Collections

CISA KEV — Actively Exploited Collection

Vulnerabilities confirmed to be under active exploitation in the wild.

2026-07-30 · MEDIUM

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

2026-07-29 · HIGH

Cisco warns of FMC static credential flaw exploited in zero-day attacks

CVE-2026-20316
2026-07-29 · MEDIUM

Hugging Face built an interactive replay of the OAl agent that breached them

2026-07-29 · HIGH

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

CVE-2026-66066
2026-07-29 · CRITICAL

WP2Shell WordPress Exploit Technical Analysis and Real Attack Data

2026-07-29 · MEDIUM

Only 1% of AI-discovered vulnerabilities have actually been exploited in the wild - a rate that matches standard, human-found bugs.

2026-07-29 · HIGH

CodeAlpha_SecureCodingReview exploit

2026-07-29 · HIGH

Binary-Exploitation exploit

2026-07-29 · HIGH

Stored-XSS-via-Content-Tag-Names-Microweber- exploit

2026-07-29 · HIGH

Exploit for Improper Authentication in Redhat Keycloak exploit

2026-07-29 · HIGH

Exploit for CVE-2026-53921 exploit

CVE-2026-53921
2026-07-29 · HIGH

Exploit for Improper Authentication in Checkpoint Multi-Domain_Security_Management exploit

2026-07-29 · HIGH

Exploit for CVE-2026-65761 exploit

CVE-2026-65761
2026-07-29 · HIGH

exploit-counter exploit

2026-07-29 · MEDIUM

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

2026-07-29 · LOW

First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face

2026-07-29 · MEDIUM

Our biggest AI security issue wasn't prompt leakage. It was what people built afterward.

2026-07-29 · HIGH

handlebars-ssti-ast-rce exploit

2026-07-29 · HIGH

Exploit for CVE-2026-64725 exploit

CVE-2026-64725
2026-07-29 · HIGH

CVE-Vulnerability-Reproduction exploit

2026-07-29 · HIGH

Exploit for Use of Hard-coded Credentials in Solarwinds Web_Help_Desk exploit

2026-07-28 · MEDIUM

OpenAI models used Artifactory zero-days to escape to the internet

2026-07-28 · MEDIUM

What do you do with CVEs you can't fix? Auditor wants proof they're 'not exploitable'

2026-07-28 · MEDIUM

Claude Mythos degrades HAWK and developed new exploit for round-reduced AES

2026-07-28 · MEDIUM

vBulletin fixes critical pre-auth RCE flaw with public exploit

2026-07-28 · MEDIUM

Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs

2026-07-28 · HIGH

Bugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation

2026-07-28 · HIGH

Root-My-Device-Payloads exploit

2026-07-28 · HIGH

Exploit for Classic Buffer Overflow in Tp-Link Tl-Wr841_Firmware exploit

2026-07-28 · HIGH

Exploit for Insertion of Sensitive Information into Log File in Ayesa Ibermatica_Rps exploit

2026-07-28 · HIGH

vulnerable-forum exploit

2026-07-28 · HIGH

Exploit for Incorrect Authorization in F5 Nginx_Plus exploit

2026-07-28 · HIGH

Hackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations

2026-07-28 · MEDIUM

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

2026-07-28 · LOW

Exploit for CVE-2026-59891

CVE-2026-59891
2026-07-28 · HIGH

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

CVE-2013-4786
2026-07-28 · HIGH

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

2026-07-28 · HIGH

Exploit for CVE-2026-8206 exploit

CVE-2026-8206
2026-07-28 · HIGH

Web-Server-Log-Parser-Threat-Detector exploit

2026-07-28 · HIGH

study_embedded_security exploit

2026-07-28 · HIGH

Exploit for Cross-site Scripting in Spip exploit

2026-07-28 · HIGH

kernel-exploit-dirty-cow-project exploit

2026-07-28 · LOW

LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed

2026-07-28 · MEDIUM

Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker

2026-07-28 · CRITICAL

U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog

2026-07-28 · MEDIUM

Has the Hugging Face incident changed anyone else’s view on open vs closed AI models for cybersecurity?

