Windows NTLM vulnerability exploited in multiple attack campaigns (CVE-2025-24054)Help Net Security·Apr 17, 00:00 UTC · Apr 17, 2025Vulnerability in the wildCVE-2025-24054CVE-2025-24071CVE-2024-43451160
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 BugsThe Hacker News·Sep 11, 08:56 UTC · Sep 11, 2025Vulnerability in the wildCVE-2025-53791CVE-2025-55234CVE-2025-54914+9 CVEs60
Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)Help Net Security·May 12, 08:27 UTC · May 12, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs160
Critical Exchange Server Flaw (CVE-2024The Hacker News·Feb 17, 07:27 UTC · Feb 17, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-21351CVE-2024-21412+1 CVEs160
How NTLM is being abused in 2025 cyberattacksKaspersky Securelist·Nov 26, 15:53 UTC · Nov 26, 2025Exploit / PoC in the wild160
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 ScoreThe Hacker News·Feb 6, 09:36 UTC · Feb 6, 2026Vulnerability in the wildCVE-2026-24423CVE-2026-23760CVE-2026-2506760
Week in review: Sudo local privilege escalation flaws fixed, Google patches actively exploited ChromeHelp Net Security·Jul 6, 00:00 UTC · Jul 6, 2025Vulnerability in the wildCVE-2025-32462CVE-2025-32463CVE-2025-6554+4 CVEs60
Microsoft Patches 67 Vulnerabilities Including WEBDAV ZeroThe Hacker News·Jun 12, 15:47 UTC · Jun 12, 2025Vulnerability in the wildCVE-2025-33053CVE-2025-47966CVE-2025-32713+3 CVEs160
Microsoft Releases June 2019 Security Updates to Patch 88 VulnerabilitiesThe Hacker News·Jun 11, 18:49 UTC · Jun 11, 2019Vulnerability in the wildCVE-2019-1040CVE-2019-1019CVE-2019-0620+2 CVEs60
Threat Brief: Microsoft Critical Vulnerabilities (CVE-2022-26809, CVE-2022-26923, CVE-2022Palo Alto Unit 42·Jun 5, 20:13 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-26809CVE-2022-26923CVE-2022-26925160
Microsoft Releases Fix for New ZeroThe Hacker News·May 11, 16:06 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+14 CVEs60
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-34621260
November 2024 Patch Tuesday forecast: New servers arrive earlyHelp Net Security·Nov 11, 00:00 UTC · Nov 11, 2024Vulnerability in the wildCVE-2024-43451CVE-2024-4903960
⚡ Weekly Recap: iOS Zero-Days, 4Chan Breach, NTLM Exploits, WhatsApp Spyware & MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025Malware in the wildCVE-2025-24054CVE-2024-43451CVE-2025-31200+7 CVEs160
⚡ Weekly Recap: NFC Fraud, Curly COMrades, NThe Hacker News·Nov 20, 10:46 UTC · Nov 20, 2025Phishing & fraud in the wildCVE-2025-8875CVE-2025-8876CVE-2025-26633+36 CVEs60
Microsoft Patch Tuesday fix Outlook zeroSecurity Affairs·Mar 26, 12:22 UTC · Mar 26, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-24880160
Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS VulnerabilityThe Hacker News·Dec 11, 15:01 UTC · Dec 11, 2024Vulnerability in the wildCVE-2024-49138CVE-2022-24521CVE-2022-37969+6 CVEs60
Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet FirewallsInfosecurity Magazine·Feb 23, 12:30 UTC · Feb 23, 2026Threat actor in the wildCVE-2019-7192CVE-2023-27532CVE-2024-40711160
Researchers uncover 4G LTE exploits that can be used to spy, spoof and cause panicCyberScoop·Mar 5, 17:28 UTC · Mar 5, 2018Exploit / PoC in the wild60
H1 2025 Malware and Vulnerability TrendsRecorded Future·Nov 13, 00:00 UTC · Nov 13, 2025Vulnerability in the wild60
CISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202)Help Net Security·Apr 29, 00:00 UTC · Apr 29, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513160
