# VulnCheck > Outpace Adversaries ## Events - [Australian Cyber Conference - Canberra](https://www.vulncheck.com/raw/events/australian-cyber-conference-2025.md): VulnCheck will be sponsoring the Australian Cyber Conference (AISA) at the National Convention Center in Canberra, Australia. Our booth is Startup Booth 55. - [AvengerCon IX](https://www.vulncheck.com/raw/events/avenger-con2025.md): AvengerCon IX is AvengerCon is a security event hosted by volunteers from the 780th MI BDE to benefit the hackers of the U.S. Cyber Command and Department of Defense. The event will take place at the Georgia Cyber Center in Augusta, Georgia. - [Aviation Cybersecurity Summit 2025](https://www.vulncheck.com/raw/events/aviation-cybersecurity-summit-2025.md): Taking place in Zurich, Switzerland, VulnCheck is sponsoring Aviation ISAC's Aviation Cybersecurity Summit 2025. - [Meet VulnCheck at the 2026 Billington Federal Cybersecurity Summit](https://www.vulncheck.com/raw/events/billington-federal-2026.md): VulnCheck is proud to be a Bronze Sponsor of the 2026 Billington Federal Cybersecurity Summit. - [Black Hat Asia 2025](https://www.vulncheck.com/raw/events/black-hat-asia2025.md): VulnCheck is heading to Singapore to compete in the very first Startup Spotlight Competition at Black Hat Asia 2025. Black Hat Asia will feature Briefings by experts from around the world presenting the latest research in cybersecurity risks, developments and trends, dozens of open-source tool demos in Arsenal, a robust Business Hall, networking opportunities, social events, and much more. - [Meet VulnCheck in Las Vegas in August 2026](https://www.vulncheck.com/raw/events/black-hat-def-con-2026.md): VulnCheck is heading to Las Vegas for Black Hat USA 2026 and DEF CON 34, and we are bringing a full week of opportunities to connect and engage with our team. - [Black Hat Europe 2023](https://www.vulncheck.com/raw/events/black-hat-europe-2023.md): Black Hat Europe 2023 in London December 4-7, 2023. Reach out to meet the team. - [Black Hat USA 2023](https://www.vulncheck.com/raw/events/black-hat-usa-2023.md): Black Hat USA 2023 in Las Vegas August 5-10, 2023. Reach out to meet the team. - [Black Hat USA 2025](https://www.vulncheck.com/raw/events/black-hat-usa2025.md): VulnCheck is heading to Las Vegas for Black Hat USA 2025. Black Hat USA 2025 will feature Briefings by experts from around the world presenting the latest research in cybersecurity risks, developments and trends, dozens of open-source tool demos in Arsenal, a robust Business Hall, networking opportunities, social events, and much more. - [Black Hat Europe 2025](https://www.vulncheck.com/raw/events/blackhat-europe-2025.md): Come meet the VulnCheck team at Black Hat Europe 2025 in London. - [BlackHat Asia](https://www.vulncheck.com/raw/events/blackhatasia2024.md): BlackHat Asia Pacific 2024 in Singapore - [BlackHat Europe](https://www.vulncheck.com/raw/events/blackhateur2024.md): BlackHat Europe 2024 in London - [BlackHat USA](https://www.vulncheck.com/raw/events/blackhatusa2024.md): BlackHat USA 2024 in Las Vegas - [Boston Application Security Conference 2023](https://www.vulncheck.com/raw/events/boston-application-security-conference-2023.md): Boston Application Security Conference in Boston April 1, 2023. - [BSides Cheltenham 2025](https://www.vulncheck.com/raw/events/bsides-cheltenham2025.md): Through education, collaboration, and innovation within the cyber security community, BSides Cheltenham is focused on building a safer digital world. - [VulnCheck at BSides Detroit 2026](https://www.vulncheck.com/raw/events/bsides-detroit-2026.md): VulnCheck Security Researcher Patrick Garrity will be presenting “Breaking Bones and Uncovering KEVs: Lessons from Security Research and Skateboarding in Detroit” - [VulnCheck’s Patrick Garrity to Present at CloudCon 2026](https://www.vulncheck.com/raw/events/cloudcon-2026.md): Patrick Garrity will present "Tracking and Tackling the Wave of AI Discovered Vulnerabilities” at CloudCon 2026 on July 27 2026 at 2 p.m. - [Code Remix Summit 2025](https://www.vulncheck.com/raw/events/code-remix2025.md): VulnCheck is heading to Miami to host a hands-on Hack Track at the Code Remix Summit. Code Remix Summit. This event brings together software engineers, architects, and leadership to explore innovative ways to evolve and secure codebases with automation, AI, and community-driven solutions. - [Make a Splash with VulnCheck at CrowdStrike Day Zero 2026](https://www.vulncheck.com/raw/events/crowdstrike-day-zero-2026.md): VulnCheck is excited to sponsor the official CrowdStrike Day Zero 2026: Threat Research Summit Pool Party, bringing together the threat research community for a day of connection, conversation, and celebration. - [VulnCheck at CS4CA Canada 2026](https://www.vulncheck.com/raw/events/cs4ca-2026.md): June 2 – 3, 2026 - [VulnCheck's Khushali Dalal to Present at Cyberjutsu Con 2026](https://www.vulncheck.com/raw/events/cyberjutsu-2026.md): VulnCheck Security Researcher Khushali Dalall will be presenting “The Reality of Cyber Careers: Wins, Setbacks, and Everything In Between” - [Discover VulnCheck at CYBERUK 2026](https://www.vulncheck.com/raw/events/cyberuk-2026.md): VulnCheck is proud to sponsor CYBERUK 2026, the UK government’s flagship cybersecurity event hosted by the National Cyber Security Centre (NCSC). - [CYBERUK 2024](https://www.vulncheck.com/raw/events/cyberuk2024.md): The UK government's flagship cyber security event - [CYBERWARCON 2025](https://www.vulncheck.com/raw/events/cyberwarcon-2025.md): CYBERWARCON hosts the world’s foremost cyber defenders, researchers, and intelligence professionals to share insights on global cyber conflict, adversary tactics, and emerging threats in Arlington, VA. - [VulnCheck is Sponsoring DistrictCon 2026](https://www.vulncheck.com/raw/events/district-con-2026.md): VulnCheck is thrilled to be a Gold Sponsor of DistrictCon 2026, which takes place Jan 24-25 in Washington, D.C. - [FIRST Cyber Threat Intelligence Conference](https://www.vulncheck.com/raw/events/first-cti2025.md): Cyber Threat Intelligence Conference is sponsored by FIRST. The conference provides a gathering place for experts in the field to share knowledge, contribute ideas, and learn the latest in proactive approaches in relation to threat intelligence. - [VulnCheck’s Patrick Garrity to Present at FIRST 38th Annual Conference](https://www.vulncheck.com/raw/events/first-denver-2026.md): Patrick Garrity will present “A Researcher-Centric Approach to Coordinated Vulnerability Disclosure” at FIRST’s 38th Annual Conference on June 15, 2026, from 2:40 - 3:25 p.m. - [FIRST VulnCon](https://www.vulncheck.com/raw/events/first-vulncon2025.md): VulnCon is sponsored by FIRST and the CVE Program. The purpose of the conference is to collaborate with various vulnerability management and cybersecurity professionals to develop forward leaning ideas that can be taken back to individual programs for action to benefit the vulnerability management ecosystem. - [VulnCheck at Gartner® Security & Risk Management Summit 2026](https://www.vulncheck.com/raw/events/gartner-srm-2026.md): We are excited to be an Exhibitor at the Gartner® Security & Risk Management Summit, where security and risk leaders come together to address today’s most pressing cybersecurity challenges and shape the future of enterprise defense. - [GovWare 2025](https://www.vulncheck.com/raw/events/govware-2025.md): As Asia’s premier cybersecurity event, GovWare brings together global leaders and innovators. Meet VulnCheck at Startup Pavillion. - [GovWare 2024](https://www.vulncheck.com/raw/events/govware2024.md): Join over 12,000 policymakers, cyber leaders and practitioners, top executives, and more at the GovWare Conference and Exhibition! A premier milestone in Asia's cyber calendar, the global cyber community gathers to explore the latest trends and cutting-edge tech, build connections and forge partnerships. - [VulnCheck’s Guillermo Menjivar Speaking at DevOps Pro Europe 2026](https://www.vulncheck.com/raw/events/guillermo-menjivar-speaking-at-devops-pro-europe-2026.md): VulnCheck Research Engineer Guillermo Menjivar will be presenting 'CVSS Is a Starting Point, Exposure Validation Turns It Into an SRE Signal' at DevOps Pro Europe 2026 on May 21, 2026. - [Health-ISAC Fall Americas Summit 2025](https://www.vulncheck.com/raw/events/health-isac-fall-americas-summit-2025.md): Health-ISAC is bringing together healthcare security professionals, innovators, and thought leaders in Carlsbad, California December 1-5. - [Catch VulnCheck at Health-ISAC Americas Spring Summit 2026](https://www.vulncheck.com/raw/events/health-isac-spring-americas-summit-2026.md): May 4-8 in Tampa, FL - [VulnCheck at Infosecurity Europe 2026](https://www.vulncheck.com/raw/events/infosec-europe-2026.md): Meet VulnCheck at Infosec Europe 2026, June 2-4, at ExCeL London. Join us at Stand F134 to explore how real-time exploitation intelligence is reshaping vulnerability prioritization and risk reduction. Plus, catch our CISO Panel on Strategies for Exploitation Risk Reduction on June 2 at 1:30 p.m. - [Infosecurity Europe 2025](https://www.vulncheck.com/raw/events/infosec-europe2025.md): VulnCheck is heading to London for Infosecurity Europe 2025. Infosecurity Europe is celebrating 30 years of building a safer cyber world for eveyone by providing the most comprehensive and cutting-edge content for attendees. - [Infosecurity Europe 2023](https://www.vulncheck.com/raw/events/infosecurity-europe-2023.md): Infosecurity Europe 2023 in London 20–22 June 2023. Reach out to meet the team. - [Infosecurity Europe 2024](https://www.vulncheck.com/raw/events/infosecurity-europe-2024.md): Infosecurity Europe 2024 in London 4–6 June 2024. Reach out to meet the team. - [Join the VulnCheck Team in San Francisco for Meetings and Dinners](https://www.vulncheck.com/raw/events/join-the-vulncheck-team-in-san-francisco.md): Throughout the week, we will be hosting a series of exclusive dinners and private, invite-only meetings, designed for meaningful conversations around emerging vulnerabilities, threat intelligence, and what’s next for proactive security teams. - [VulnCheck's Jonathan Peterson Speaking at Wild West Hackin' Fest 2026](https://www.vulncheck.com/raw/events/jonathan-peterson-speaking-at-wild-west-hackin-fest-2026.md): VulnCheck Exploit Developer and Vulnerability Researcher Jonathan Peterson will be presenting 'Portable Deserialization Payloads Using Go' at Wild West Hackin' Fest 2026 on February 12, 2026. - [KKR Euro CISO Summit 2025](https://www.vulncheck.com/raw/events/kkr-euro-ciso-summit-2025.md): VulnCheck heads to Paris for the KKR Euro CISO Summit 2025. This is a one-day event brings together professionals across the security and tech space for engaging sessions and real-world discussions. - [Join VulnCheck at LABScon 2026](https://www.vulncheck.com/raw/events/labscon-26.md): VulnCheck is proud to sponsor LABScon 2026 Capture the Flag competition, where security researchers, exploit developers, and defenders put their skills to the test.  - [VulnCheck's Adam Powis to Present at LCHS 2026](https://www.vulncheck.com/raw/events/lchs-2026.md): VulnCheck Engineer Adam Powis will be presenting “From Canary Intelligence to C2: Mapping an Attack Fleet with Target Intelligence” - [Join VulnCheck at Black Hat Asia](https://www.vulncheck.com/raw/events/meet-vulncheck-at-blackhat-asia-2026.md): VulnCheck is proud to sponsor Black Asia, 21 - 24 April, at Marina Bay Sands in Singapore. Black Hat Asia brings together cybersecurity leaders, researchers, and practitioners to share cutting-edge insights and defense strategies. - [Meet VulnCheck at VulnCon 2026](https://www.vulncheck.com/raw/events/meet-vulncheck-at-vulncon-2026.md): Join VulnCheck at CVE | FIRST Vulnerability Conference 2026 (VulnCon 2026) and Annual CNA Summit, where the global vulnerability management community gathers to collaborate, exchange research, and advance the vulnerability ecosystem. The conference takes place April 13 - 16 in Scottsdale, Arizona, bringing together researchers, vendors, and defenders working to improve how vulnerabilities are discovered, prioritized, and remediated. - [OODAcon 2025](https://www.vulncheck.com/raw/events/oodacon-2025.md): Bringing together global leaders, technologists, and strategists to explore the intersection of innovation, security, and resilience. - [OSINT Tech Expo 2025](https://www.vulncheck.com/raw/events/osint-tech-expo2025.md): Meet the VulnCheck team at the OSINT Tech Expo in Reston, Virginia on May 2nd. OSINT Tech Expo brings OSINT professionals together to network and hear first-hand from "lightning talks" by OSINT speakers. - [OWASP Global AppSec Dublin 2023](https://www.vulncheck.com/raw/events/owasp-global-appsec-dublin-2023.md): OWASP Global AppSec Dublin 2023 February 13-16, 2023. - [OWASP Global AppSec Washington DC 2023](https://www.vulncheck.com/raw/events/owasp-global-appsec-washington-dc-2023.md): OWASP Global AppSec Washington DC 2023 October 30, 2023 - November 3, 2023. - [VulnCheck at RLBN East 2026](https://www.vulncheck.com/raw/events/rbln-east-2026.md): VulnCheck is a Quantum Tier Partner and proud sponsor of RLBN East (June 12-14 in Reston, VA), bringing together security practitioners, researchers, and leaders focused on advancing vulnerability management and coordinated disclosure. - [Meet VulnCheck at RLBN Europe 2026](https://www.vulncheck.com/raw/events/rbln-europe-2026.md): VulnCheck is proud to be a Quantum Tier Partner and sponsor of RLBN Europe 2026. - [RSA Conference 2023 USA](https://www.vulncheck.com/raw/events/rsa-conference-2023-usa.md): RSA Conference 2023 USA in San Francisco April 24-27, 2023. Reach out to meet the team. - [RSA Conference 2024](https://www.vulncheck.com/raw/events/rsac2024.md): USA RSA Conference for 2024 in San Francisco - [RSAC 2025](https://www.vulncheck.com/raw/events/rsac2025.md): VulnCheck is heading to San Francisco for RSAC 2025. RSAC aims to bring cybersecurity industry leaders, innovators, and professionals together to unite by a common mission: to foresee risks, counter threats, and embrace the challenges ahead. - [S4x23](https://www.vulncheck.com/raw/events/s4x23.md): ICS security community event at Loews Miami Beach in February 13-16, 2023. Reach out to meet the team. - [S4x24](https://www.vulncheck.com/raw/events/s4x24.md): ICS security community event at Loews Miami Beach in March 4-7, 2024. Reach out to meet the team. - [S4x25](https://www.vulncheck.com/raw/events/s4x25.md): S4X25 is the premiere event for ICS and OT cybersecurity leaders and practitioners to push the OT industry forward. This year’s event is in Tampa, FL. - [Experience S4x26 in Style at the Cabana with VulnCheck](https://www.vulncheck.com/raw/events/s4x26.md): VulnCheck is proud to host a Premium Cabana at S4x26, the premier gathering for cybersecurity innovators and tech enthusiasts. The Cabana Session takes place on Wednesday, Feb 25, from 1 - 4:30 p.m. ET. - [Sea Air and Space 2024](https://www.vulncheck.com/raw/events/seaandair2024.md): Sea Air and Space 2024 at National Harbor - [SOF Week 2025](https://www.vulncheck.com/raw/events/sof-week2025.md): SOF Week is an annual conference for the international SOF community to learn, connect, and honor its members. The event is jointly sponsored by USSOCOM and Global SOF. - [Software and Supply Chain Assurance Forum 2023](https://www.vulncheck.com/raw/events/software-and-supply-chain-assurance-forum.md): Software and Supply Chain Assurance Forum in Tysons Corner VA February 13-16, 2023. Reach out to meet the team. - [VulnCheck Participates in FS-ISAC Americas Spring Summit 2026 as a Silver Sponsor with a Solutions Showcase Presentation](https://www.vulncheck.com/raw/events/spring-summit-sponsor.md): VulnCheck is proud to be a Silver Sponsor at the FS-ISAC Americas Spring Summit 2026, March 1-4, in Orlando, Florida. FS-ISAC brings together financial security professionals, innovators, and thought leaders dedicated to advancing cybersecurity and resilience across the financial ecosystem. - [VulnCheck Heading to Federal Bridge Collective Networking Event 2026](https://www.vulncheck.com/raw/events/tac-federal-bridge-collective-networking-event.md): VulnCheck is proud to sponsor the TAC Federal Bridge Collective Networking Event, an afternoon of high-impact networking that brings together federal agencies, government contractors, recruiters, and industry professionals. - [THREATCON1](https://www.vulncheck.com/raw/events/threatcon-1-2025.md): VulnCheck is hosting THREATCON1 in Reston, VA from September 21-22, 2025. A place where leaders in cyber threat response collaborate to get better, smarter and faster in how we protect our global economy and national security. - [THREATCON1 Call for Sponsors](https://www.vulncheck.com/raw/events/threatcon1-2026-cfs.md): VulnCheck is hosting THREATCON1 in Reston, VA from September 21-22, 2025. A place where leaders in cyber threat response collaborate to get better, smarter and faster in how we protect our global economy and national security. - [Vuln4Cast 2024](https://www.vulncheck.com/raw/events/vuln4cast-2024.md): VulnCheck is a Gold Sponsor at FIRST's Vuln4Cast October 3-4 in the Netherlands. This Technical Colloquia gathers a global audience to present, discuss, and improve vulnerability measurement and prediction models, methodologies, and techniques. - [VulnCheck’s Scott Moore at BSides Knoxville 2026](https://www.vulncheck.com/raw/events/vulncheck's-scott-moore-bsides-knoxville-2026.md): Security Architect Scott Moore will be presenting “The Myth of the Meteoric Rise in Vulnerabilities” - [VulnCon](https://www.vulncheck.com/raw/events/vulncon2024.md): CVE/FIRST VulnCon 2024 & Annual CNA Summit - [VulnCheck is Sponsoring WiCyS 2026](https://www.vulncheck.com/raw/events/wicys-2026.md): VulnCheck is proud to be a Gold sponsor of WiCyS 2026, which takes place March 11-13. The premier event dedicated to advancing women and underrepresented professionals in cybersecurity. ## News - [Anthony Bettini On SBOMs](https://www.vulncheck.com/raw/news/anthony-sboms.md): What They Are, What They Are Not, And How Organizations Can Use Them To Make Us More Secure - [Anthony Bettini on Converting Vulnerabilities to Exploit Intelligence](https://www.vulncheck.com/raw/news/converting-vulnerabilities.md): Check out the episode for our conversation on his lessons and themes after founding three companies and why he completely ignores the competitive landscape - [Correlating CVE's to botnets, threat actors and ransomware families.](https://www.vulncheck.com/raw/news/correlating_cve39s_to_botnets_threat_actors_and_ransomware_families.md): This video summarizes how VulnCheck easily correlates CVE's to botnets, threat actors and ransomware families for customers ... - [Forbes' Cloud 100 List Rising Star](https://www.vulncheck.com/raw/news/forbes-cloud-100.md): VulnCheck is honored to be name to the Forbes Cloud 100 List as one of their 20 Rising Stars for our unparalleled vulnerability and exploit data solutions for enterprise, government and cybersecurity solutions providers. - [Get to Know VulnCheck in Three Minutes!](https://www.vulncheck.com/raw/news/get_to_know_vulncheck_in_three_minutes.md): This video will give viewers a high-level, three-minute overview of the problem VulnCheck is solving in the cybersecurity market, ... - [Mass Technology Leadership Council Tech Top 50 Startup of the Year Nominee](https://www.vulncheck.com/raw/news/mass-technology-leadership-council-tech-top50-startup-of-the-year-nominee.md): The Mass Technology Leadership Council (MassTLC) announced the finalists for the 2024 Tech Top 50, and we are honored to be nominated for Startup of the Year. The Tech Top 50 is an annual recognition of the most innovative and fastest-growing technology companies in Massachusetts. - [The Massachusetts Technology Leadership Council (MTLC) Tech Top 50 Startup of the Year 2025: VulnCheck](https://www.vulncheck.com/raw/news/mass-technology-leadership-council-tech-top50-startup-of-the-year-winner.md): The Massachusetts Technology Leadership Council (MTLC) announced the winners and honorees of its annual Tech Top 50 for 2025 on March 13 which recognizes the leaders powering Massachusetts’ tech ecosystem. VulnCheck won Startup of the Year 2025. - [Microsoft Advisories Are Getting Worse](https://www.vulncheck.com/raw/news/microsoft-advisories.md): A predictable patch cadence is nice, but the software giant can do more. - [Prioritizing Vulnerabilities Through Knowledge and Automation](https://www.vulncheck.com/raw/news/prioritizing-vulnerabilites.md): Jacob Baines of VulnCheck examines how automation and shared knowledge can aid teams in prioritizing vulnerabilities. - [RSA Conference Innovation Sandbox](https://www.vulncheck.com/raw/news/rsa-conference-innovation-sandbox.md): VulnCheck is an RSAC Innovation Sandbox Finalist and will be presenting at the live event on Monday, May 6 at the Moscone Center, San Francisco, CA. Click to view why we were nominated. - [Anthony Bettini on Converting Vulnerabilities to Exploit Intelligence](https://www.vulncheck.com/raw/news/secure-ventures-kyle.md): Check out the episode for our conversation on his lessons and themes after founding three companies and why he completely ignores the competitive landscape - [Snake Oilers: Sublime Security, VulnCheck and Devicie](https://www.vulncheck.com/raw/news/snake-oilers-vulncheck.md): VulnCheck: Provides vulnerability intelligence to governments, large enterprises and vendors - [Understanding the VulnCheck Exploit Intelligence Platform](https://www.vulncheck.com/raw/news/understanding_the_vulncheck_exploit_intelligence_platform.md): This video provides viewers with a high-level overview of the Exploit Intelligence Platform that we deliver to our global installed ... - [VulnCheck Named as a Prestigious 2025 SINET16 Innovator](https://www.vulncheck.com/raw/news/vulncheck-recognized-as-a-2025-sinet16-innovator.md): Company's Unique Approach to Exploit Intelligence Receives Another Elite Industry Recognition - [VulnCheck is Different: We ARE Exploit Intelligence.](https://www.vulncheck.com/raw/news/vulncheck_is_different_we_are_exploit_intelligence.md): VulnCheck is different. We are building a platform that helps customers respond to the threats that matter, and we're filling an ... - [VulnCheck KEV Community Intro](https://www.vulncheck.com/raw/news/vulncheck_kev_community_intro.md): Introducing the VulnCheck Known Exploited