2026-07-28 · MEDIUM

Automated AI penetration testing with Claude Code or Codex: what setup actually works best?

2026-07-28 · HIGH

mt6897-unlock-attempt exploit

2026-07-28 · HIGH

Exploit for CVE-2026-40000 exploit

CVE-2026-40000
2026-07-28 · HIGH

Exploit for CVE-2026-39875 exploit

CVE-2026-39875
2026-07-28 · CRITICAL

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

2026-07-28 · CRITICAL

CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks

2026-07-28 · CRITICAL

Hackers Exploiting Arista VeloCloud Orchestrator 0-Day Vulnerability in the Wild

2026-07-28 · MEDIUM

Unpatched Fastjson Vulnerability Exploited in Attacks

2026-07-28 · HIGH

Exploit for CVE-2026-9830 exploit

CVE-2026-9830
2026-07-28 · HIGH

flask-kvsession-pickle-rce exploit

2026-07-28 · MEDIUM

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

2026-07-28 · MEDIUM

Hackers target US firms in FastJson RCE zero-day attacks

2026-07-27 · MEDIUM

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

2026-07-27 · HIGH

Exploit for CVE-2026-42533 exploit

CVE-2026-42533
2026-07-27 · HIGH

pentest-confirm-mcp exploit

2026-07-27 · HIGH

Exploit for Path Traversal in Mate-Desktop Atril exploit

2026-07-27 · MEDIUM

New Certighost PoC exploit lets attackers hijack Windows domains

2026-07-27 · MEDIUM

Adversaries Don't Need a Zero-Day — They Read Your Rulebook

2026-07-27 · LOW

Sextortion scammers are exploiting ShinyHunters data leaks

2026-07-27 · MEDIUM

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

2026-07-27 · MEDIUM

Exploit for CVE-2026-65008

CVE-2026-65008
2026-07-27 · MEDIUM

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

2026-07-27 · MEDIUM

PTC Windchill Vulnerability Exploited in Ransomware Campaign

2026-07-27 · HIGH

CVE-64600-Refluxfs-POC exploit

2026-07-27 · HIGH

Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Wavlink Wl-Nu516U1_Firmware exploit

2026-07-27 · HIGH

Exploit for CVE-2026-58138 exploit

CVE-2026-58138
2026-07-27 · HIGH

mod-poc-msf-p3 exploit

2026-07-27 · HIGH

relay-secreport-bench exploit

2026-07-27 · HIGH

Web-Payloads-Arsenal exploit

2026-07-27 · HIGH

CSFR-XSS-IDOR exploit

2026-07-27 · MEDIUM

Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits

2026-07-27 · HIGH

CVE Exploitation Campaign — Unattributed Threat Actor

2026-07-27 · HIGH

High-Severity: Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise (CVE-2026-54121)

CVE-2026-54121
2026-07-26 · MEDIUM

Penetration Tester Path

2026-07-26 · HIGH

Weekly Cyber Security Newsletter Bulletin Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories

2026-07-26 · HIGH

cis-hardening-metasploitable2 exploit

2026-07-26 · HIGH

vulnerability-exploitation-initial-access exploit

2026-07-26 · HIGH

ethical-hacking-elewayte-projects exploit

2026-07-26 · HIGH

Exploit for CVE-2026-66012 exploit

CVE-2026-66012
2026-07-26 · HIGH

Exploit for CVE-2026-15981 exploit

CVE-2026-15981
2026-07-26 · HIGH

Exploit for CVE-2026-58480 exploit

CVE-2026-58480
2026-07-26 · HIGH

Exploit for CVE-2026-10818 exploit

CVE-2026-10818
2026-07-26 · CRITICAL

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

2026-07-26 · MEDIUM

Update: Thank you guys so much for all the help!

