Known Exploited Vulnerabilities and counting....

A known exploited vulnerability (KEV) refers to a software vulnerability that is being actively exploited by cybercriminals or threat actors. When a vulnerability becomes known to be exploited in the wild, it signals that the vulnerability poses a significant and imminent risk to organizations.

Cybersecurity Editorial Brief — May 25, 2026

Google has issued a public warning about proposed lawful-access legislation, cautioning that the bill would create a "surveillance infrastructure" with significant cybersecurity implications. The company's concerns center on the potential for government-mandated access mechanisms to introduce systemic vulnerabilities that could be exploited by malicious actors. This represents a familiar tension in cybersecurity policy: the technical reality that backdoors and special access channels, regardless of their intended use, create attack surfaces that cannot be selectively secured for "authorized" parties only.

The warning underscores ongoing debates about encryption, lawful intercept capabilities, and the practical security trade-offs inherent in surveillance legislation. Security professionals have consistently demonstrated that weakening encryption or building in access mechanisms fundamentally compromises the integrity of secure systems. Google's public stance reflects industry consensus that such measures, while potentially serving law enforcement objectives, create measurable risks to the broader security posture of communications infrastructure.

Sources: The Globe and Mail

Woman Looking at Computer Screen

CVEs form a database of known security vulnerabilities that are actively tracked and managed by a group of organizations, such as the U.S. National Cyber Security Alliance. CVEs are an important tool for network security management because they not only provide an inventory of existing vulnerabilities, but also provide information about how the vulnerability can be exploited and instructions on how to protect against it.

Search Known Exploits

Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment

Loading vendors and products...

Upcoming Patch Due Dates

via Binding Operational Directive 22-01

(BOD) 22-01 is a directive issued by the Cybersecurity and Infrastructure Security Agency (CISA) in the United States to federal agencies and federal contractors in order to improve their cybersecurity practices. It provides a set of guidelines and requirements that these agencies and contractors must follow to increase their defenses against cyber threats.

Loading...

News Logo

Cyber Security News

You may have missed...


📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://hackread.comMay 25

Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches - Hackread

A hacker is selling a 340M OnlyFans user database allegedly built by matching old breach data and public profiles to real OnlyFans accounts.

https://www.visualcapitalist.comApr 30

The Biggest Crypto Hacks Since 2025, Ranked by Money Lost

Comprehensive ranking of the 10 largest crypto hacks since 2025, with Bybit's $1.4 billion breach at the top, followed by KelpDAO and Drift Trade both...

https://thehackernews.comMay 23

Microsoft Defender Vulnerabilities CVE-2026-41091 and CVE-2026-45498 Under Active Exploitation

Microsoft disclosed that privilege escalation and denial-of-service flaws in Defender (CVE-2026-41091 and CVE-2026-45498) have come under active explo...

https://gizmodo.comMay 24

The SolarWinds Hack Was More Humiliating for the Government Than We Thought

But we now have a few more crumbs to work with, because new revelations from Bloomberg have revealed that the hackers were in Treasury Department ...

https://www.tomshardware.comMay 24

Wi-Fi controlled hacking USB cable stealthily packs in a microcontroller, microSD storage, and more

... cybersecurity learners'. News. By Mark Tyson published 12 hours ago. The $82 Hacknect 'looks like a normal USB cable' and its makers are enjoying ...

https://cybermagazine.comMay 24

Dragos: Putting Operational Technology Risks in Perspective | Cybersecurity Magazine

In this Cyber Magazine Q&A, Magpie Graham, VP Strategic Intelligence at Dragos, examines the evolving OT threat landscape and key operational ...

https://www.kucoin.comMay 24

France Accounts for 70% of Global Crypto Wrench Attacks, Says Joe Nakamoto | KuCoin

Why This Story Matters for Crypto Security. Wrench attacks occupy a different threat category than the digital exploits most crypto users prepare for.

https://www.visualcapitalist.comMay 24

The Biggest Crypto Hacks Since 2025, Ranked by Money Lost

Analysis of the largest crypto hacks including KelpDAO and Drift, showing how attackers compromised third-party systems and verification mechanisms.


Updated daily