Vulnerabilities (KEV) catalog, a free community database of known exploited ... - [VulnCheck Known Exploited Vulnerabilties - Community Update](https://www.vulncheck.com/raw/news/vulncheck_known_exploited_vulnerabilties__community_update.md): Patrick Garrity provides a quick update on VulnCheck KEV (Known Exploited Vulnerabilities), a free community service that we ... - [VulnCheck Mission: Deliver exploit & vulnerability intelligence faster than anyone.](https://www.vulncheck.com/raw/news/vulncheck_mission_deliver_exploit_amp_vulnerability_intelligence_faster_than_anyone.md): This video will provide a high-level overview of why VulnCheck exists and our mission of supporting the global ecosystem with ... - [VulnCheck: Prioritizing vulnerabilities for global cybersecurity teams.](https://www.vulncheck.com/raw/news/vulncheck_prioritizing_vulnerabilities_for_global_cybersecurity_teams.md): B is spent globally on vulnerability management, yet teams are still fighting a losing battle. This video provides a high-level ... - [VulnCheck: RSAC Innovation Sandbox Submission](https://www.vulncheck.com/raw/news/vulncheck_rsac_innovation_sandbox_submission.md): VulnCheck is the vulnerability intelligence company helping enterprises, government organizations, and cybersecurity vendors ... - [Why vulnerability management needs a refresh](https://www.vulncheck.com/raw/news/vulnerability-management.md): Adversaries are exploiting new vulnerabilities much faster than organizations are remediating them - [Vulns Rising - A History Behind the Exponential Growth in Software Vulnerability Disclosure](https://www.vulncheck.com/raw/news/vulns_rising__a_history_behind_the_exponential_growth_in_software_vulnerability_disclosure.md): Patrick Garrity, Security Researcher shares his perspective on the exponential growth in software vulnerabilities published ... - [Webinar: Exploring Vulnerability Exploitation Beyond CISA KEV](https://www.vulncheck.com/raw/news/webinar_exploring_vulnerability_exploitation_beyond_cisa_kev.md): In this webinar, we will discuss the important role CISA's Known Exploited Vulnerabilities (KEV) catalog has played in vulnerability ... ## Press - [VulnCheck Drives Record Growth with 3x Year-over-Year ARR as Demand for Exploit Intelligence Skyrockets](https://www.vulncheck.com/raw/press/2024-record-growth.md): Exploit intelligence leader scales significantly and receives industry recognition for disrupting legacy approach to vulnerability management and threat intelligence - [VulnCheck Announces Cybersecurity Leaders Jen Easterly and Andrew Boyd as Keynote Speakers for THREATCON1 ](https://www.vulncheck.com/raw/press/2025-threatcon-1-keynote-speakers-announcement.md): Easterly and Boyd join defenders at inaugural conference focused on countering emerging threats, September 21-22 in Reston, VA - [Cybersecurity Leaders Take the Stage Next Week at VulnCheck’s Inaugural THREATCON1 Summit](https://www.vulncheck.com/raw/press/2025-threatcon-1-podcast-announcement.md): Exploit Intelligence Leader Launches THREATCON1 Podcast with First Two Episodes Featuring Jen Easterly and Andrew Boyd - [VulnCheck and Filigran Partner to Transform Enterprise Threat Intelligence Capabilities](https://www.vulncheck.com/raw/press/2025-vulncheck-filigran-partnership.md): Integration Fuels Security Teams with Real-Time, Actionable Insights on Vulnerability Exploitations - [VulnCheck Launches Integration with ThreatQuotient, a Securonix Company, to Help Defenders Prioritize Remediation with Powerful Threat & Exploit Intelligence Solution](https://www.vulncheck.com/raw/press/2025-vulncheck-threatquotient-partnership.md): Now Available in the ThreatQuotient Marketplace, the Integration Provides Security Teams with Timely Updates on Known Exploited Vulnerabilities, Attack Vectors and Threat Actor Activities - [VulnCheck Ranks No. 478 on the 2026 Inc. 5000 List of America's Fastest-Growing Private Companies](https://www.vulncheck.com/raw/press/2026-inc-5000-vulncheck.md): 717% Three-Year Revenue Growth Places VulnCheck in the Top 10% Overall and Among the Top 10 Cybersecurity Companies - [VulnCheck Announces Former U.S. Cyber Command and NSA Leader Gen. Paul M. Nakasone (Ret.) as 2026 THREATCON1 Keynote Speaker](https://www.vulncheck.com/raw/press/2026-threatcon-1-keynote-speakers-announcement.md): Conference returns for second year, opens call for presentations for showcase and technical tracks - [E-TECH SYSTEM Signs Distribution Agreement with VulnCheck for South Korea](https://www.vulncheck.com/raw/press/e-tech-system-vulncheck-south-korea.md): E-TECH SYSTEM, an IT solutions and services consulting company headed by CEO Kim Beom-su, announced that it has signed a distribution agreement with VulnCheck, The Exploit Intelligence Company, to bring VulnCheck’s solutions to enterprises across South Korea. - [VulnCheck Expands Executive Leadership Team to Accelerate Growth and Surging Demand for Vulnerability, Threat and Exploit Intelligence](https://www.vulncheck.com/raw/press/expanding-leadership.md): Former [redacted], Rapid7, and Finite State leaders bring decades of experience building, scaling, and marketing world-class cybersecurity organizations and products - [Finalist at Black Hat Asia 2025](https://www.vulncheck.com/raw/press/finalist-at-black-hat-asia-2025.md): VulnCheck Named Startup Spotlight Competition Finalist at Black Hat Asia 2025 - [VulnCheck Named One of 20 Rising Stars as Part of Forbes’ Cloud 100 List](https://www.vulncheck.com/raw/press/forbes-top-20-rising-stars.md): VulnCheck has been named one of the 20 Rising Stars as part of the ninth annual Forbes 2024 Cloud 100 list, the definitive list of the top 100 private cloud companies in the world. - [VulnCheck Selected as Finalist for RSA Conference 2024 Innovation Sandbox Contest](https://www.vulncheck.com/raw/press/innovation-sandbox.md): Exploit Intelligence Company Recognized for Helping Enterprise, Government and Cybersecurity Solution Providers Solve the Vulnerability Prioritization Challenge - [VulnCheck Unveils New Intelligence Capabilities to Track Vulnerable Internet-Connected Devices and Attacker Infrastructure](https://www.vulncheck.com/raw/press/iot.md): IP Intelligence Integrates with Next-Generation Firewalls to Block Command and Control Infrastructure in Real-Time - [VulnCheck Named CVE Numbering Authority for Common Vulnerabilities Exposures and Exposures](https://www.vulncheck.com/raw/press/named-cna.md): On the Heels of Accreditation, Company Launches Advisories Program to Simplify How Researchers Share Vulnerabilities with Vendors - [VulnCheck Offers Vulnerability Management Continuity by NVD 1.0 After Migration Deadline Maintaining NIST NVD](https://www.vulncheck.com/raw/press/nvd.md): VulnCheck Community Platform Tier Offering Provides Security Teams with Extended Timeline to Migrate to NVD\’s 2.0 APIs After December 15 Deadline - [VulnCheck Exploit Intelligence Report Separates Real-World Exploitation Activity from Theoretical Vulnerability Risk](https://www.vulncheck.com/raw/press/real-world-exploit-report.md): Analysis Finds 1% of Vulnerabilities Were Exploited in the Wild in 2025 and Identifies the 50 Most Routinely Targeted Flaws of Last Year - [VulnCheck Raises $3.2 Million to Solve Prioritization Challenge for Enterprise, Government and Cybersecurity Solution Providers](https://www.vulncheck.com/raw/press/seed-funding.md): Sorenson Ventures leads seed funding with participation from In-Q-Tel; Vulnerability intelligence startup powered by former lead researchers and exploit developers at Tenable, Rapid7, Dragos and Veracode - [VulnCheck Closes $7.95 Million in Seed Funding to Accelerate Momentum Amid Growing Demand for its Next-Generation Exploit Intelligence Solutions Amid Growing Demand for its Next-Generation Exploit Intelligence Solutions](https://www.vulncheck.com/raw/press/seed-funding-momentum.md): Financing will help the 2024 RSAC Innovation Sandbox contest finalist develop new enterprise and critical infrastructure offerings that consolidate legacy vulnerability management solutions - [VulnCheck Secures $12 Million in Series A Funding to Meet Surging Global Demand for Exploit Intelligence Solutions](https://www.vulncheck.com/raw/press/series-a.md): Ten Eleven Ventures Leads Round; Funding Fuels Company's Disruptive Approach to Solving Vulnerability Prioritization Challenge for Organizations Worldwide - [VulnCheck Integrates with ServiceNow to Advance Vulnerability Management](https://www.vulncheck.com/raw/press/service-now.md): VulnCheck for Vulnerability Response and VulnCheck for SBOM Response Now Available in ServiceNow Store; Delivering Prioritized, Actionable Intelligence to Power Threat Response - [Intelligence Solutions to the Public Sector](https://www.vulncheck.com/raw/press/vulncheck-and-carahsoft-partner.md): New Partnership Bolsters Vulnerability Management for U.S. Federal, State and Local Government Agencies - [VulnCheck Announces Inaugural THREATCON1 Security Conference](https://www.vulncheck.com/raw/press/vulncheck-announces-inaugural-threatcon1-security-conference.md): Event Brings Together Researchers, Analysts and Cyber Experts to Showcase Cutting-Edge Research and Real-World Threat Response Strategies - [VulnCheck Partner Program Delivers Real-Time Exploit Intelligence at Scale](https://www.vulncheck.com/raw/press/vulncheck-announces-partner-program.md): New Program Supports Partner Community with First Early-Warning Exploit Intelligence Platform, Enabling New Mitigation Services to Speed the Remediation Process. - [VulnCheck Announces Strategic Leadership Appointments to Accelerate Growth](https://www.vulncheck.com/raw/press/vulncheck-announces-strategic-leadership-appointments-to-accelerate-growth.md): Expanding Leadership Team to Meet Surging Demand for Exploit Intelligence - [VulnCheck and Cyware Partner to Bolster Vulnerability Management](https://www.vulncheck.com/raw/press/vulncheck-cyware.md): Leading Intelligence Companies Join Forces to Identify, Prioritize and Remediate Vulnerabilities That Matter Most; Cyware to Ship with VulnCheck KEV - [VulnCheck Establishes EMEA Headquarters in Cheltenham, UK Amid Soaring Global Demand for Exploit Intelligence](https://www.vulncheck.com/raw/press/vulncheck-establishes-emea-headquarters-in-cheltenham-uk-amid-soaring-global-demand-for-exploit-intelligence.md): Company expands international presence following 319% year-over-year EMEA ARR growth and 100% customer growth - [VulnCheck Joins Operational Technology Cybersecurity Coalition to Advance Real-Time Exploit Intelligence](https://www.vulncheck.com/raw/press/vulncheck-joins-operational-technology-cybersecurity-coalition.md): Partnership expands collaboration to strengthen operational technology security and critical infrastructure protection - [VulnCheck Launches Catalog of Known Exploited Vulnerabilities Fused Exploit Intelligence with Exploit Intelligence](https://www.vulncheck.com/raw/press/vulncheck-kev.md): Company Provides Security Teams and Detection Engineers with Publicly Available Tool to Better Manage Threats and Solve the Prioritization Challenge Deadline - [VulnCheck KEV Surges to Track More than 3,600 Known Exploited Vulnerabilities](https://www.vulncheck.com/raw/press/vulncheck-kev-10000.md): Exploit