2026-07-26 · HIGH

vibe-playground exploit

2026-07-26 · HIGH

tri-services-exploitation-report exploit

2026-07-26 · HIGH

Exploit for Deserialization of Untrusted Data in Dataease exploit

2026-07-26 · HIGH

HTB-Writeups exploit

2026-07-26 · HIGH

Older call of duty titles on steam have remote code execution exploits yet are still sold on the store. How is this acceptable?

CVE-2018-20817
2026-07-25 · HIGH

Exploit for SQL Injection in Trispark Novusedu exploit

2026-07-25 · HIGH

Exploit for SQL Injection in Fortra Delivernow exploit

2026-07-25 · HIGH

Exploit for Improper Authentication in Sonicwall Directory_Services_Connector exploit

2026-07-25 · MEDIUM

Someone build a Serverless Hermes Agent specialized in PenTest/SecAudit

2026-07-25 · MEDIUM

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

2026-07-25 · MEDIUM

Rockwell Patches Code Execution Flaws in Arena Simulation Software

2026-07-24 · HIGH

CVE-2026-16723: A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable

CVE-2026-16723
2026-07-24 · HIGH

Class06-Security-Vulnerability-Demo exploit

2026-07-24 · HIGH

Exploit for Relative Path Traversal in Microsoft exploit

2026-07-24 · HIGH

Exploit for Incorrect Authorization in Adobe Coldfusion exploit

2026-07-24 · HIGH

Exploit for Missing Authentication for Critical Function in Erlang Erlang\/Otp exploit

2026-07-24 · HIGH

Exploit for Out-of-bounds Read in Microsoft exploit

2026-07-24 · HIGH

Exploit for Command Injection in Paloaltonetworks Pan-Os exploit

2026-07-24 · MEDIUM

Hermes AI agent used to automate attack on Thai Finance Ministry

2026-07-24 · MEDIUM

Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

2026-07-24 · MEDIUM

OpenAI's cyber eval models escaped their sandbox and hacked Hugging Face to cheat on a test

2026-07-24 · MEDIUM

Looking for SOC analysts to roast/test my MVP

2026-07-24 · HIGH

2026-07-tare-nightbox33-cloud exploit

2026-07-24 · HIGH

Vulhub-vulnerability-reproduction-reports exploit

2026-07-24 · HIGH

exploitarium exploit

2026-07-24 · HIGH

Exploit for CVE-2026-63766 exploit

CVE-2026-63766
2026-07-24 · HIGH

Russian Hackers Exploiting Zimbra Zero-Day to Steal 90 Days of Emails

2026-07-24 · CRITICAL

Critical: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud C (CVE-2026-41940)

CVE-2026-41940
2026-07-24 · CRITICAL

Critical: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (CVE-2024-24919)

CVE-2024-24919
2026-07-23 · MEDIUM

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

2026-07-23 · CRITICAL

Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

2026-07-23 · MEDIUM

Russian hackers exploit Zimbra zero-click flaw for email theft

2026-07-23 · HIGH

CVE-2026-16445: A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia

CVE-2026-16445
2026-07-23 · HIGH

Exploit for SQL Injection in Ivanti Endpoint_Manager exploit

2026-07-23 · HIGH

Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy exploit

2026-07-23 · HIGH

Fastjson1.2.83_EXP exploit

2026-07-23 · HIGH

fastjson-jsontype-rce-hzhsec exploit

2026-07-23 · HIGH

open-redirect-poc exploit

2026-07-23 · HIGH

Exploit for OS Command Injection in Php exploit

2026-07-23 · CRITICAL

Exploit for CVE-2025-2783 exploit

CVE-2025-2783
2026-07-23 · CRITICAL

New Check Point Zero-Day Vulnerability Exploited in the Wild

2026-07-23 · LOW

Exploit for CVE-2026-64600

CVE-2026-64600
2026-07-23 · LOW

CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure

2026-07-23 · MEDIUM

Exploit for CVE-2026-56121

CVE-2026-56121
2026-07-23 · CRITICAL

July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws

2026-07-23 · CRITICAL

Check Point patches actively exploited SmartConsole authentication bypass flaw

2026-07-23 · MEDIUM

Check Point warns of SmartConsole zero-day exploited in attacks

2026-07-23 · MEDIUM

A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits

2026-07-22 · MEDIUM

Cybersecurity statistics of the week (July 13th - July 19th)

