CISA KEV — Actively Exploited Collection
Vulnerabilities confirmed to be under active exploitation in the wild.
2026-07-30 · MEDIUMRussian hackers exploit Exchange OWA zero-day for long-term mailbox access
2026-07-29 · HIGHCisco warns of FMC static credential flaw exploited in zero-day attacks
CVE-2026-20316
2026-07-29 · MEDIUM
Hugging Face built an interactive replay of the OAl agent that breached them
2026-07-29 · HIGHCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
CVE-2026-66066
2026-07-29 · CRITICAL
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
2026-07-29 · MEDIUMOnly 1% of AI-discovered vulnerabilities have actually been exploited in the wild - a rate that matches standard, human-found bugs.
2026-07-29 · HIGHCodeAlpha_SecureCodingReview exploit
2026-07-29 · HIGHBinary-Exploitation exploit
2026-07-29 · HIGHStored-XSS-via-Content-Tag-Names-Microweber- exploit
2026-07-29 · HIGHExploit for Improper Authentication in Redhat Keycloak exploit
2026-07-29 · HIGHExploit for CVE-2026-53921 exploit
CVE-2026-53921
2026-07-29 · HIGH
Exploit for Improper Authentication in Checkpoint Multi-Domain_Security_Management exploit
2026-07-29 · HIGHExploit for CVE-2026-65761 exploit
CVE-2026-65761
2026-07-29 · HIGH
exploit-counter exploit
2026-07-29 · MEDIUMJFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
2026-07-29 · LOWFirst-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face
2026-07-29 · MEDIUMOur biggest AI security issue wasn't prompt leakage. It was what people built afterward.
2026-07-29 · HIGHhandlebars-ssti-ast-rce exploit
2026-07-29 · HIGHExploit for CVE-2026-64725 exploit
CVE-2026-64725
2026-07-29 · HIGH
CVE-Vulnerability-Reproduction exploit
2026-07-29 · HIGHExploit for Use of Hard-coded Credentials in Solarwinds Web_Help_Desk exploit
2026-07-28 · MEDIUMOpenAI models used Artifactory zero-days to escape to the internet
2026-07-28 · MEDIUMWhat do you do with CVEs you can't fix? Auditor wants proof they're 'not exploitable'
2026-07-28 · MEDIUMClaude Mythos degrades HAWK and developed new exploit for round-reduced AES
2026-07-28 · MEDIUMvBulletin fixes critical pre-auth RCE flaw with public exploit
2026-07-28 · MEDIUMFlying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs
2026-07-28 · HIGHBugcrowd introduces Savant Pathseeker for agentic penetration testing with exploit validation
2026-07-28 · HIGHRoot-My-Device-Payloads exploit
2026-07-28 · HIGHExploit for Classic Buffer Overflow in Tp-Link Tl-Wr841_Firmware exploit
2026-07-28 · HIGHExploit for Insertion of Sensitive Information into Log File in Ayesa Ibermatica_Rps exploit
2026-07-28 · HIGHvulnerable-forum exploit
2026-07-28 · HIGHExploit for Incorrect Authorization in F5 Nginx_Plus exploit
2026-07-28 · HIGHHackers Exploiting FastJson RCE 0-Day in the Wild to Attack US-based Organizations
2026-07-28 · MEDIUMJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
2026-07-28 · LOWExploit for CVE-2026-59891
CVE-2026-59891
2026-07-28 · HIGH
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
CVE-2013-4786
2026-07-28 · HIGH
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
2026-07-28 · HIGHExploit for CVE-2026-8206 exploit
CVE-2026-8206
2026-07-28 · HIGH
Web-Server-Log-Parser-Threat-Detector exploit
2026-07-28 · HIGHstudy_embedded_security exploit
2026-07-28 · HIGHExploit for Cross-site Scripting in Spip exploit
2026-07-28 · HIGHkernel-exploit-dirty-cow-project exploit
2026-07-28 · LOWLegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed
2026-07-28 · MEDIUMHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
2026-07-28 · CRITICALU.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
2026-07-28 · MEDIUMHas the Hugging Face incident changed anyone else’s view on open vs closed AI models for cybersecurity?