Intelligence Company Now Tracking 173% More Known Exploited Vulnerabilities than CISA KEV; VulnCheck Community Surpasses 10,000 Users - [VulnCheck KEV Alerts](https://www.vulncheck.com/raw/press/vulncheck-kev-alerts.md): VulnCheck KEV Alerts Deliver Instant Warnings on Actively Exploited Vulnerabilities with Real-Time Slack and Email Notifications - [VulnCheck Launches Canary Intelligence to Provide Verified Evidence of Active Exploitation ](https://www.vulncheck.com/raw/press/vulncheck-launches-canary-intelligence.md): First-party telemetry from live, intentionally vulnerable systems gives security teams real-time proof of exploitation for faster, more confident vulnerability response - [VulnCheck Achieves Record-Setting ARR Growth with Unprecedented Demand for Its Transformative Approach to Exploit Intelligence](https://www.vulncheck.com/raw/press/vulncheck-momentum-2025.md): Expanded global customer footprint, strategic appointments and fresh funding underpin record-setting year for exploit intelligence leader - [VulnCheck introduces VulnCheck NVD++ as a Reliable, High-Performance Alternative to the NIST NVD 2.0 API](https://www.vulncheck.com/raw/press/vulncheck-nvd.md): VulnCheck NVD++ Reduces the Industry’s Dependence on NIST for Reliable and Performant Access to CVE Data - [VulnCheck Adds Common Platform Enumeration (CPE) Data to its NVD++ Service to Improve Vulnerability Prioritization](https://www.vulncheck.com/raw/press/vulncheck-nvd-cpe.md): Latest Update to Community Tier Offering Fills Information Gap and Reduces Industry’s Dependence on NIST NVD for Context on Vulnerable Software, Applications and Systems - [VulnCheck Raises $25M Series B Financing to Address Surging Demand for its Exploit Intelligence Solutions](https://www.vulncheck.com/raw/press/vulncheck-raises-25m-series-b-financing.md): Sorenson Capital Leads Funding Round to Accelerate Adoption of Company’s Industry-Leading Exploitation-Anchored Intelligence Offering - [VulnCheck Named as a Prestigious 2025 SINET16 Innovator](https://www.vulncheck.com/raw/press/vulncheck-recognized-as-a-2025-sinet16-innovator.md): Company's Unique Approach to Exploit Intelligence Receives Another Elite Industry Recognition - [VulnCheck to Support the CVE Program Through Potential Contract Transition](https://www.vulncheck.com/raw/press/vulncheck-to-support-cve-program.md): VulnCheck announces its commitment to supporting the CVE program amidst potential disruptions to MITRE's contract, ensuring continued access to vulnerability data and CVE assignments for the cybersecurity community. - [VulnCheck Launches XDB: The Most Comprehensive Hub of Exploits for Modern Security Teams](https://www.vulncheck.com/raw/press/xdb.md): Largest real-time collection of exploits hosted on git repositories helps researchers, offensive teams and detection engineers solve the vulnerability prioritization challenge and bolster security ## Blog - [The VulnCheck 2022 Exploited Vulnerability Report - A Year Long the CISA KEV Catalog - Blog - VulnCheck Review of the CISA KEV Catalog](https://www.vulncheck.com/raw/blog/2022-cisa-kev-review.md): A review of the vulnerabilities added to the CISA KEV Catalog in 2022. VulnCheck examines which vulnerabilities were added in 2022, who exploited them, and how long it took to add them to the Catalog. - [The VulnCheck 2022 Exploited Vulnerability Report - Missing CISA KEV Catalog Entries - Blog - VulnCheck Catalog Entries](https://www.vulncheck.com/raw/blog/2022-missing-kev-report.md): A review of the vulnerabilities that should have been added to the CISA KEV Catalog in 2022, but weren't. - [Insight into the 2022 Top Routinely Exploited Vulnerabilities VulnCheck](https://www.vulncheck.com/raw/blog/2022-top-exploited.md): VulnCheck provides additional insight into CISA's 2022 Top Routinely Exploited Vulnerabilities by looking at the availability of exploits and examining which threat actors, botnets, and ransomware crews used the vulnerabilities. - [2024 Trends in Vulnerability Exploitation](https://www.vulncheck.com/raw/blog/2024-exploitation-trends.md): In September, VulnCheck identified evidence of 78 CVEs that were publicly disclosed for the first time as exploited in the wild. - [Verizon's 2024 DBIR Report - Mapping CIS Controls to Incident Classification Patterns](https://www.vulncheck.com/raw/blog/2024-verizon-dbir.md): Verizon's annual DBIR report incident classification patterns mapped to the Center for Internet Security's (CIS) Critical Security Controls. - [THREATCON1 2025 Recap: A New Standard for Cybersecurity Events](https://www.vulncheck.com/raw/blog/2025-threatcon1-recap.md): VulnCheck's inaugural THREATCON1 event brought together hundreds of cybersecurity professionals for a groundbreaking conference focused on emerging threats and innovative solutions. - [Introducing the 2026 VulnCheck Exploit Intelligence Report](https://www.vulncheck.com/raw/blog/2026-vulncheck-exploit-intelligence-report.md): In-depth analysis of 2025 CVEs and exploit trends from VulnCheck’s research team. The 2026 Exploit Intelligence Report includes an evaluation of the public exploit ecosystem, ransomware and state-sponsored threat actor deep dives, and a data-driven list of 2025’s routinely targeted vulnerabilities. - [5 Ways to Enhance Your Security Product Offering with VulnCheck](https://www.vulncheck.com/raw/blog/5-ways-to-enhance-your-security-product.md): Discover 5 ways VulnCheck enhances your security product offering with real-time intelligence, detection capabilities, and expanded vulnerability visibility. - [Active C2 Servers](https://www.vulncheck.com/raw/blog/active-c2-servers.md): Exploit Intel 101 - Active C2 Servers - [The First CVE Wave: Signs That AI-Assisted Vulnerability Discovery Is Reshaping Disclosure Volumes](https://www.vulncheck.com/raw/blog/ai-assisted-vulnerability-discovery.md): Public CVE disclosure volumes are surging across major software suppliers and open source projects, and the evidence increasingly points to AI-assisted vulnerability discovery as the driving force. - [Aimy Captcha-Less Form Guard: The Anti-Bot Plugin That Hands Bots the Keys](https://www.vulncheck.com/raw/blog/aimy-captcha-less-form-guard-object-injection.md): VulnCheck's Initial Access Intelligence team details an unauthenticated PHP object injection in the Aimy Captcha-Less Form Guard plugin for Joomla, where a repeating-key XOR published alongside its own ciphertext turns every protected form into an unserialize() sink and, on Joomla 3.9 through 5.2.1, into remote code execution. - [Tracking CVEs Attributed to Anthropic Researchers and Project Glasswing](https://www.vulncheck.com/raw/blog/anthropic-glasswing-cves.md): A primary source breakdown of every CVE publicly credited to Anthropic researchers and Project Glasswing, based on a full search of the CVE record database. - [Observations on Anthropic’s Vulnerability Disclosure Ledger](https://www.vulncheck.com/raw/blog/anthropic-ledger.md): Public CVE disclosure volumes are surging across major software suppliers and open source projects, and the evidence increasingly points to AI-assisted vulnerability discovery as the driving force. - [Attacker Infrastructure](https://www.vulncheck.com/raw/blog/attacker-infrastructure.md): Exploit Intel 101 - Attacker Infrastructure - [Helping Enterprises & Governments Adopt Stakeholder Specific Vulnerability Categorization (SSVC)](https://www.vulncheck.com/raw/blog/automating-ssvc.md): VulnCheck now provides automated SSVC decisions for federal and enterprise agencies. - [BigAnt Small Chain - CVE-2025-0364 Exploitation](https://www.vulncheck.com/raw/blog/bigant-cve-2025-0364.md): VulnCheck identifies an unauthenticated remote code execution in the BigAnt chat server - [Exposing CVEs from Black Bastas' Chats](https://www.vulncheck.com/raw/blog/black-basta-chats.md): Late last week, chat logs from Black Basta became available, offering rare insight into the operations of one of the most infamous ransomware groups. This research focuses on the vulnerabilities and CVEs mentioned in these logs, with the goal of providing defenders with actionable intelligence on the tactics of Black Basta. - [Dispatch from the Desert: VulnCheck at BlackHat, Security Wasteland, and DEFCON](https://www.vulncheck.com/raw/blog/blackhat-2025-review.md): Recapping our 2025 BlackHat and Defcon experience. - [Helping Federal Agencies Meet CISA’s Accelerated Remediation Timelines outlined in CISA BOD 26-04](https://www.vulncheck.com/raw/blog/cisa-bod-26-04.md): VulnCheck provides automated SSVC decisions for federal and enterprise agencies to help address CISA BOD 26-04. - [Exploring CISA’s 2023 Top Routinely Exploited Vulnerabilities](https://www.vulncheck.com/raw/blog/cisa-top-exploited-2024.md): In September, VulnCheck identified evidence of 78 CVEs that were publicly disclosed for the first time as exploited in the wild. - [CVE-2026-20079 - Cisco FMC Authentication Bypass RCE Analysis](https://www.vulncheck.com/raw/blog/cisco-fmc-auth-bypass-cve-2026-20079.md): VulnCheck's Initial Access Intelligence team analysis of CVE-2026-20079, an authentication bypass and remote code execution vulnerability in Cisco Secure Firewall Management Center. - [Widespread Cisco IOS XE Implants in the Wild](https://www.vulncheck.com/raw/blog/cisco-implants.md): VulnCheck scanned the internet for implanted Cisco IOS XE systems and found thousands of results. - [Herding Cats: Recent Cisco SD-WAN Manager Vulnerabilities](https://www.vulncheck.com/raw/blog/cisco-sd-wan-manager-vulns.md): VulnCheck’s Initial Access Intelligence team has been tracking and analyzing half a dozen recent vulnerabilities in Cisco Catalyst SD-WAN Manager, several of which have begun to see in-the-wild exploitation. Industry focus has been on CVE-2026-20127, but several other vulnerabilities also pose significant risk. - [Common Vulnerabilities and Exposures](https://www.vulncheck.com/raw/blog/common-vulnerabilities-and-exposures.md): Exploit Intel 101 - Common Vulnerabilities and Exposures (CVE) - [Common Vulnerability Scoring System (CVSS)](https://www.vulncheck.com/raw/blog/common-vulnerability-scoring-system.md): Exploit Intel 101 - Common Vulnerability Scoring System (CVSS) - [A Peek Into the Known Exploited Vulnerabilities of 2024](https://www.vulncheck.com/raw/blog/comparing-kevs-jupyter.md): VulnCheck now provides an automated approach to providing broader visibility into differences between VulnCheck KEV and CISA KEV through a Jupyter Notebook publicly available on GitHub. - [Does Confluence Dream of Shells?](https://www.vulncheck.com/raw/blog/confluence-dreams-of-shells.md): Examining memory resident payloads landed with CVE-2023-22527. - [Copy Fail and Its Descendants: A Real Human's Guide to Kernel Page-Cache LPEs](https://www.vulncheck.com/raw/blog/copy-fails-descendants-recent-linux-lpes.md): Recent disclosures around two recent Linux LPEs Copy Fail and Dirty Frag discovered with the assistance of AI have exposed a broader class of Linux kernel local privilege escalation vulnerabilities involving page-cache overwrite primitives. This analysis separates the technical reality from the noisy wave of AI-generated disclosures and recycled proofs of concept - [9 Year-Old PHP Vulnerability Keeps Swinging As One