2026-07-22 · HIGH

I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

CVE-2026-4986
2026-07-22 · CRITICAL

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

2026-07-22 · CRITICAL

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog

2026-07-22 · MEDIUM

CISA orders urgent action on actively exploited Langflow RCE flaw

2026-07-22 · HIGH

Exploit for Injection in Glpi-Project Glpi exploit

2026-07-22 · HIGH

cloud-misconfig-lab exploit

2026-07-22 · HIGH

Exploit for SQL Injection in Tenable Nessus exploit

2026-07-22 · HIGH

stealth-privesc exploit

2026-07-22 · HIGH

Exploit for CVE-2026-53595 exploit

CVE-2026-53595
2026-07-22 · HIGH

fastjson-1.2.83-rce-jdk8-jdk25 exploit

2026-07-22 · LOW

Exploit for CVE-2026-50055

CVE-2026-50055
2026-07-22 · HIGH

n8n-nodes-metasploit exploit

2026-07-22 · HIGH

AutoBugBounty exploit

2026-07-22 · HIGH

BlackOpz-Toolkit exploit

2026-07-22 · HIGH

-vsftpd-exploit-lab exploit

2026-07-22 · HIGH

FastjsonSecurity exploit

2026-07-22 · HIGH

Exploit for Origin Validation Error in Ultraviolet Cocos_Ai exploit

2026-07-22 · CRITICAL

Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild

2026-07-22 · HIGH

OpenAIs GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers

2026-07-22 · HIGH

phpmailer_5.2.16_exploit- exploit

2026-07-22 · HIGH

xssscannerpro exploit

2026-07-22 · HIGH

Metasploitable2-Exploit exploit

2026-07-22 · HIGH

Exploit for CVE-2026-52813 exploit

CVE-2026-52813
2026-07-22 · HIGH

Epoch-BreachScope exploit

2026-07-22 · HIGH

Minima-private exploit

2026-07-22 · HIGH

Exploit for Heap-based Buffer Overflow in F5 Nginx_Plus exploit

2026-07-22 · HIGH

Exploit for Improper Authentication in Apache Camel exploit

2026-07-22 · CRITICAL

Critical SharePoint RCE flaw exploited to steal machine keys

2026-07-21 · MEDIUM

OpenAI Models Escaped Containment and Hacked HuggingFace

2026-07-21 · HIGH

CVE-2026-14448: An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi

CVE-2026-14448
2026-07-21 · CRITICAL

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

CVE-2026-50522
2026-07-21 · CRITICAL

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

2026-07-21 · HIGH

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

2026-07-21 · HIGH

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

2026-07-21 · HIGH

wp-ssrf-cloud-metadata exploit

2026-07-21 · HIGH

Exploit for CVE-2018-3214 exploit

CVE-2018-3214
2026-07-21 · HIGH

fastjson-1.2.83-rce exploit

2026-07-21 · HIGH

Exploit for Improper Privilege Management in Stylemixthemes Masterstudy_Lms exploit

2026-07-21 · HIGH

KubernetesExploitationGuide exploit

2026-07-21 · HIGH

fastjson-json-type-rce exploit

2026-07-21 · HIGH

Exploitation-Basics exploit

2026-07-21 · CRITICAL

Exploit for CVE-2022-30190 exploit

CVE-2022-30190
2026-07-21 · CRITICAL

SonicWall SMA zero-days were exploited weeks before disclosure

2026-07-21 · CRITICAL

SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

2026-07-21 · MEDIUM

Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack

2026-07-21 · HIGH

wp2shell_sqli_min_poc exploit

2026-07-21 · HIGH

fastjson-1.2.83-poc exploit

2026-07-21 · HIGH

llm-redteam-helixpay exploit

2026-07-21 · MEDIUM

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

2026-07-21 · MEDIUM

Windows LegacyHive zero-day flaw gets free, unofficial patches

2026-07-21 · MEDIUM

XSSer v.1.9 - "Bl4ck Swarm!" released

2026-07-21 · MEDIUM

New Release: UFONet v2.0 - "R3DST4R!"...