2026-07-28 · MEDIUMAutomated AI penetration testing with Claude Code or Codex: what setup actually works best?
2026-07-28 · HIGHmt6897-unlock-attempt exploit
2026-07-28 · HIGHExploit for CVE-2026-40000 exploit
CVE-2026-40000
2026-07-28 · HIGH
Exploit for CVE-2026-39875 exploit
CVE-2026-39875
2026-07-28 · CRITICAL
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
2026-07-28 · CRITICALCISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks
2026-07-28 · CRITICALHackers Exploiting Arista VeloCloud Orchestrator 0-Day Vulnerability in the Wild
2026-07-28 · MEDIUMUnpatched Fastjson Vulnerability Exploited in Attacks
2026-07-28 · HIGHExploit for CVE-2026-9830 exploit
CVE-2026-9830
2026-07-28 · HIGH
flask-kvsession-pickle-rce exploit
2026-07-28 · MEDIUMCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
2026-07-28 · MEDIUMHackers target US firms in FastJson RCE zero-day attacks
2026-07-27 · MEDIUMArista patches VeloCloud Orchestrator zero-day exploited in attacks
2026-07-27 · HIGHExploit for CVE-2026-42533 exploit
CVE-2026-42533
2026-07-27 · HIGH
pentest-confirm-mcp exploit
2026-07-27 · HIGHExploit for Path Traversal in Mate-Desktop Atril exploit
2026-07-27 · MEDIUMNew Certighost PoC exploit lets attackers hijack Windows domains
2026-07-27 · MEDIUMAdversaries Don't Need a Zero-Day — They Read Your Rulebook
2026-07-27 · LOWSextortion scammers are exploiting ShinyHunters data leaks
2026-07-27 · MEDIUMExploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
2026-07-27 · MEDIUMExploit for CVE-2026-65008
CVE-2026-65008
2026-07-27 · MEDIUM
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
2026-07-27 · MEDIUMPTC Windchill Vulnerability Exploited in Ransomware Campaign
2026-07-27 · HIGHCVE-64600-Refluxfs-POC exploit
2026-07-27 · HIGHExploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Wavlink Wl-Nu516U1_Firmware exploit
2026-07-27 · HIGHExploit for CVE-2026-58138 exploit
CVE-2026-58138
2026-07-27 · HIGH
mod-poc-msf-p3 exploit
2026-07-27 · HIGHrelay-secreport-bench exploit
2026-07-27 · HIGHWeb-Payloads-Arsenal exploit
2026-07-27 · HIGHCSFR-XSS-IDOR exploit
2026-07-27 · MEDIUMAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
2026-07-27 · HIGHCVE Exploitation Campaign — Unattributed Threat Actor
2026-07-27 · HIGHHigh-Severity: Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise (CVE-2026-54121)
CVE-2026-54121
2026-07-26 · MEDIUM
Penetration Tester Path
2026-07-26 · HIGHWeekly Cyber Security Newsletter Bulletin Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories
2026-07-26 · HIGHcis-hardening-metasploitable2 exploit
2026-07-26 · HIGHvulnerability-exploitation-initial-access exploit
2026-07-26 · HIGHethical-hacking-elewayte-projects exploit
2026-07-26 · HIGHExploit for CVE-2026-66012 exploit
CVE-2026-66012
2026-07-26 · HIGH
Exploit for CVE-2026-15981 exploit
CVE-2026-15981
2026-07-26 · HIGH
Exploit for CVE-2026-58480 exploit
CVE-2026-58480
2026-07-26 · HIGH
Exploit for CVE-2026-10818 exploit
CVE-2026-10818
2026-07-26 · CRITICAL
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
2026-07-26 · MEDIUMUpdate: Thank you guys so much for all the help!