of the Most Targeted Vulnerabilities](https://www.vulncheck.com/raw/blog/cve-2017-9841.md): CVE-2017-9841 is still a primary exploit path for several botnets. What is old is still new in the eyes of cybercrime. - [A Different Payload for CVE-2022-47966](https://www.vulncheck.com/raw/blog/cve-2022-47966-payload.md): Exploring a memory resident payload for CVE-2022-47966. - [Analysis of Pre-Auth RCE in Sophos Web Appliance (CVE-2023-1671) VulnCheck](https://www.vulncheck.com/raw/blog/cve-2023-1671-analysis.md): CVE-2023-1671 is a pre-authenticated command injection in Sophos Web Appliance. In this blog post, VulnCheck researchers analyze the vulnerability and develop a proof of concept (PoC) for it. - [Executing from Memory Using ActiveMQ CVE-2023-46604](https://www.vulncheck.com/raw/blog/cve-2023-44604-activemq-in-memory.md): VulnCheck finds a new way to exploit ActiveMQ CVE-2023-46604 that allows the attacker to hide in memory and avoid process-based detections. - [CVE-2025-10035: Critical Vulnerability in Fortra GoAnywhere MFT](https://www.vulncheck.com/raw/blog/cve-2025-10035-fortra-go-anywhere-mft.md): A new critical vulnerability was disclosed in Fortra's GoAnywhere managed file transfer product, which has been targeted in the past by ransomware and extortion groups - [Critical vulnerability in React and Next.js (CVE-2025-55182)](https://www.vulncheck.com/raw/blog/cve-2025-55182-react-nextjs.md): On December 3, 2025, React developers disclosed CVE-2025-55182 (React2Shell), an unauthenticated remote code execution vulnerability with a CVSS score of 10 that affects React Server Components and Next.js. This blog post provides an overview of the vulnerability, RCE path, research analysis, and recommended actions. - [Expanding Access to CVE Data - CVE Program’s CVE List added to VulnCheck Community](https://www.vulncheck.com/raw/blog/cve-community.md): Given the security community's ongoing concerns about the reliability and performance of NIST's National Vulnerability Database, we recognized a growing need to address these challenges with alternative sources. - [CVE Fragility Is Real, But Totally Fixable.](https://www.vulncheck.com/raw/blog/cve-fragility.md): Forrester’s recent blog by Eric Nost, Mitregeddon Averted, But Fragility in CVE Processes Remain, shines a much-needed spotlight on the systemic challenges facing the CVE and NVD ecosystem from the industry analyst perspective. - [Who to Trust? National Vulnerability Database CVSS Accuracy Issues - VulnCheck](https://www.vulncheck.com/raw/blog/cvss-accuracy-issues.md): The National Vulnerability Database contains thousands of CVSS vectors. How accurate are those vectors and does accuracy matter? - [Critical CVEs, CVSS v4, and the Adoption Gap No One Talks About](https://www.vulncheck.com/raw/blog/cvss-severity.md): A common topic that’s been brought to my attention on several occasions is the perceived increase in vulnerabilities deemed “Critical” by their CVSS severity. According to FIRST, CVSS severity ratings are intended to help organizations assess and prioritize vulnerability management efforts. With this in mind, I set out to explore CVSS severity trends over time, which ultimately led me to examine the impact and adoption of CVSS v4. - [Are the Top 25 CWEs Truly the Most Dangerous Software Weaknesses in 2024?](https://www.vulncheck.com/raw/blog/cwe-top-25-2024.md): In November, Mitre released the 2024 CWE Top 25 Most Dangerous Software Weaknesses list. Today, VulnCheck issued a report re-evaluating the rankings with a threat-centric approach. - [What 28 Days of Faster Vulnerability Intelligence Is Worth](https://www.vulncheck.com/raw/blog/economic-value-lead-time.md): Using IBM's 2025 Cost of a Data Breach data, VulnCheck's 28-day speed advantage translates to $518,000 in risk avoided per incident. - [A Comparison of Exploit-DB and 0day.today](https://www.vulncheck.com/raw/blog/edb-0day-compare.md): Exploit-DB and 0day.today are two of the largest public exploit databases. In this blog, we compare the databases to determine which one is the most relevant today. - [Finding the Routers Energetic Bear Is Looking For](https://www.vulncheck.com/raw/blog/energetic-target-intel.md): How VulnCheck Target Intelligence makes NSA router-hygiene guidance actionable - [Does ENISA EUVD live up to all the hype?](https://www.vulncheck.com/raw/blog/enisa-euvd.md): This research aims to share experiences and observations to help others better understand how ENISA EUVD compares with existing vulnerability sources and whether it can serve as a reliable alternative for these established services. - [VulnCheck’s Commitment to Expanding Access to Vulnerability Enrichment](https://www.vulncheck.com/raw/blog/expanding-vulnerability-enrichment.md): In response to NIST NVD's announcement that it will significantly limit CVE enrichment starting April 15, 2026, VulnCheck reaffirms its commitment to filling the data gap through its free NVD++ community service and plans to expand coverage with CVSS scores over the next month - [A Follow-up to the Exploit-DB and 0day.today Comparison](https://www.vulncheck.com/raw/blog/exploit-database-followup.md): Following reader suggestions, we take a deeper look at the types of vulnerabilities in the Exploit-DB and 0day.today exploit databases. We also examine exploit attack vectors and find out how many of the exploits have been used in the wild. - [Exploit Intelligence](https://www.vulncheck.com/raw/blog/exploit-intelligence.md): Exploit Intel 101 - Exploit Intelligence and the Role of Threat Actor Intelligence in Cybersecurity Products - [2025 Q1 Trends in Vulnerability Exploitation](https://www.vulncheck.com/raw/blog/exploitation-trends-q1-2025.md): In Q1 2025, VulnCheck identified evidence of 159 CVEs publicly disclosed for the first time as exploited in the wild. - [Exploring ABB Vulnerabilities and Their Impact on Industrial Control Systems](https://www.vulncheck.com/raw/blog/exploring-abb-ics-vulns.md): We explore two key vulnerabilities in ABB's building automation and energy management software, ABB Cylon Aspect. - [Fake Security Researcher GitHub Repositories Deliver Malicious Implant Blog - VulnCheck](https://www.vulncheck.com/raw/blog/fake-repos-deliver-malicious-implant.md): VulnCheck discovers a network of fake security researcher accounts promoting hidden malware. - [Exploring Targeted Technologies and Countries of the Flax Typhoon Botnet](https://www.vulncheck.com/raw/blog/flax-typhoon-botnet.md): Last week, Five Eyes agencies issued a Joint Cybersecurity Advisory titled, “People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations” which we explore in this blog post. - [Following the Trail of Flax Typhoon to Uncover Newly Discovered Vulnerabilities in Linear Emerge Access Control Devices](https://www.vulncheck.com/raw/blog/flax-typhoon-linear-merge.md): A newly disclosed vulnerability, CVE-2024-9441, affects the Linear Emerge E3 series. The vulnerability has not yet been patched by the vendor, and exploits are already circulating, raising concerns of imminent exploitation. - [FortiCloud SSO Login Bypass Vulnerabilities Exploited in the Wild](https://www.vulncheck.com/raw/blog/forticloud-sso-login-bypass.md): Fortinet disclosed two critical vulnerabilities on December 9 that arise from improper cryptographic signature verification and enable remote attackers to bypass SSO login on vulnerable devices. The vulnerabilities are being exploited in the wild. - [Fortinet FortiWeb Exploitation Hits Silently Patched Vulnerability](https://www.vulncheck.com/raw/blog/fortinet-forti-web-exploitation-hits-silently-patched-vulnerability.md): A silently patched vulnerability (CVE-2025-64446) in Fortinet FortiWeb is being exploited in the wild to add administrative users and compromise target devices - [CVE-2026-28496 - FOSSBilling Auth Bypass and Twig SSTI to Unauthenticated RCE](https://www.vulncheck.com/raw/blog/fossbilling-auth-bypass-ssti-rce.md): VulnCheck's Initial Access Intelligence team analyzes a chained auth bypass and Twig SSTI in FOSSBilling that yields pre-authentication remote code execution against default installs. - [Four-Faith Industrial Router CVE-2024-12856 Exploited in the Wild](https://www.vulncheck.com/raw/blog/four-faith-cve-2024-12856.md): VulnCheck discovers that a new vulnerability affecting Four-Faith industrial routers has been exploited in the wild - [Frost Checks First: Selective Exploitation](https://www.vulncheck.com/raw/blog/frost-checks-first.md): New CVE-2025-2611 attacks led us to a selective exploitation tool named frost that only fires when targets match precise fingerprints. VulnCheck's Canary Intelligence, EVI, and IP Intel exposed the CVEs involved, the operator's infrastructure, and the internet-exposed systems they can reach. - [Command Injection in Jenkins via Git Parameter (CVE-2025-53652)](https://www.vulncheck.com/raw/blog/git-parameter-rce.md): CVE-2025-53652 was disclosed as a medium-severity vulnerability in the Jenkins Git Parameter plugin but it enables command injection and remote code execution when this popular plugin is installed. We break down the vulnerability and share detection guidance for defenders. - [GLPI Exploitation Timeline](https://www.vulncheck.com/raw/blog/glpi-exploitation.md): Taking a look at the timeline leading up to exploitation of CVE-2022-35914 and the current state of attacks in the wild. - [Introducing go-exploit - An Exploit Framework for Go](https://www.vulncheck.com/raw/blog/go-exploit.md): VulnCheck is excited to announce the open-source release of our in-house exploit framework, go-exploit. Designed with simplicity and portability in mind, go-exploit empowers exploit developers to create compact, self-contained, and consistent exploits. - [VulnCheck go-exploit External C2s](https://www.vulncheck.com/raw/blog/go-exploit-external-c2s.md): Adding support for external C2 channels and payloads in the go-exploit framework to enable flexible exploitation interaction and platform integration. - [Introducing a New Command-and-Control Feature in go-exploit: The ShellTunnel](https://www.vulncheck.com/raw/blog/go-exploit-shelltunnel.md): The latest feature to hit go-exploit is ShellTunnel. ShellTunnel captures reverse shell traffic and routes it through an intermediary attacker-controlled server before reaching the main command-and-control (C2) server. - [Hijackable Go Module Repositories](https://www.vulncheck.com/raw/blog/go-repojacking.md): VulnCheck scans the Go module ecosystem for module repositories affected by repojacking, and discover hundreds of thousands of affected module-versions. - [Assessing Potential Exploitation of Grafana's CVE-2021-43798 for Initial Access Access - Blog - VulnCheck](https://www.vulncheck.com/raw/blog/grafana-cve-2021-43798.md): Examining previous exploits for Grafana's CVE-2021-43798 and looking for a path to establish initial access. - [Helping Improve and Scale the CVE Ecosystem Through the Lens of Security Research](https://www.vulncheck.com/raw/blog/helping-scale-cve.md): VulnCheck is committed to accelerating visibility and improving data quality for defenders. We support the CVE Program and continue to expand our contributions by assigning CVE IDs to vulnerabilities observed by, discovered by, or