2026-07-21 · HIGH

Exploit for CVE-2026-23550 exploit

CVE-2026-23550
2026-07-21 · HIGH

fastjson-jsontype-rce-lab exploit

2026-07-21 · HIGH

Exploit for Out-of-bounds Write in Watchguard Fireware exploit

2026-07-21 · HIGH

wp2shell-Wordpress-TOWN exploit

2026-07-21 · HIGH

Exploit for CVE-2026-12191 exploit

CVE-2026-12191
2026-07-21 · HIGH

Exploit for CVE-2026-44680 exploit

CVE-2026-44680
2026-07-21 · HIGH

Exploit for CVE-2026-11374 exploit

CVE-2026-11374
2026-07-20 · MEDIUM

Estée Lauder discloses data breach via Oracle E-Business flaw

2026-07-20 · MEDIUM

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

2026-07-20 · MEDIUM

Is web penetration testing still a good career to invest in, or should I pivot while I'm still a junior?

2026-07-20 · MEDIUM

Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries

2026-07-20 · CRITICAL

Critical wp2shell RCE Vulnerability Complete Coverage Including PoC and Active Exploitation Details

2026-07-20 · HIGH

Critical ServiceNow code execution flaw now exploited in attacks

2026-07-20 · HIGH

zero-copy-web-application-firewall exploit

2026-07-20 · HIGH

Exploit for Path Traversal in Jenkins exploit

2026-07-20 · HIGH

everything-claude-code exploit

2026-07-20 · HIGH

appsec-audit exploit

2026-07-20 · HIGH

Exploit for CVE-2026-61498 exploit

CVE-2026-61498
2026-07-20 · HIGH

vibesec-static exploit

2026-07-20 · CRITICAL

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

2026-07-20 · MEDIUM

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

2026-07-20 · HIGH

Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?

CVE-2026-14440
2026-07-20 · HIGH

TP-Link-TL-WR841ND-Security-Audit exploit

2026-07-20 · HIGH

Exploit for CVE-2025-9951 exploit

CVE-2025-9951
2026-07-20 · HIGH

PLUGINS-DETECTOR exploit

2026-07-20 · HIGH

fz-b2-rootshell exploit

2026-07-20 · CRITICAL

WP2Shell WordPress Vulnerabilities Exploited in the Wild

2026-07-20 · MEDIUM

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

2026-07-20 · MEDIUM

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

2026-07-20 · HIGH

Critical ServiceNow code execution flaw now exploited in attacks

CVE-2026-6875
2026-07-19 · HIGH

CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an

CVE-2026-13445
2026-07-19 · MEDIUM

Recovering from a malicious APK installation on CMF Phone. HELP!

2026-07-19 · MEDIUM

What AI cyber security platforms are spearheading the field.

2026-07-19 · HIGH

BythosEngine exploit

2026-07-19 · HIGH

DarkSword-PROV2 exploit

2026-07-19 · HIGH

react2shell-poc exploit

2026-07-19 · HIGH

Exploit for CVE-2026-46420 exploit

CVE-2026-46420
2026-07-19 · MEDIUM

I resurrected a classic 2013 Active Defense tool (Honeyports), Rewritten in Python 3 with a Web UI and Threading 👍

