The Hacker News·23h ago criticalAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure#cve-2026-87902#exploit#malware 16 sources in the wild 2 min1
The Hacker News·1d agoWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session#comment2shell#cyber#exploit 6 sources in the wild 3 min
Cyber Security News·2d ago highHackers Exploited Ethereum Bridge Contract to Drain Full Balance from Payy Network#payy#ethereum#bridge 2 sources in the wild 3 min
SecurityWeek·4d ago highNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity#exploit#ms-defender#proof-of-concept 7 sources in the wild 2 min
The Hacker News·4d ago criticalZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access#command-execution#cve#endpoint 8 sources in the wild 2 min3
GBHackers·4d ago highCritical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands#cyber#exploit#malware in the wild 4 min2
Cyber Security News·4d ago criticalHackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords#campaign#china#data-theft 2 sources in the wild 5 min1
Hugging Face Blog·5d agoJun Kim, oMLX creator and maintainer, joins Hugging Face to support the MLX community#cyber#exploit#malwareThreat actor in the wild
The Hacker News·8d ago highPublic Exploits Released for Four Linux Kernel Flaws That Enable Local Root#exploit#ipsec#linux-kernel 2 sources 5 min
Metasploit Framework commits·10d agoAdd GitLab WorkHorse File Read Auxiliary Module (CVE-2026-85706)#cve-2026-85706#exploit#file-read1
The Register · Security·16d ago highHundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script#ai-agents#cve-2026-81578#cve-2026-82078 in the wild 4 min2
Dark Reading·16d agoNightmare-Eclipse Strikes Again with 'ShieldCrash' Windows Exploit#exploit#microsoft#shieldcrash2
The Hacker News·16d ago highPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances#ai-agents#authentication-bypass#education in the wild 5 min1
BleepingComputer·18d ago criticalGoogle warns of new Chrome zero-day bug exploited in attacks#chrome#exploit#googleExploit / PoC in the wild
Web discovery (articles for new exploits & KEV entries)·19d ago criticalWordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026 ...#cisa#exploit#kevCVE-2026-63030 in the wild 2 min1
The Hacker News·19d ago highTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released#aspnet#exploit#padding-oracle 5 min1
Exploit-DB·24d ago[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution#exploit#exploit-db#metabaseExploit / PoC1
Exploit-DB·24d ago[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)#exploit#exploit-db#freepbxExploit / PoC2
Security Affairs·28d ago highPaperCut Zero-Day Under Active Attack: Emergency Patch Released#clop#emergency-patch#exploit in the wild 2 min1
The Hacker News·29d ago highCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable#balance-underflow#blockchain#cosmos in the wild 6 min
Exploit-DB·Aug 25, 2026[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE#exploit#mod-sql#pocCVE-2026-421671
Palo Alto Unit 42·Aug 19, 2026 highNew Mirai Variant Targeting Network Security Devices#botnet#d-link#exploit in the wild 15 min
Palo Alto Unit 42·Aug 17, 2026IoT Under Siege: The Anatomy of the Latest Mirai Campaign Leveraging Multiple IoT Exploits#botnet#cve-2023-1389#ddos in the wild 13 min1