reported to VulnCheck. - [Novel Use of "mount" Spotted in Hikvision Attacks](https://www.vulncheck.com/raw/blog/hikvision-mount-shell.md): VulnCheck researchers spotted a novel use of the "mount" command in real-world exploitation of Hikvision CVE-2021-36260. The attacker used NFS to drop and execute binaries, bypassing traditional download methods and evading common detection signatures. This technique has since been integrated into VulnCheck’s open-source go-exploit framework. - [Reimagining How We Think About Threat Actors](https://www.vulncheck.com/raw/blog/how-we-think-about-threat-actors.md): Taking a data-driven approach to visualizing the profile of threat actors can provide meaningful information without the time-consuming process of sifting through lengthy reports of information. - [ICTBroadcast Command Injection Actively Exploited (CVE-2025-2611)](https://www.vulncheck.com/raw/blog/ictbroadcast-kev.md): Attackers are abusing an unauthenticated command injection bug in ICTBroadcast (CVE-2025-2611) to execute remote commands and drop reverse shells. VulnCheck caught the exploitation, linked it to related research, and had detections available for customers well before the activity began. - [VulnCheck Initial Access Intelligence Update - August 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-august-2024.md): In August 2024, we developed new Initial Access Intelligence (IAI) artifacts for 20 CVEs, covering 17 different vendors and products. - [VulnCheck Initial Access Intelligence Update - July 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-july-2024.md): In July 2024, we developed new Initial Access Intelligence (IAI) artifacts for 14 CVEs, covering 13 different vendors and 10 different products. - [VulnCheck Initial Access Intelligence Update - June 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-june-2024.md): In June 2024, we developed new Initial Access Intelligence (IAI) artifacts for 15 CVEs, covering 13 different vendors and 13 different products. - [VulnCheck Initial Access Intelligence Update - May 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-may-2024.md): In May 2024, we developed new Initial Access Intelligence (IAI) artifacts for 20 CVEs, covering 16 different vendors and 18 different products. - [Detecting Exploitation w/ VulnCheck Initial Access Intelligence - November 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-november-2024.md): In November 2024, VulnCheck developed new Initial Access Intelligence (IAI) artifacts for 15 CVEs, covering 14 different vendors and products. - [Detecting Exploitation w/ VulnCheck Initial Access Intelligence - October 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-october-2024.md): In October 2024, VulnCheck developed new Initial Access Intelligence (IAI) artifacts for 21 CVEs, covering 16 different vendors and products. - [VulnCheck Initial Access Intelligence Update - September 2024](https://www.vulncheck.com/raw/blog/initial-access-intelligence-september-2024.md): In September 2024, we developed new Initial Access Intelligence (IAI) artifacts for 16 CVEs, covering 14 different vendors and products. - [Introducing VulnCheck Canary Intelligence](https://www.vulncheck.com/raw/blog/introducing-vulncheck-canary-intelligence.md): Introducing VulnCheck Canary Intelligence, a new offering that captures real-world exploitation as it happens. - [7777-Botnet Infection Vectors](https://www.vulncheck.com/raw/blog/ip-intel-7777-botnet.md): VulnCheck recently announced an IP Intelligence product that tracks attacker command & control (C2) infrastructure, as well as internet-facing potentially vulnerable systems. Using this data, we’ll explore the vulnerabilities that the 7777-Botnet is likely using to infect new hosts. - [Growth Starts with People](https://www.vulncheck.com/raw/blog/joining-vulncheck.md): VulnCheck is excited to announce four new leadership team additions! - [Joomla! CVE-2023-23752 to Code Execution](https://www.vulncheck.com/raw/blog/joomla-for-rce.md): CVE-2023-23752 is an information leak affecting Joomla! 4.0 - 4.7. How can an attacker use this vulnerability to achieve code execution? How many internet-facing systems are at risk? - [Fileless Remote Code Execution on Juniper Firewalls](https://www.vulncheck.com/raw/blog/juniper-cve-2023-36845.md): Learn about VulnCheck's development of an exploit for CVE-2023-36845, leading to stealthy code execution on Juniper firewalls, while also assessing the prevalence of unpatched systems in the wild. - [Expanding VulnCheck’s KEV: Auditing ShadowServer, New CVE Assignments, and Source Expansion](https://www.vulncheck.com/raw/blog/kev-expansion-2025.md): Expanding VulnCheck’s KEV: Auditing ShadowServer, New CVE Assignments, and Source Expansion - [Prioritizing CISA Known Exploited Vulnerabilities](https://www.vulncheck.com/raw/blog/kev-prioritization.md): The CISA Known Exploited Vulnerabilities (KEV) Catalog tracks vulnerabilities that have been exploited in the wild, and it currently has more than 800 entries. - [VulnCheck Exploited Vulnerabilities Report - May 2024](https://www.vulncheck.com/raw/blog/kev-report-may-2024.md): In May, VulnCheck identified evidence of 103 CVEs that were publicly disclosed for the first time as exploited in the wild, marking a 90.7% increase over April. - [VulnCheck Exploited Vulnerabilities Report - September 2024](https://www.vulncheck.com/raw/blog/kev-report-september-2024.md): In September, VulnCheck identified evidence of 78 CVEs that were publicly disclosed for the first time as exploited in the wild. - [VulnCheck Known Exploited Vulnerabilities Report - Summer 2024](https://www.vulncheck.com/raw/blog/kev-report-summer-2024.md): During June, July, and August, we captured exploitation evidence for 158 vulnerabilities, with initial evidence emerging within this period for the first time. The evidence was collected from over 35 different sources. - [The Linuxsys Cryptominer](https://www.vulncheck.com/raw/blog/linuxsys-cryptominer.md): VulnCheck observes exploitation of CVE-2021-41773 in the wild, and attributes the attack to the Linuxsys cryptominer. The team additionally discovers that the cryptominer has been part of a long-running campaign exploiting multiple vulnerabilities with a consistent attacker methodology since at least 2021. - [A Log4Shell Retrospective - Overblown and Exaggerated](https://www.vulncheck.com/raw/blog/log4shell-retro.md): Log4Shell was proclaimed one of the most critical vulnerabilities, but in this blog, VulnCheck challenges that perspective, revealing the limited number of vulnerable systems still present two years after the initial disclosure. - [Making Serialization Gadgets by Hand - .NET](https://www.vulncheck.com/raw/blog/making-dotnet-gadgets.md): Creating a language-native .NET source for deserialization gadgets - [Making Serialization Gadgets by Hand - Java](https://www.vulncheck.com/raw/blog/making-java-gadgets.md): Learn how to start creating Java serialization gadgets yourself - or use VulnCheck's go-exploit library for Golang-based exploits! - [Intelligence is the Most Important and Most Lucrative Asset in Cybersecurity](https://www.vulncheck.com/raw/blog/mastercard-recorded-future-acquisition.md): Recorded Future was acquired by Mastercard today for $2.65B, which is an encouraging macro indicator for the threat intelligence market and adjacent markets. - [From Canary Intelligence to C2 - Mapping an Attack Fleet with Target Intelligence](https://www.vulncheck.com/raw/blog/meowproject.md): Starting from 30 days of canary hits, we used VulnCheck's new Target Intelligence product to fingerprint an attacker's fleet and map an entire credential-harvesting operation — its hardened Kubernetes cluster, its C2 panels, and the playbook it runs against victims. - [Weaponized Vulnerabilities Deserve a Seat at The Prioritization Table](https://www.vulncheck.com/raw/blog/metasploit-kev.md): To help security practitioners prioritize vulnerabilities using exploit evidence, we've outlined why weaponized vulnerabilities should be prioritized by mapping Metasploit modules and VulnCheck Known Exploited Vulnerabilities. - [Metro4Shell: Exploitation of React Native’s Metro Server in the Wild](https://www.vulncheck.com/raw/blog/metro4shell_eitw.md): VulnCheck observed in-the-wild exploitation of CVE-2025-11953 targeting exposed React Native Metro servers shortly after public disclosure. Analysis of repeated attacks shows consistent, operational payload delivery rather than opportunistic scanning. This post examines how the vulnerability was exploited and why early exploitation visibility matters for defenders. - [Exploiting MikroTik RouterOS Hardware with CVE-2023-30799](https://www.vulncheck.com/raw/blog/mikrotik-foisted-revisited.md): VulnCheck develops an exploit that gets a root shell on MikroTik RouterOS. - [Monsta FTP: An SSRF Blocklist That Forgot IPv6 Exists](https://www.vulncheck.com/raw/blog/monsta-ftp-ssrf-ipv6-blocklist-bypass.md): VulnCheck's Initial Access Intelligence team details an unauthenticated SSRF in Monsta FTP 2.14.4, where an IPv4-only blocklist waves through the IPv4-mapped IPv6 form of the cloud metadata endpoint and bypasses both the front gate and the anti-rebinding recheck. - [Moobot Uses a Fake Vulnerability](https://www.vulncheck.com/raw/blog/moobot-uses-fake-vulnerability.md): An investigation into CVE-2022-28958 finds the vulnerability doesn't actually exist. - [The Mystery OAST Host Behind a Regionally Focused Exploit Operation](https://www.vulncheck.com/raw/blog/mystery-oast.md): VulnCheck Canary Intelligence uncovered a long-running attacker-owned OAST service operating from Google Cloud. The actor blended stock Nuclei templates with custom payloads while focusing their activity on canaries deployed in a single region. This unusual combination reveals a structured, sustained scanning operation rather than ordinary opportunistic spraying. - [n8n Should Have More Than One CISA KEV Entry](https://www.vulncheck.com/raw/blog/n8n-needs-more-kev.md): CISA recently added CVE-2025-68613, an authenticated n8n RCE, to its KEV catalog, but that framing misses how the vulnerability is actually exploited. In practice, it can be paired with CVE-2026-21858, an authentication bypass that is already being actively exploited in the wild. With over 14,000 exposed n8n instances, this attack path is both practical and widespread. The bypass enabling these chains likely warrants its own KEV entry. - [2026 State of Exploitation: Exploiting The Network Edge](https://www.vulncheck.com/raw/blog/network-edge-device-report-2026.md): What’s really being targeted at the network edge? VulnCheck’s 2026 research shows that a significant portion of exploited vulnerabilities affect end-of-life devices, with consumer networking equipment and botnets driving much of the activity. This report breaks down the trends shaping real-world exploitation. - [New Citrix NetScaler Zero-Day Vulnerability Exploited in the Wild](https://www.vulncheck.com/raw/blog/new-citrix-netscaler-zero-day-vulnerability-exploited-in-the-wild.md): Three new Citrix NetScaler vulnerabilities were disclosed on August 26, including CVE-2025-7775, a fresh zero-day flaw being used in the wild - [Finding Something New About