2026-07-26 · HIGHvibe-playground exploit
2026-07-26 · HIGHtri-services-exploitation-report exploit
2026-07-26 · HIGHExploit for Deserialization of Untrusted Data in Dataease exploit
2026-07-26 · HIGHHTB-Writeups exploit
2026-07-26 · HIGHOlder call of duty titles on steam have remote code execution exploits yet are still sold on the store. How is this acceptable?
CVE-2018-20817
2026-07-25 · HIGH
Exploit for SQL Injection in Trispark Novusedu exploit
2026-07-25 · HIGHExploit for SQL Injection in Fortra Delivernow exploit
2026-07-25 · HIGHExploit for Improper Authentication in Sonicwall Directory_Services_Connector exploit
2026-07-25 · MEDIUMSomeone build a Serverless Hermes Agent specialized in PenTest/SecAudit
2026-07-25 · MEDIUMResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
2026-07-25 · MEDIUMRockwell Patches Code Execution Flaws in Arena Simulation Software
2026-07-24 · HIGHCVE-2026-16723: A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable
CVE-2026-16723
2026-07-24 · HIGH
Class06-Security-Vulnerability-Demo exploit
2026-07-24 · HIGHExploit for Relative Path Traversal in Microsoft exploit
2026-07-24 · HIGHExploit for Incorrect Authorization in Adobe Coldfusion exploit
2026-07-24 · HIGHExploit for Missing Authentication for Critical Function in Erlang Erlang\/Otp exploit
2026-07-24 · HIGHExploit for Out-of-bounds Read in Microsoft exploit
2026-07-24 · HIGHExploit for Command Injection in Paloaltonetworks Pan-Os exploit
2026-07-24 · MEDIUMHermes AI agent used to automate attack on Thai Finance Ministry
2026-07-24 · MEDIUMCertighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
2026-07-24 · MEDIUMOpenAI's cyber eval models escaped their sandbox and hacked Hugging Face to cheat on a test
2026-07-24 · MEDIUMLooking for SOC analysts to roast/test my MVP
2026-07-24 · HIGH2026-07-tare-nightbox33-cloud exploit
2026-07-24 · HIGHVulhub-vulnerability-reproduction-reports exploit
2026-07-24 · HIGHexploitarium exploit
2026-07-24 · HIGHExploit for CVE-2026-63766 exploit
CVE-2026-63766
2026-07-24 · HIGH
Russian Hackers Exploiting Zimbra Zero-Day to Steal 90 Days of Emails
2026-07-24 · CRITICALCritical: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud C (CVE-2026-41940)
CVE-2026-41940
2026-07-24 · CRITICAL
Critical: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (CVE-2024-24919)
CVE-2024-24919
2026-07-23 · MEDIUM
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
2026-07-23 · CRITICALHackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials
2026-07-23 · MEDIUMRussian hackers exploit Zimbra zero-click flaw for email theft
2026-07-23 · HIGHCVE-2026-16445: A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia
CVE-2026-16445
2026-07-23 · HIGH
Exploit for SQL Injection in Ivanti Endpoint_Manager exploit
2026-07-23 · HIGHExploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy exploit
2026-07-23 · HIGHFastjson1.2.83_EXP exploit
2026-07-23 · HIGHfastjson-jsontype-rce-hzhsec exploit
2026-07-23 · HIGHopen-redirect-poc exploit
2026-07-23 · HIGHExploit for OS Command Injection in Php exploit
2026-07-23 · CRITICALExploit for CVE-2025-2783 exploit
CVE-2025-2783
2026-07-23 · CRITICAL
New Check Point Zero-Day Vulnerability Exploited in the Wild
2026-07-23 · LOWExploit for CVE-2026-64600
CVE-2026-64600
2026-07-23 · LOW
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
2026-07-23 · MEDIUMExploit for CVE-2026-56121
CVE-2026-56121
2026-07-23 · CRITICAL
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
2026-07-23 · CRITICALCheck Point patches actively exploited SmartConsole authentication bypass flaw
