‘mess’ for future generationsThe Record·Oct 15, 14:39 UTC · Oct 15, 2024Malware in the wild60
Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)Help Net Security·Oct 8, 00:00 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43573CVE-2024-43572CVE-2024-38112+3 CVEs60
Vulnerable APIs and Bot Attacks Costing Businesses Up to $186 Billion AnnuallyThe Hacker News·Oct 7, 11:25 UTC · Oct 7, 2024Vulnerability55
Overlooked essentials: API security best practicesHelp Net Security·Sep 19, 11:38 UTC · Sep 19, 2024Data breach60
Unpatched MS Office flaw may leak NTLM hashes to attackers (CVE-2024-38200)Help Net Security·Aug 12, 00:00 UTC · Aug 12, 2024VulnerabilityCVE-2024-38200160
June 2024 Patch Tuesday forecast: Multiple announcements from MicrosoftHelp Net Security·Jun 12, 06:51 UTC · Jun 12, 2024VulnerabilityCVE-2024-30080CVE-2024-3010360
VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at RiskThe Hacker News·Feb 22, 02:28 UTC · Feb 22, 2024VulnerabilityCVE-2024-22245CVE-2024-22250CVE-2024-2172660
Alation Connected Sheets enables business users to pull data from other sources into spreadsheetsHelp Net Security·Jan 11, 12:09 UTC · Jan 11, 2024Policy & legal55
A Few More Reasons Why RDP is Insecure (Surprise!)The Hacker News·Jul 20, 10:48 UTC · Jul 20, 2023Data breachCVE-2023-24905CVE-2023-3533260
Why Developers Hate Changing Language VersionsThe Hacker News·Jul 8, 11:08 UTC · Jul 8, 2022Vulnerability55
A server of the Jenkins project hacked by exploiting a Confluence flawSecurity Affairs·Sep 7, 13:04 UTC · Sep 7, 2021RansomwareCVE-2021-2608460
The crypto-agility mandate, and how to get thereHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2020Vulnerability55
6.8% of the top 100,000 websites still accept old, insecure SSL versionsHelp Net Security·Mar 10, 14:45 UTC · Mar 10, 2019Malware55
Chrome, Firefox, Edge and Safari Plans to Disable TLS 1.0 and 1.1 in 2020The Hacker News·Oct 15, 00:00 UTC · Oct 15, 2018Vulnerability55
VMware addresses a critical remote code execution vulnerability in AirWatch AgentSecurity Affairs·Jun 12, 12:22 UTC · Jun 12, 2018VulnerabilityCVE-2018-696860
The Internet Engineering Task Force has finally announced the approval of TLS 1.3Security Affairs·Mar 26, 11:59 UTC · Mar 26, 2018Vulnerability55
Cisco Meeting Server- CVE-2016-6445 allows to impersonate legitimate usersSecurity Affairs·Oct 14, 05:52 UTC · Oct 14, 2016Vulnerability in the wildCVE-2016-644560
Microsoft Security Updates November 2015Kaspersky Securelist·Nov 10, 22:13 UTC · Nov 10, 2015Vulnerability55
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2GHelp Net Security·Aug 11, 00:00 UTC · Aug 11, 2026VulnerabilityCVE-2025-4861860
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkThe Hacker News·Jul 27, 06:30 UTC · Jul 27, 2026Phishing & fraudCVE-2024-6587CVE-2026-40217CVE-2026-3502960