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026The Hacker News·Apr 28, 05:50 UTC · Apr 28, 2026Exploit / PoC in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513160
Threat Advisory: Microsoft Outlook privilege escalation vulnerability being exploited in the wildCisco Talos·Mar 15, 23:46 UTC · Mar 15, 2023Exploit / PoC in the wildCVE-2023-2339760
PoC exploit for Ivanti Endpoint Manager vulnerabilities released (CVE-2024-13159)Help Net Security·Feb 24, 00:00 UTC · Feb 24, 2025Exploit / PoC in the wildCVE-2024-13159CVE-2024-10811CVE-2024-13161+1 CVEs60
17,000+ Microsoft Exchange servers in Germany are vulnerable to attack, BSI warnsHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2024Exploit / PoC in the wildCVE-2024-21410CVE-2024-2619860
Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device ManagerThe Hacker News·Jan 9, 09:52 UTC · Jan 9, 2024Vulnerability in the wildCVE-2023-50916CVE-2023-39296CVE-2023-47559+4 CVEs60
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, ZeroThe Hacker News·Oct 14, 10:56 UTC · Oct 14, 2025Malware in the wildCVE-2025-2104360
CISA warns of attacks using Microsoft Word, Adobe bugsThe Record·Sep 12, 21:22 UTC · Sep 12, 2023Advisory in the wildCVE-2023-36761CVE-2023-36802CVE-2023-26369160
Microsoft patches actively exploited zero-day (CVE-2021-36948), more Print Spooler flawsHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2021Exploit / PoC in the wildCVE-2021-36948CVE-2021-36936CVE-2021-34483+3 CVEs160
Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint ManagerThe Hacker News·Feb 20, 10:44 UTC · Feb 20, 2025Exploit / PoC in the wildCVE-2024-10811CVE-2024-13161CVE-2024-13160+3 CVEs60
Microsoft Patch Tuesday, May 2022 EditionKrebs on Security·May 11, 12:33 UTC · May 11, 2022Vulnerability in the wildCVE-2022-26925CVE-2021-36942CVE-2022-26937160
Microsoft Fixes Three ZeroInfosecurity Magazine·May 11, 09:00 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs60
Researchers Find Exploit Allowing NTLMv1 Despite Active Directory RestrictionsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Exploit / PoC in the wild60
AI-powered campaign compromises 600 FortiGate systems worldwideSecurity Affairs·Feb 23, 10:39 UTC · Feb 23, 2026Threat actor in the wildCVE-2019-7192CVE-2023-27532CVE-2024-40711160
Legacy Windows Protocols Still Expose Networks to Credential TheftInfosecurity Magazine·Oct 14, 16:45 UTC · Oct 14, 2025Vulnerability in the wild60
Microsoft Releases Windows Updates to Patch Actively Exploited VulnerabilityThe Hacker News·Aug 11, 05:31 UTC · Aug 11, 2021Vulnerability in the wildCVE-2021-36948CVE-2021-36942CVE-2021-36936+4 CVEs60
December 2023 Patch Tuesday: 33 fixes to wind the year downHelp Net Security·Dec 12, 00:00 UTC · Dec 12, 2023Vulnerability in the wildCVE-2023-35628CVE-2023-35636CVE-2023-23397+4 CVEs60
Microsoft, Adobe, SAP deliver critical fixes for September 2025 Patch TuesdayHelp Net Security·Sep 10, 00:00 UTC · Sep 10, 2025Vulnerability in the wildCVE-2025-54918CVE-2025-54916CVE-2025-55232+8 CVEs60
NTLM Hash Exploit Targets Poland and Romania Days After PatchInfosecurity Magazine·Apr 17, 16:45 UTC · Apr 17, 2025Vulnerability in the wildCVE-2025-24054CVE-2024-43451CVE-2025-24071160
Microsoft Patch Tuesday, March 2023 EditionKrebs on Security·Mar 15, 00:00 UTC · Mar 15, 2023Vulnerability in the wildCVE-2023-23397CVE-2023-2488060