2026-07-23 · MEDIUMCheck Point warns of SmartConsole zero-day exploited in attacks
2026-07-23 · MEDIUMA project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
2026-07-22 · MEDIUMCybersecurity statistics of the week (July 13th - July 19th)
2026-07-22 · HIGHI was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
CVE-2026-4986
2026-07-22 · CRITICAL
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
2026-07-22 · CRITICALU.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
2026-07-22 · MEDIUMCISA orders urgent action on actively exploited Langflow RCE flaw
2026-07-22 · HIGHExploit for Injection in Glpi-Project Glpi exploit
2026-07-22 · HIGHcloud-misconfig-lab exploit
2026-07-22 · HIGHExploit for SQL Injection in Tenable Nessus exploit
2026-07-22 · HIGHstealth-privesc exploit
2026-07-22 · HIGHExploit for CVE-2026-53595 exploit
CVE-2026-53595
2026-07-22 · HIGH
fastjson-1.2.83-rce-jdk8-jdk25 exploit
2026-07-22 · LOWExploit for CVE-2026-50055
CVE-2026-50055
2026-07-22 · HIGH
n8n-nodes-metasploit exploit
2026-07-22 · HIGHAutoBugBounty exploit
2026-07-22 · HIGHBlackOpz-Toolkit exploit
2026-07-22 · HIGH-vsftpd-exploit-lab exploit
2026-07-22 · HIGHFastjsonSecurity exploit
2026-07-22 · HIGHExploit for Origin Validation Error in Ultraviolet Cocos_Ai exploit
2026-07-22 · CRITICALHackers are Actively Exploiting ServiceNow Vulnerability in the Wild
2026-07-22 · HIGHOpenAIs GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers
2026-07-22 · HIGHphpmailer_5.2.16_exploit- exploit
2026-07-22 · HIGHxssscannerpro exploit
2026-07-22 · HIGHMetasploitable2-Exploit exploit
2026-07-22 · HIGHExploit for CVE-2026-52813 exploit
CVE-2026-52813
2026-07-22 · HIGH
Epoch-BreachScope exploit
2026-07-22 · HIGHMinima-private exploit
2026-07-22 · HIGHExploit for Heap-based Buffer Overflow in F5 Nginx_Plus exploit
2026-07-22 · HIGHExploit for Improper Authentication in Apache Camel exploit
2026-07-22 · CRITICALCritical SharePoint RCE flaw exploited to steal machine keys
2026-07-21 · MEDIUMOpenAI Models Escaped Containment and Hacked HuggingFace
2026-07-21 · HIGHCVE-2026-14448: An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi
CVE-2026-14448
2026-07-21 · CRITICAL
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
CVE-2026-50522
2026-07-21 · CRITICAL
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
2026-07-21 · HIGHWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
2026-07-21 · HIGHExploitation of ServiceNow Vulnerability Seen Days After Disclosure
2026-07-21 · HIGHwp-ssrf-cloud-metadata exploit
2026-07-21 · HIGHExploit for CVE-2018-3214 exploit
CVE-2018-3214
2026-07-21 · HIGH
fastjson-1.2.83-rce exploit
2026-07-21 · HIGHExploit for Improper Privilege Management in Stylemixthemes Masterstudy_Lms exploit
2026-07-21 · HIGHKubernetesExploitationGuide exploit
2026-07-21 · HIGHfastjson-json-type-rce exploit
2026-07-21 · HIGHExploitation-Basics exploit
2026-07-21 · CRITICALExploit for CVE-2022-30190 exploit
CVE-2022-30190
2026-07-21 · CRITICAL
SonicWall SMA zero-days were exploited weeks before disclosure
2026-07-21 · CRITICALSonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
2026-07-21 · MEDIUMEstée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
2026-07-21 · HIGHwp2shell_sqli_min_poc exploit
2026-07-21 · HIGHfastjson-1.2.83-poc exploit
2026-07-21 · HIGHllm-redteam-helixpay exploit
2026-07-21 · MEDIUMCritical Palo Alto VPN bug now exploited by Qilin ransomware gang
2026-07-21 · MEDIUMWindows LegacyHive zero-day flaw gets free, unofficial patches
2026-07-21 · MEDIUMXSSer v.1.9 - "Bl4ck Swarm!" released
2026-07-21 · MEDIUMNew Release: UFONet v2.0 - "R3DST4R!"...