CVE-2022-1388](https://www.vulncheck.com/raw/blog/new-cve-2022-1388.md): In search of an interesting new detail about CVE-2022-1388, VulnCheck researchers pore over open source intelligence. The researchers detail exploit variants, find signature bypasses, and publish a novel exploit variant. - [New Year, New UI](https://www.vulncheck.com/raw/blog/new-year-new-ui.md): VulnCheck's new update enhances our CVE pages bringing actionable threat intelligence to the forefront. - [NIST’s New Deferred CVE Status: What It Means for Defenders](https://www.vulncheck.com/raw/blog/nist-nvd-deferred.md): VulnCheck treats every CVE as a forever-day, because we know exploitation doesn’t adhere to timelines or maintenance cycles. - [VulnCheck Research Highlights: November 2025](https://www.vulncheck.com/raw/blog/november-2025-research-highlights.md): Insights on emerging threats, VulnCheck-observed exploitation in the wild, and published CVEs from VulnCheck’s research teams - [The Real Danger Lurking in the NVD Backlog](https://www.vulncheck.com/raw/blog/nvd-backlog-exploitation.md): A look into the real dangers of exploitation lurking in the NVD Backlog - [Danger is Still Lurking in the NVD Backlog](https://www.vulncheck.com/raw/blog/nvd-backlog-exploitation-lurking.md): A look into the real dangers of exploitation still lurking in the NVD Backlog - [Enhancing Access to NIST NVD data... Introducing CPE Enrichment in VulnCheck NVD++](https://www.vulncheck.com/raw/blog/nvd-cpe.md): To help close the enrichment gap for CVEs in the “Awaiting Analysis’ status, VulnCheck prioritized the generation of CPEs from reliable sources and has started adding them into the JSON available through our NVD++ service as “vcConfigurations”. - [VulnCheck's CPE Coverage Update (3-weeks after launch)](https://www.vulncheck.com/raw/blog/nvd-cpe-update.md): To help close the enrichment gap for CVEs in the “Awaiting Analysis" status, VulnCheck generates CPEs from reliable sources and has made them available through our NVD++ service as “vcConfigurations”. - [Enhancing Access to NIST NVD data... Introducing VulnCheck NVD++](https://www.vulncheck.com/raw/blog/nvd-plus-plus.md): Given the security community's ongoing concerns about the reliability, rate limits, and performance of NIST's National Vulnerability Database (NVD) 2.0 API, we recognized a growing need to address these challenges. - [Why We Are Open-Sourcing NVD 1.0](https://www.vulncheck.com/raw/blog/nvd-why.md): Managing vulnerabilities at scale is something the entire cybersecurity ecosystem has struggled with for a long time. - [NVIDIA GEN3C: Unauthenticated RCE via Pickle Deserialization in the Inference API](https://www.vulncheck.com/raw/blog/nvidia-gen3c-unauth-pickle-rce.md): VulnCheck's Initial Access Intelligence team details an unauthenticated remote code execution in NVIDIA's GEN3C, where two FastAPI inference endpoints deserialize raw HTTP request bodies with pickle.loads() with no authentication. - [VulnCheck Research Highlights: October 2025](https://www.vulncheck.com/raw/blog/october-2025-research-highlights.md): Insights on recent emerging threats, initial access vulnerabilities, and published CVEs from VulnCheck’s research teams - [Weaponizing Apache OFBiz CVE-2023-51467](https://www.vulncheck.com/raw/blog/ofbiz-cve-2023-51467.md): VulnCheck bypasses the Apache OFBiz Groovy sandbox to land a memory resident reverse shell. - [Exploring VulnCheck Intelligence in OpenCTI](https://www.vulncheck.com/raw/blog/opencti-integration.md): VulnCheck integrates with OpenCTI - an open-source Threat Intelligence Platform by Filigran - [Exploitation of Openfire CVE-2023-32315](https://www.vulncheck.com/raw/blog/openfire-cve-2023-32315.md): CVE-2023-32315 was first exploited in the wild in June 2023. However, VulnCheck has discovered an new approach to exploiting this vulnerability, streamlining the attack process and adeptly bypassing the generation of log entries. In addition, VulnCheck analyzes the remaining indicators of compromise and shares network detections. - [Oracle E-Business Suite CVE-2025-61882 Exploited in Extortion Attacks](https://www.vulncheck.com/raw/blog/oracle-e-business-suite-cve-2025-61882-exploited-in-extortion-attacks.md): A new Oracle E-Business Suite zero-day vulnerability is being linked to a Cl0p extortion campaign that exfiltrated EBS data from Oracle customer environments - [Outpacing NIST NVD with VulnCheck NVD++](https://www.vulncheck.com/raw/blog/outpacing-nvd-cpe.md): VulnCheck NVD++ provides CPE for 76.95% of CVEs published in 2024 while NIST NVD only provides CPE for 41.35% of CVEs - [PaperCut Exploitation - A Different Path to Code Execution](https://www.vulncheck.com/raw/blog/papercut-rce.md): Public exploits and detections for CVE-2023-27350 focus on code execution using the PaperCut print scripting interface. In this blog, VulnCheck shares a new code execution vector and demonstrates how existing detections aren't robust enough to flag the new activity. - [ProjectSend CVE-2024-11680 Exploited in the Wild](https://www.vulncheck.com/raw/blog/projectsend-exploited-itw.md): VulnCheck discovers evidence that ProjectSend has been exploited in the wild and assigns CVE-2024-11680 - [Bring VulnCheck Intelligence to Your Python and Go Apps with Our New SDKs](https://www.vulncheck.com/raw/blog/python-go-sdk.md): VulnCheck delivers intelligence to Your Python and Go Applications with our new SDKs - [Accelerating Our Footprint and Innovation: Why VulnCheck Posted a Record-Setting Q3](https://www.vulncheck.com/raw/blog/q3-2025-momentum.md): This quarter was a defining one for VulnCheck — not just in numbers, but in what those numbers represent and how critical VulnCheck is in both enriching cyber products in the market and protecting our global economy and national security. - [What's Next: React2Shell Beyond Next.js](https://www.vulncheck.com/raw/blog/react2shell-beyond-nextjs.md): VulnCheck's Initial Access Intelligence team analyzes React2Shell CVE-2025-55182 exploitability in frameworks that utilize the vulnerable components outside of Next.js alone, with emphasis on exploitation steps and potential fingerprinting paths. - [React2Shell and What Our Canaries See](https://www.vulncheck.com/raw/blog/react2shell-canaries.md): We're already seeing active React2Shell exploitation, and defenders need to know what it looks like. VulnCheck Canary Intelligence has captured real attacker probes and payloads, offering early insight into how operators are weaponizing the vulnerability. The post includes detailed examples and a list of observed IPs to support immediate defensive action. - [React2Shell Exploits on GitHub](https://www.vulncheck.com/raw/blog/react2shell-github.md): VulnCheck reviewed the full wave of React2Shell exploits published on GitHub, discarding about half as broken or misleading and surfacing several genuinely interesting techniques from the rest. We curated the usable set, highlighted the notable variants, and made the entire approved dataset freely available in VulnCheck's Exploit Database (XDB). - [Reacting to Shells: React2Shell Variants & the CVE-2025-55182 Exploit Ecosystem](https://www.vulncheck.com/raw/blog/reacting-to-shells-react2shell-variants-ecosystem.md): An analysis of React2Shell variants, public exploits, paths to RCE, and implications for detection and response - [Looking for CVE-2023-43261 in the Real World](https://www.vulncheck.com/raw/blog/real-world-cve-2023-43261.md): VulnCheck was excited to breach ICS networks when CVE-2023-43261 was first disclosed. However, there is more to this than the CVE description would lead you to believe. Follow VulnCheck’s journey from CVE description to exploitation in the wild - [Reducing Attack Surface Risk](https://www.vulncheck.com/raw/blog/reducing-attack-surface-risk-oem-series.md): OEM Use Case Series: Reducing Attack Surface Risk - Know Who Your Adversaries Are and How Naming Conventions Matter in Vulnerability Management - [How to Report a Security Vulnerability to VulnCheck](https://www.vulncheck.com/raw/blog/report-a-vulnerability.md): VulnCheck offers a free vulnerability reporting service designed to reduce the burden of disclosure and support researchers. - [The Return of the Kinsing](https://www.vulncheck.com/raw/blog/return-of-the-kinsing.md): Canary Intelligence linked exploitation of CVE-2023-46604, CVE-2023-38646, and CVE-2025-55182 to the same Kinsing infrastructure, including a shared staging host and attacker IP first seen in the canary network on March 12, 2026. The research shows how an older malware family is still adapting by adding new exploit paths while continuing to rely on established infrastructure. - [Exposing RocketMQ CVE-2023-33246 Payloads](https://www.vulncheck.com/raw/blog/rocketmq-exploit-payloads.md): VulnCheck demonstrates the use of the RocketMQ remoting protocol to retrieve the broker configuration file, and shares attacker payloads used in the wild for exploitation with CVE-2023-33246. - [Quantifying 2026 Routinely Targeted Vulnerabilities (So Far)](https://www.vulncheck.com/raw/blog/routinely-targeted-vulnerabilities-may-2026.md): VulnCheck identified 25 CVEs disclosed in 2026 that have been routinely targeted by adversaries and researchers so far this year, drawing from a global body of exploit code and exploitation data. - [ScriptCase - Hunt It, Exploit It, Defend It](https://www.vulncheck.com/raw/blog/scriptcase-rce.md): A month after disclosure, hundreds of ScriptCase servers remain exposed and actively targeted. This post walks through finding vulnerable instances, exploiting them with just a few curl commands, and the key detection points defenders can use to stop attacks. - [SiftRanking Canary Intelligence](https://www.vulncheck.com/raw/blog/siftrank_canaries.md): Canary Intelligence captures thousands of real-world exploitation attempts every day, but scale alone does not create insight. This post walks through how clustering, structured feature extraction, and SiftRank transform raw exploitation telemetry into AI-driven prioritization. The result is a repeatable workflow that surfaces high-leverage attacker activity in minutes. - [Street Smarts: SmarterMail ConnectToHub Unauthenticated RCE (CVE-2026-24423)](https://www.vulncheck.com/raw/blog/smartermail-connecttohub-rce-cve-2026-24423.md): Exploring an unauthenticated remote code execution in the SmarterTools SmarterMail server via the ConnectToHub mounting functionality. - [Actively Exploited Industrial Control Systems Hardware - SolarView Series - Blog - VulnCheck](https://www.vulncheck.com/raw/blog/solarview-exploitation.md): VulnCheck analyzes four CVEs that impact SolarView, a solar power monitoring system. We discover the number of internet-facing systems and the likelihood of exploitation in the wild. - [Assessing Potential Exploitation of Sophos Firewall and CVE-2022-3236 Blog - VulnCheck](https://www.vulncheck.com/raw/blog/sophos-cve-2022-3236.md): Sophos Firewalls were exploited using CVE-2022-3236 in September, 2022. Few details have been published about this vulnerability. In this blog, we look at log entries the exploit creates and determine how many vulnerable internet-facing firewalls still exist. - [State of Exploitation - A Peek into 1H-2024 Vulnerability