2026-07-19 · MEDIUM

Breaking into the industry

2026-07-19 · HIGH

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

2026-07-19 · HIGH

APEX_FRAMEWORK exploit

2026-07-19 · HIGH

wp2shell_stock_chain exploit

2026-07-19 · HIGH

Exploit for CVE-2026-60137 exploit

CVE-2026-60137
2026-07-19 · HIGH

Exploit for Unrestricted Upload of File with Dangerous Type in Templaza Astroid_Framework exploit

2026-07-19 · MEDIUM

From 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign

2026-07-18 · MEDIUM

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

2026-07-18 · MEDIUM

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

2026-07-18 · MEDIUM

White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination

2026-07-17 · MEDIUM

ClickLock macOS stealer relies on a pasted Terminal command, not an exploit

2026-07-17 · MEDIUM

Openwrt pre-auth remote root exploit

2026-07-17 · HIGH

CVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out

CVE-2021-44228
2026-07-17 · MEDIUM

can anyone help me solve exploit development challenge.

2026-07-17 · MEDIUM

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

2026-07-17 · MEDIUM

New Windows LegacyHive zero-day gives hackers admin privileges

2026-07-17 · MEDIUM

Is MITRE is biased towards the historically what techniques are used rather then what's being used actively?

2026-07-17 · MEDIUM

Windows Server 2022 reach end of mainstream support in 90 days

2026-07-17 · MEDIUM

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

2026-07-17 · MEDIUM

CISA urges immediate action on actively exploited Fortinet flaws

2026-07-16 · MEDIUM

New Exploitable BOLA Found in Immich (self-hosted media platform)

2026-07-16 · MEDIUM

CISA orders feds to patch actively exploited Oracle flaw by Saturday

2026-07-16 · MEDIUM

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

2026-07-16 · MEDIUM

AI Agent for reconaissasion

2026-07-16 · MEDIUM

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

2026-07-16 · HIGH

ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL

CVE-2026-13585
2026-07-16 · MEDIUM

i get stuck

2026-07-16 · MEDIUM

Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)

2026-07-15 · MEDIUM

Zoom warns of critical account takeover vulnerability

2026-07-15 · MEDIUM

File-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion

2026-07-15 · MEDIUM

Coverage-First SOC: why domains and telemetry matter as much as threat intel

2026-07-15 · MEDIUM

Runtime detection for ECS/EC2, what are people actually using?

2026-07-15 · MEDIUM

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

2026-07-15 · MEDIUM

KQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'

2026-07-15 · MEDIUM

2-Click Cursor Exploit Enables Dev Environment Takeover

2026-07-15 · MEDIUM

CISA warns admins to patch actively exploited SharePoint flaws

2026-07-15 · MEDIUM

Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption

2026-07-15 · MEDIUM

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates

2026-07-14 · HIGH

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

CVE-2026-15409CVE-2026-15410
2026-07-14 · MEDIUM

Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)

2026-07-14 · MEDIUM

🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries

2026-07-14 · MEDIUM

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

2026-07-14 · MEDIUM

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

2026-07-14 · MEDIUM

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

2026-07-14 · MEDIUM

LastPass, Bitwarden users targeted with fake security alerts

2026-07-14 · MEDIUM

ESET discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass Secure Boot by exploiting decade-old vulnerabilities

2026-07-14 · MEDIUM

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

2026-07-14 · MEDIUM

You Don't Have to Run an Exploit to Know If You're Vulnerable

2026-07-14 · MEDIUM

Cybersecurity projects

2026-07-14 · MEDIUM

Cursor IDE Auto-Executes Malicious Code in Poisoned Repos

2026-07-14 · MEDIUM

Nightmare Eclipse could be dropping his big promised exploit today

2026-07-14 · MEDIUM

Zimbra Classic Web Client has a critical stored XSS, patched in ZCS 10.1.19 (reported by Google TAG, no CVE yet, not flagged as exploited in the wild)

2026-07-13 · MEDIUM

I vibed an Application Inventory Service

2026-07-13 · MEDIUM

CISA warns of actively exploited RCE flaws in Joomla extensions

2026-07-13 · MEDIUM

Organizations Warned of Exploited Joomla Extension Vulnerabilities

2026-07-13 · MEDIUM

Passed OSCP from Rajasthan things nobody told me about preparation

2026-07-13 · MEDIUM

Large-scale exploitation campaign targeting website content management systems (CMS)