2026-07-21 · HIGHExploit for CVE-2026-23550 exploit
CVE-2026-23550
2026-07-21 · HIGH
fastjson-jsontype-rce-lab exploit
2026-07-21 · HIGHExploit for Out-of-bounds Write in Watchguard Fireware exploit
2026-07-21 · HIGHwp2shell-Wordpress-TOWN exploit
2026-07-21 · HIGHExploit for CVE-2026-12191 exploit
CVE-2026-12191
2026-07-21 · HIGH
Exploit for CVE-2026-44680 exploit
CVE-2026-44680
2026-07-21 · HIGH
Exploit for CVE-2026-11374 exploit
CVE-2026-11374
2026-07-20 · MEDIUM
Estée Lauder discloses data breach via Oracle E-Business flaw
2026-07-20 · MEDIUMSonicWall SMA1000 flaws exploited as zero-days to push custom malware
2026-07-20 · MEDIUMIs web penetration testing still a good career to invest in, or should I pivot while I'm still a junior?
2026-07-20 · MEDIUMOpen Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries
2026-07-20 · CRITICALCritical wp2shell RCE Vulnerability Complete Coverage Including PoC and Active Exploitation Details
2026-07-20 · HIGHCritical ServiceNow code execution flaw now exploited in attacks
2026-07-20 · HIGHzero-copy-web-application-firewall exploit
2026-07-20 · HIGHExploit for Path Traversal in Jenkins exploit
2026-07-20 · HIGHeverything-claude-code exploit
2026-07-20 · HIGHappsec-audit exploit
2026-07-20 · HIGHExploit for CVE-2026-61498 exploit
CVE-2026-61498
2026-07-20 · HIGH
vibesec-static exploit
2026-07-20 · CRITICALMicrosoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
2026-07-20 · MEDIUM⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
2026-07-20 · HIGHCloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?
CVE-2026-14440
2026-07-20 · HIGH
TP-Link-TL-WR841ND-Security-Audit exploit
2026-07-20 · HIGHExploit for CVE-2025-9951 exploit
CVE-2025-9951
2026-07-20 · HIGH
PLUGINS-DETECTOR exploit
2026-07-20 · HIGHfz-b2-rootshell exploit
2026-07-20 · CRITICALWP2Shell WordPress Vulnerabilities Exploited in the Wild
2026-07-20 · MEDIUMExploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
2026-07-20 · MEDIUMCapital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
2026-07-20 · HIGHCritical ServiceNow code execution flaw now exploited in attacks
CVE-2026-6875
2026-07-19 · HIGH
CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an
CVE-2026-13445
2026-07-19 · MEDIUM
Recovering from a malicious APK installation on CMF Phone. HELP!
2026-07-19 · MEDIUMWhat AI cyber security platforms are spearheading the field.
2026-07-19 · HIGHBythosEngine exploit
2026-07-19 · HIGHDarkSword-PROV2 exploit
2026-07-19 · HIGHreact2shell-poc exploit
2026-07-19 · HIGHExploit for CVE-2026-46420 exploit
CVE-2026-46420
2026-07-19 · MEDIUM
I resurrected a classic 2013 Active Defense tool (Honeyports), Rewritten in Python 3 with a Web UI and Threading 👍
2026-07-19 · MEDIUMBreaking into the industry
2026-07-19 · HIGHAttackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
2026-07-19 · HIGHAPEX_FRAMEWORK exploit
2026-07-19 · HIGHwp2shell_stock_chain exploit
2026-07-19 · HIGHExploit for CVE-2026-60137 exploit
CVE-2026-60137
2026-07-19 · HIGH
Exploit for Unrestricted Upload of File with Dangerous Type in Templaza Astroid_Framework exploit
2026-07-19 · MEDIUMFrom 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign
2026-07-18 · MEDIUMUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives
2026-07-18 · MEDIUMWordPress Core "wp2shell" RCE flaws get public exploits, patch now
2026-07-18 · MEDIUMWhite House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
2026-07-17 · MEDIUMClickLock macOS stealer relies on a pasted Terminal command, not an exploit
2026-07-17 · MEDIUMOpenwrt pre-auth remote root exploit
2026-07-17 · HIGHCVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out
CVE-2021-44228
2026-07-17 · MEDIUM
can anyone help me solve exploit development challenge.
