Why React Didn't Kill XSS: The New JavaScript Injection PlaybookThe Hacker News·Jul 29, 10:00 UTC · Jul 29, 2025Vulnerability55
Adobe released out-of-band updates for After Effects and Media EncoderSecurity Affairs·Feb 20, 15:36 UTC · Feb 20, 2020VulnerabilityCVE-2020-3765CVE-2020-376460
Out-of-band security update fixes Adobe Media Encoder issueSecurity Affairs·Sep 15, 21:14 UTC · Sep 15, 2020VulnerabilityCVE-2020-9739CVE-2020-9744CVE-2020-974560
Adobe fixes over a dozen flaws in Media Encoder, Download ManagerSecurity Affairs·Jul 14, 17:59 UTC · Jul 14, 2020VulnerabilityCVE-2020-9688CVE-2020-9669CVE-2020-9671+3 CVEs60
Adobe addressed critical flaws in Media Encoder and Illustrator productsSecurity Affairs·Nov 13, 13:19 UTC · Nov 13, 2019Exploit / PoCCVE-2019-8246CVE-2019-8247CVE-2019-824860
Adobe Patches Critical Bugs Affecting Media Encoder and After EffectsThe Hacker News·Feb 20, 10:09 UTC · Feb 20, 2020Vulnerability in the wildCVE-2020-3765CVE-2020-376460
Adobe Releases Critical Patches for Flash, Acrobat Reader, and Media EncoderThe Hacker News·May 15, 00:00 UTC · May 15, 2019Vulnerability in the wildCVE-2019-7837CVE-2019-784260
Moodle vulnerability exposed users to account takeoverSecurity Affairs·Apr 8, 20:22 UTC · Apr 8, 2021Vulnerability55
Operation PowerFall: CVE-2020Kaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2020Exploit / PoCCVE-2020-098660
New Wekby Attacks Use DNS Requests As Command and Control MechanismPalo Alto Unit 42·Nov 1, 10:15 UTC · Nov 1, 2018Exploit / PoC60
New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel ImplantsCisco Talos·Sep 19, 12:00 UTC · Sep 19, 2023Malware55
Friday Squid Blogging: Giant Squid ArtSchneier on Security·Nov 12, 22:16 UTC · Nov 12, 2021Ransomware60
Adobe Patch Tuesday patches fix over 80 flaws in Flash, Acrobat Reader, and Media EncoderSecurity Affairs·May 15, 06:14 UTC · May 15, 2019VulnerabilityCVE-2019-7837CVE-2019-784260
Malware Using the Registry to Store a Zeus Configuration FileCisco Talos·Sep 4, 17:00 UTC · Sep 4, 2014Malware55
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Magnitude exploit kitKaspersky Securelist·Jun 24, 10:00 UTC · Jun 24, 2020Ransomware in the wildCVE-2018-8174CVE-2018-8653CVE-2019-1367+3 CVEs60
Equation Group: from Houston with loveKaspersky Securelist·Feb 19, 09:00 UTC · Feb 19, 2015Vulnerability55
Bad Apples: Weaponizing native macOS primitives for movement and executionCisco Talos·Apr 21, 10:00 UTC · Apr 21, 2026Industry55
CERT/CC Warns binary-parser Bug Allows Node.js PrivilegeThe Hacker News·Jan 27, 14:10 UTC · Jan 27, 2026VulnerabilityCVE-2026-124560
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
A new Chrome 0-day is sending the Internet into a new chapter of Groundhog DayArs Technica · Security·Sep 28, 21:23 UTC · Sep 28, 2023Exploit / PoCCVE-2023-5217CVE-2023-486360
A Data Exfiltration Attack Scenario: The Porsche ExperienceThe Hacker News·Jul 28, 11:48 UTC · Jul 28, 2023Exploit / PoC60
Manjusaka: A Chinese sibling of Sliver and Cobalt StrikeCisco Talos·Aug 2, 12:00 UTC · Aug 2, 2022Malware55
UPS: Observations on CVE-2015-3113, Prior ZeroPalo Alto Unit 42·Nov 1, 09:48 UTC · Nov 1, 2018VulnerabilityCVE-2015-3113CVE-2014-1776CVE-2014-633260
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AICisco Talos·Aug 4, 10:00 UTC · Aug 4, 2026Vulnerability55
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
CISA Adds Exploited Magento RCE Flaw CVE-2026The Hacker News·Jun 4, 11:53 UTC · Jun 4, 2026Vulnerability in the wildCVE-2026-4524760
Semgrep Multimodal brings AI reasoning and rule-based analysis to code securityHelp Net Security·Mar 20, 00:00 UTC · Mar 20, 2026Exploit / PoC160
Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical InfrastructureThe Hacker News·Mar 9, 18:22 UTC · Mar 9, 2026Vulnerability55
UAT-7290 targets high value telecommunications infrastructure in South AsiaCisco Talos·Jan 8, 11:00 UTC · Jan 8, 2026Exploit / PoC60
5 Threats That Reshaped Web Security This Year [2025]The Hacker News·Dec 4, 11:30 UTC · Dec 4, 2025VulnerabilityCVE-2025-54135CVE-2025-53109CVE-2025-5528460
Mem3nt0 moriKaspersky Securelist·Oct 27, 03:00 UTC · Oct 27, 2025Exploit / PoC in the wildCVE-2025-278360
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer AttacksThe Hacker News·Sep 24, 11:03 UTC · Sep 24, 2025Vulnerability in the wild60
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
U.S. CISA adds Apache Tomcat flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 2, 13:47 UTC · Apr 2, 2025Exploit / PoC in the wildCVE-2025-2481360
Threat actors rapidly exploit new Apache Tomcat flaw following PoC releaseSecurity Affairs·Mar 17, 19:59 UTC · Mar 17, 2025Exploit / PoC in the wildCVE-2025-2481360
Microsoft Detects New XCSSET MacOS Malware VariantInfosecurity Magazine·Feb 17, 14:30 UTC · Feb 17, 2025Malware55