2026-07-13 · MEDIUM

Participants Needed: Master's Research on AI Governance & the EU AI Act

2026-07-12 · MEDIUM

Passive security measurement of 10,020 .it domains: CSP, cookies, TLS and email authentication

2026-07-11 · MEDIUM

BloodBash Feedback Needed Before DEF CON 34 Red Team Village Talk - AD/hybrid Recon Tool

2026-07-11 · MEDIUM

Australia warns of global campaign targeting vulnerable CMS platforms

2026-07-10 · MEDIUM

How do you keep archived firewall logs usable during a threat hunt?

2026-07-10 · MEDIUM

Closing the Timing Gap: Defensive Temporal Observability

2026-07-10 · MEDIUM

Hackers exploit critical auth bypass in Gitea Docker image

2026-07-10 · MEDIUM

CISA KEV Threat Intel Orchestrator

2026-07-09 · MEDIUM

MOD REQUEST: Can you ban the excessive AI posters please?

2026-07-09 · MEDIUM

12 Million Impacted by Data Breach at Japanese Telco KDDI

2026-07-09 · MEDIUM

Microsoft patches RoguePlanet Defender zero-day vulnerability

2026-07-08 · MEDIUM

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

2026-07-08 · MEDIUM

AI agents went from "cool demo" to "exploiting CVEs in 10 hours"

2026-07-08 · MEDIUM

Hackers exploit Roundcube flaw to spy on academic researchers

2026-07-08 · MEDIUM

Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches

2026-07-08 · MEDIUM

CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

2026-07-08 · MEDIUM

CISA orders feds to prioritize patching Langflow auth bypass flaw

2026-07-08 · MEDIUM

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

2026-07-08 · MEDIUM

Ubiquiti warns of new max severity UniFi OS vulnerability

2026-07-08 · MEDIUM

CISA orders feds to patch max severity ColdFusion flaw by Friday

2026-07-07 · MEDIUM

Safer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...

2026-07-07 · MEDIUM

Chinese hackers develop LONGLEASH malware to expand ORB network

2026-07-07 · MEDIUM

Cybersecurity statistics of the week (June 29th - July 5th)

2026-07-07 · MEDIUM

Spain arrests suspected member of pro-Russian hacktivist groups

2026-07-07 · MEDIUM

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

2026-07-06 · HIGH

Januscape (CVE-2026-53359): 16 year old Critical Linux KVM Guest-to-Host Escape, PoC Public

CVE-2026-53359
2026-07-06 · MEDIUM

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

2026-07-06 · MEDIUM

Anyone know these listening ports/vendors used?

2026-07-06 · HIGH

Exploitarium coverage update: CVE-2026-20896 Gitea probing confirmed + 10 new rules added

CVE-2026-20896
2026-07-06 · MEDIUM

I feel like a fraud and I don't know what to do

2026-07-06 · HIGH

Max severity Adobe ColdFusion flaw now exploited in attacks

CVE-2026-48282
2026-07-06 · MEDIUM

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

2026-07-06 · MEDIUM

Vale a pena estudar cibersegurança para quem trabalha com manutenção de notebooks?

2026-07-06 · MEDIUM

Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments

2026-07-06 · MEDIUM

Cyber Security Analyst vs. Insider Threat / DLP Analyst?

2026-07-05 · MEDIUM

Building an interactive career simulator for network engineers: From CCNA basics to SOC and Pentest operations.

2026-07-05 · MEDIUM

Did global cybersecurity tightening make my university VPN stop working?

2026-07-05 · MEDIUM

Ssl cert renewal every 200days

2026-07-05 · HIGH

Patch now: CISA warns of actively exploited Linux kernel zero-day (CVE-2026-43456)

CVE-2026-43456