2026-07-17 · MEDIUMIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
2026-07-17 · MEDIUMNew Windows LegacyHive zero-day gives hackers admin privileges
2026-07-17 · MEDIUMIs MITRE is biased towards the historically what techniques are used rather then what's being used actively?
2026-07-17 · MEDIUMWindows Server 2022 reach end of mainstream support in 90 days
2026-07-17 · MEDIUMFresh SharePoint Vulnerability Exploited Soon After Disclosure
2026-07-17 · MEDIUMCISA urges immediate action on actively exploited Fortinet flaws
2026-07-16 · MEDIUMNew Exploitable BOLA Found in Immich (self-hosted media platform)
2026-07-16 · MEDIUMCISA orders feds to patch actively exploited Oracle flaw by Saturday
2026-07-16 · MEDIUMF5 Patches Multiple NGINX, BIG-IP Vulnerabilities
2026-07-16 · MEDIUMAI Agent for reconaissasion
2026-07-16 · MEDIUMNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
2026-07-16 · HIGHASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
CVE-2026-13585
2026-07-16 · MEDIUM
i get stuck
2026-07-16 · MEDIUMSubject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
2026-07-15 · MEDIUMZoom warns of critical account takeover vulnerability
2026-07-15 · MEDIUMFile-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion
2026-07-15 · MEDIUMCoverage-First SOC: why domains and telemetry matter as much as threat intel
2026-07-15 · MEDIUMRuntime detection for ECS/EC2, what are people actually using?
2026-07-15 · MEDIUMCISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
2026-07-15 · MEDIUMKQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'
2026-07-15 · MEDIUM2-Click Cursor Exploit Enables Dev Environment Takeover
2026-07-15 · MEDIUMCISA warns admins to patch actively exploited SharePoint flaws
2026-07-15 · MEDIUMProgress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
2026-07-15 · MEDIUMCritical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
2026-07-14 · HIGHSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
CVE-2026-15409CVE-2026-15410
2026-07-14 · MEDIUM
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
2026-07-14 · MEDIUM🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
2026-07-14 · MEDIUMMicrosoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
2026-07-14 · MEDIUMMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
2026-07-14 · MEDIUMProgress confirms ShareFile zero-day flaw behind Storage Zone shutdown
2026-07-14 · MEDIUMLastPass, Bitwarden users targeted with fake security alerts
2026-07-14 · MEDIUMESET discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass Secure Boot by exploiting decade-old vulnerabilities
2026-07-14 · MEDIUM7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
2026-07-14 · MEDIUMYou Don't Have to Run an Exploit to Know If You're Vulnerable
2026-07-14 · MEDIUMCybersecurity projects
2026-07-14 · MEDIUMCursor IDE Auto-Executes Malicious Code in Poisoned Repos
2026-07-14 · MEDIUMNightmare Eclipse could be dropping his big promised exploit today
2026-07-14 · MEDIUMZimbra Classic Web Client has a critical stored XSS, patched in ZCS 10.1.19 (reported by Google TAG, no CVE yet, not flagged as exploited in the wild)
2026-07-13 · MEDIUMI vibed an Application Inventory Service
2026-07-13 · MEDIUMCISA warns of actively exploited RCE flaws in Joomla extensions
2026-07-13 · MEDIUMOrganizations Warned of Exploited Joomla Extension Vulnerabilities
2026-07-13 · MEDIUMPassed OSCP from Rajasthan things nobody told me about preparation
2026-07-13 · MEDIUMLarge-scale exploitation campaign targeting website content management systems (CMS)
2026-07-13 · MEDIUMParticipants Needed: Master's Research on AI Governance & the EU AI Act
2026-07-12 · MEDIUMPassive security measurement of 10,020 .it domains: CSP, cookies, TLS and email authentication
2026-07-11 · MEDIUMBloodBash Feedback Needed Before DEF CON 34 Red Team Village Talk - AD/hybrid Recon Tool
2026-07-11 · MEDIUMAustralia warns of global campaign targeting vulnerable CMS platforms
2026-07-10 · MEDIUMHow do you keep archived firewall logs usable during a threat hunt?
