‘Trojan Source’ Bug Threatens the Security of All CodeKrebs on Security·Nov 1, 05:21 UTC · Nov 1, 2021Malware55
Trojan Source bugs may lead to extensive supply-chain attacks on source codeHelp Net Security·Nov 2, 00:00 UTC · Nov 2, 2021MalwareCVE-2021-42574CVE-2021-4269460
Verisign, Amazon patch zero-day vulnerability that utilized homoglyph charactersCyberScoop·Mar 5, 23:15 UTC · Mar 5, 2020Exploit / PoC in the wild60
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & MoreThe Hacker News·Nov 3, 17:59 UTC · Nov 3, 2025Threat actorCVE-2025-61932CVE-2025-55315CVE-2025-10680+18 CVEs160
Vulnerability allows attackers to register malicious lookalikes of legitimate web domainsHelp Net Security·Mar 5, 00:00 UTC · Mar 5, 2020Vulnerability55
UPS: Observations on CVE-2015-3113, Prior ZeroPalo Alto Unit 42·Nov 1, 09:48 UTC · Nov 1, 2018VulnerabilityCVE-2015-3113CVE-2014-1776CVE-2014-633260
GlassWorm malware has resurfaced on the Open VSX registrySecurity Affairs·Nov 10, 20:06 UTC · Nov 10, 2025Malware55
4 Ways to Improve Security Using Recorded Future DNS IntelligenceRecorded Future·Aug 12, 00:00 UTC · Aug 12, 2025Malware55
TAG-140 Deploys DRAT V2 RAT, Targeting Indian Government, Defense, and Rail SectorsThe Hacker News·Jul 7, 17:00 UTC · Jul 7, 2025Malware55
⚡ Weekly Recap: Windows 0-Day, VPN Exploits, Weaponized AI, Hijacked Antivirus and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-29824CVE-2024-11859CVE-2025-3102+17 CVEs60
Security Affairs newsletter Round 413 by Pierluigi PaganiniSecurity Affairs·Apr 2, 15:10 UTC · Apr 2, 2023Ransomware in the wildCVE-2023-23529CVE-2023-23397CVE-2023-22809+1 CVEs60
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wildCisco Talos·Dec 10, 19:37 UTC · Dec 10, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
Internet Explorer and Windows zeroKaspersky Securelist·Aug 12, 07:00 UTC · Aug 12, 2020Exploit / PoCCVE-2020-0986CVE-2020-1380CVE-2020-0674+3 CVEs60
There's a new 'text bomb' that will crash iPhones with a single symbolCyberScoop·Feb 16, 19:13 UTC · Feb 16, 2018Exploit / PoC in the wild60
Hackers Exploit 'Telegram Messenger' ZeroThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2018Exploit / PoC in the wild60
Hackers in the Russian underground exploited a Telegram ZeroSecurity Affairs·Feb 13, 21:17 UTC · Feb 13, 2018Exploit / PoC in the wild60
Passwords Evolved: Authentication Guidance for the Modern EraTroy Hunt·Jul 26, 07:40 UTC · Jul 26, 2017Data breach60
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 ConflictRecorded Future·Jul 16, 00:00 UTC · Jul 16, 2026Malware55
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New StoriesThe Hacker News·Jun 4, 14:00 UTC · Jun 4, 2026Malware in the wildCVE-2026-20230160
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
One Missed Threat Per Week: What 25M Alerts Reveal About LowThe Hacker News·May 8, 10:30 UTC · May 8, 2026Exploit / PoC60
Thousands of Adobe Commerce stores hacked in competing CosmicSting campaignsSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Threat actorCVE-2024-3410260
CosmicSting attack & defense overviewSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Data breach in the wildCVE-2024-2961CVE-2024-3410260
ThreatsDay Bulletin: DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs RisingThe Hacker News·Nov 5, 10:38 UTC · Nov 5, 2025Malware in the wildCVE-2017-1188260
Wiz Uncovers Critical Access Bypass Flaw in AIThe Hacker News·Jul 30, 07:43 UTC · Jul 30, 2025Exploit / PoC in the wild60
Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and MalwareThe Hacker News·Jul 29, 09:05 UTC · Jul 29, 2025MalwareCVE-2023-38950CVE-2023-38951CVE-2023-3895260
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden PromptsThe Hacker News·May 23, 04:34 UTC · May 23, 2025Vulnerability55
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
Google fixed two actively exploited Android flawsSecurity Affairs·Mar 4, 13:29 UTC · Mar 4, 2025Exploit / PoC in the wildCVE-2024-43093CVE-2024-50302CVE-2024-53104+1 CVEs60
What NIST’s latest password standards mean, and why the old ones weren’t workingCisco Talos·Oct 10, 18:00 UTC · Oct 10, 2024Data breach in the wildCVE-2024-43572CVE-2024-4357360
CISA is warning us (again) about the threat to critical infrastructure networksCisco Talos·Oct 3, 18:00 UTC · Oct 3, 2024Ransomware60
THN Cybersecurity Recap: Last Week's Top Threats and Trends (September 23The Hacker News·Sep 30, 13:22 UTC · Sep 30, 2024Ransomware in the wildCVE-2024-810560
Microsoft 365 Copilot Vulnerability Exposes User Data RisksInfosecurity Magazine·Aug 27, 17:15 UTC · Aug 27, 2024Vulnerability155
Analyzing the vulnerability landscape in Q2 2024Kaspersky Securelist·Aug 21, 07:41 UTC · Aug 21, 2024VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Microsoft Patch Tuesday security updates for August 2024 six actively exploited bugsSecurity Affairs·Aug 14, 07:17 UTC · Aug 14, 2024Vulnerability in the wildCVE-2024-38189CVE-2024-38178CVE-2024-38193+12 CVEs260
Here’s how carefully concealed backdoor in fake AWS files escaped mainstream noticeArs Technica · Security·Jul 15, 00:00 UTC · Jul 15, 2024Malware55