2026-07-10 · MEDIUMClosing the Timing Gap: Defensive Temporal Observability
2026-07-10 · MEDIUMHackers exploit critical auth bypass in Gitea Docker image
2026-07-10 · MEDIUMCISA KEV Threat Intel Orchestrator
2026-07-09 · MEDIUMMOD REQUEST: Can you ban the excessive AI posters please?
2026-07-09 · MEDIUM12 Million Impacted by Data Breach at Japanese Telco KDDI
2026-07-09 · MEDIUMMicrosoft patches RoguePlanet Defender zero-day vulnerability
2026-07-08 · MEDIUMLone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
2026-07-08 · MEDIUMAI agents went from "cool demo" to "exploiting CVEs in 10 hours"
2026-07-08 · MEDIUMHackers exploit Roundcube flaw to spy on academic researchers
2026-07-08 · MEDIUMDrift Corpus: binary diffs of 240+ 2026 Windows kernel patches
2026-07-08 · MEDIUMCISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
2026-07-08 · MEDIUMCISA orders feds to prioritize patching Langflow auth bypass flaw
2026-07-08 · MEDIUMChina-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
2026-07-08 · MEDIUMUbiquiti warns of new max severity UniFi OS vulnerability
2026-07-08 · MEDIUMCISA orders feds to patch max severity ColdFusion flaw by Friday
2026-07-07 · MEDIUMSafer-dependencies: A toolkit for claude code to ensure dependencies used aren't vuln, don't use abandoned packages, implement cooldown to avoid supply chain attacks, etc...
2026-07-07 · MEDIUMChinese hackers develop LONGLEASH malware to expand ORB network
2026-07-07 · MEDIUMCybersecurity statistics of the week (June 29th - July 5th)
2026-07-07 · MEDIUMSpain arrests suspected member of pro-Russian hacktivist groups
2026-07-07 · MEDIUMSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
2026-07-06 · HIGHJanuscape (CVE-2026-53359): 16 year old Critical Linux KVM Guest-to-Host Escape, PoC Public
CVE-2026-53359
2026-07-06 · MEDIUM
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
2026-07-06 · MEDIUMAnyone know these listening ports/vendors used?
2026-07-06 · HIGHExploitarium coverage update: CVE-2026-20896 Gitea probing confirmed + 10 new rules added
CVE-2026-20896
2026-07-06 · MEDIUM
I feel like a fraud and I don't know what to do
2026-07-06 · HIGHMax severity Adobe ColdFusion flaw now exploited in attacks
CVE-2026-48282
2026-07-06 · MEDIUM
Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
2026-07-06 · MEDIUMVale a pena estudar cibersegurança para quem trabalha com manutenção de notebooks?
2026-07-06 · MEDIUMPrompt Injection Attacks Trick AI Agents Into Making Crypto Payments
2026-07-06 · MEDIUMCyber Security Analyst vs. Insider Threat / DLP Analyst?
2026-07-05 · MEDIUMBuilding an interactive career simulator for network engineers: From CCNA basics to SOC and Pentest operations.
2026-07-05 · MEDIUMDid global cybersecurity tightening make my university VPN stop working?
2026-07-05 · MEDIUMSsl cert renewal every 200days
2026-07-05 · HIGHPatch now: CISA warns of actively exploited Linux kernel zero-day (CVE-2026-43456)
CVE-2026-43456