Exploitation](https://www.vulncheck.com/raw/blog/state-of-exploitation-1h-2024.md): A Look into the Last 6-months of Vulnerability Exploitation… January-June 2024 - [State of Exploitation - A look Into The 1H-2025 Vulnerability Exploitation & Threat Activity](https://www.vulncheck.com/raw/blog/state-of-exploitation-1h-2025.md): A Look into the Last 6-months of Vulnerability Exploitation… January-June 2025 - [VulnCheck State of Exploitation 1H-2026](https://www.vulncheck.com/raw/blog/state-of-exploitation-1h-2026.md): Key Trends and Findings from Known Exploited Vulnerabilities, AI discovered vulnerabilities, and AI targeted technologies from the first half of 2026 - [VulnCheck State of Exploitation 2026](https://www.vulncheck.com/raw/blog/state-of-exploitation-2026.md): Key Trends and Findings from 2025’s Known Exploited Vulnerabilities - [State of Exploitation - A Peek into the Last Decade of Vulnerability Exploitation](https://www.vulncheck.com/raw/blog/state-of-exploitation-a-decade.md): A Look into the Last Decade of Vulnerability Exploitation… 2014 - 2023 - [Still Up. Still Evil.](https://www.vulncheck.com/raw/blog/stillup-stillevil.md): VulnCheck tracked thousands of attacker systems over a 90-day window to see how long malicious infrastructure really lasts. The results show that exposure doesn’t mean disruption, as many phishing kits, proxies, and C2 tools stay online for weeks or even months. - [Exploring the Anatomy of an Exploited CVE with VulnCheck KEV](https://www.vulncheck.com/raw/blog/the-anatomy-of-an-exploited-cve.md): Using VulnCheck KEV, we explore the anatomy of an exploited CVE. We map publicly available exploitation evidence to Atlassian Confluence CVE-2023-22527 to create a visual timeline of exploitation. - [There Are Too Many Damn Honeypots](https://www.vulncheck.com/raw/blog/too-many-honeypots.md): VulnCheck faces a horde of honeypots while assessing the potential impact of Atlassian Confluence's CVE-2023-22527. This blog delves into Shodan queries to filter out honeypots and uncover the actual on-premise Confluence install base. - [Top 10 VulnCheck Research Blogs of 2023](https://www.vulncheck.com/raw/blog/top-10-2023.md): In our last blog of 2023, we highlight the top 10 VulnCheck research blogs that explored new exploit techniques or exploitation in the wild. - [Top 5 Reasons to Use VulnCheck Community](https://www.vulncheck.com/raw/blog/top-5-reasons-to-use-vulncheck-community.md): VulnCheck Community delivers timely and valuable vulnerability intelligence at machine speeds - [Tales from the Exploit Mines: Gladinet Triofox CVE-2025-12480 RCE](https://www.vulncheck.com/raw/blog/triofox-exploit-cve-2025-12480.md): Triofox CVE-2025-12480 exploitation from beginning to end, all sharp edges included. - [Understanding APTs](https://www.vulncheck.com/raw/blog/understanding-apts.md): Exploit Intel 101 - Understanding APTs - [Understanding Command & Control (C2) Infrastructure](https://www.vulncheck.com/raw/blog/understanding-command-control-infrastructure.md): Exploit Intel 101 - Understanding Command & Control (C2) Infrastructure - [Understanding Exploit Availability](https://www.vulncheck.com/raw/blog/understanding-exploit-availability.md): Exploit Intel 101 - Understanding Exploit Availability - [Understanding Exploit Maturity](https://www.vulncheck.com/raw/blog/understanding-exploit-maturity.md): Exploit Intel 101 - Understanding Exploit Maturity - [Understanding Exploit Proof-of-Concept](https://www.vulncheck.com/raw/blog/understanding-exploit-proof-of-concept.md): Exploit Intel 101 - Understanding Exploit Proof-of-Concept - [Understanding Exploits](https://www.vulncheck.com/raw/blog/understanding-exploits.md): Exploit Intel 101 - Understanding Exploits - [Understanding Initial Access Exploits](https://www.vulncheck.com/raw/blog/understanding-initial-access-exploits.md): Exploit Intel 101 - Understanding Initial Access Exploits - [Understanding Software Dependency Graphs](https://www.vulncheck.com/raw/blog/understanding-software-dependency-graphs.md): Exploit Intel 101 - Understanding Software Dependency Graphs - [Understanding Software Supply Chain Security](https://www.vulncheck.com/raw/blog/understanding-software-supply-chain-security.md): Exploit Intel 101 - Understanding Software Supply Chain Security - [Verizon's 2024 DBIR Report - Mapping Mitre Att&CK tactics and techniques to Incident Classification Patterns](https://www.vulncheck.com/raw/blog/verizon-dbir-2024-mitre.md): Verizon's 2024 annual DBIR report incident classification patterns mapped to the Mitre Att&CK tactics and techniques. - [Bring VulnCheck Anywhere w/ VulnCheck CLI](https://www.vulncheck.com/raw/blog/vulncheck-cli-anywhere.md): VulnCheck delivers intelligence to the command line with VulnCheck’s new open source tool, VulnCheck CLI. - [Learn How to Operationalize Exploit Intelligence in Splunk with VulnCheck’s New Splunkbase App](https://www.vulncheck.com/raw/blog/vulncheck-exploit-intelligence-app-in-splunkbase.md): Bring real-world exploit and vulnerability intelligence directly into Splunk, making it easier for security teams to enrich CVE data, prioritize remediation and respond faster to emerging threats. - [VulnCheck & Filigran: Delivering Actionable Security Intelligence for the Enterprise](https://www.vulncheck.com/raw/blog/vulncheck-filigran-parternship.md): Filigran and VulnCheck are proud to announce a strategic partnership that transforms enterprise threat intelligence capabilities through seamless integration. This collaboration brings together Filigran's market-leading OpenCTI platform with VulnCheck's comprehensive exploit intelligence solutions, creating a powerful joint offering that delivers immediate business value to security teams to enable scalable, automated response actioning. - [VulnCheck go-exploit Goes Scanless](https://www.vulncheck.com/raw/blog/vulncheck-goes-scanless.md): Demonstrating the new scanless feature in the go-exploit exploit framework. - [VulnCheck Initial Access Intelligence - 2024 Year in Review](https://www.vulncheck.com/raw/blog/vulncheck-iai-2024.md): In 2024, VulnCheck's Initial Access Intelligence (IAI) team delivered custom exploits and detection artifacts for 169 CVEs. Among these, 99 CVEs (58.6%) were actively exploited in the wild. - [Getting Ahead of Exploitation with Initial Access Intelligence](https://www.vulncheck.com/raw/blog/vulncheck-initial-access.md): IAI delivers production-ready, validated exploits and detections for vulnerabilities most likely to be exploited for initial access and most likely to be added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. - [VulnCheck Insights: CVE Context at the Hover of Your Cursor](https://www.vulncheck.com/raw/blog/vulncheck-insights-chrome-extension.md): Instead of bouncing between tabs, you now get instant, current context the moment a CVE appears on your screen. - [Timely Threat Intelligence for Defenders with VulnCheck KEV Alerts](https://www.vulncheck.com/raw/blog/vulncheck-kev-alerts.md): We're excited to announce the expansion of VulnCheck Community to include VulnCheck KEV Alerts via Email and Slack - [VulnCheck and Sevco - Real-time Threat Visibility and the Most Comprehensive Asset Intelligence](https://www.vulncheck.com/raw/blog/vulncheck-sevco.md): Sevco is a market leader. Through this collaboration, Sevco has integrated VulnCheck data to roll out a significant set of enhancements to its existing vulnerability prioritization and exposure management capabilities. - [VulnCheck and ThreatConnect - Real-time Threat Visibility and the Most Comprehensive Asset Intelligence](https://www.vulncheck.com/raw/blog/vulncheck-threatconnect-partnership.md): VulnCheck is partnering with ThreatConnect to deliver a new level of vulnerability prioritization to joint customers with VulnCheck exploit and vulnerability data integrated into ThreatConnect’s industry-leading TI Ops Platform. - [VulnCheck Integrates with ThreatQuotient: Operationalize Exploit Intelligence in the ThreatQ Platform and is Now Generally Available on the ThreatQ Marketplace](https://www.vulncheck.com/raw/blog/vulncheck-threatquotient-partnership.md): This integration brings VulnCheck’s exploit-centric vulnerability intelligence directly into ThreatQ, enabling joint customers to supercharge threat operations, vulnerability prioritization, and incident response with real-world exploit data. - [Vulnerability Exchange Formats - CycloneDX, SPDX, VDR, and VEX](https://www.vulncheck.com/raw/blog/vulnerability-exchange-formats.md): Exploit Intel 101 - Vulnerability Exchange Formats (CycloneDX, SPDX, VDR, and VEX) - [Taking an Evidence-Based Approach to Vulnerability Prioritization](https://www.vulncheck.com/raw/blog/vulnerability-prioritization.md): To help security practitioners prioritize vulnerabilities using exploit evidence, we've outlined key considerations and strategies in this blog. Alongside exploit intelligence, it’s crucial to incorporate environmental and asset context using decision-based frameworks such as Stakeholder-Specific Vulnerability Categorization. - [Vulnerability Prioritization](https://www.vulncheck.com/raw/blog/vulnerability-prioritization-101.md): Exploit Intel 101 - Vulnerability Prioritization - [Website Launch](https://www.vulncheck.com/raw/blog/website-launch.md): We've been around, supporting our customers since 2021, but only recently launched our website. - [WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030](https://www.vulncheck.com/raw/blog/wp2shell.md): Two new WordPress core vulnerabilities were disclosed on July 17, prompting broad concern from the security community. CVE-2026-60137 and CVE-2026-63030 are able to be chained for remote code execution against out-of-the-box WordPress installations, with multiple paths to RCE possible. - [Xiongmai IoT Exploitation](https://www.vulncheck.com/raw/blog/xiongmai-iot-exploitation.md): An examination of vulnerabilities affecting Xiongmai IoT devices, including exploit development and an analysis of exploitation in the wild. - [XWiki CVE-2025-24893 Exploited in the Wild](https://www.vulncheck.com/raw/blog/xwiki-cve-2025-24893-eitw.md): VulnCheck Canaries captured live exploitation of XWiki CVE-2025-24893, a vulnerability absent from CISA KEV but actively abused in the wild. - [XWiki Under Increased Attack](https://www.vulncheck.com/raw/blog/xwiki-under-increased-attack.md): What began as one attacker exploiting CVE-2025-24893 has become a multi-actor scramble including botnets, miners, and custom tooling. Our early Canary detections show how quickly real-world exploitation now evolves. - [ENDLESSDOORS Is Phoning Home. Pick Up.](https://www.vulncheck.com/raw/blog/zbt-endlessdoors.md): Twenty router models sold on Amazon, AliExpress, and Alibaba ship with a remote-control implant enabled by default. It runs as root, it uses no encryption, and it authenticates nobody. Whoever answers the phone owns the device. - [re: Zyxel VPN Series Pre-auth Remote Command Execution](https://www.vulncheck.com/raw/blog/zyxel-cve-2023-33012.md): VulnCheck uncovers the truth behind the recently published Zyxel pre-auth remote code execution: limited to specific configurations, limitations on repeated exploitation, and no evidence of active exploitation. - [Zyxel HTTP Vulnerability](https://www.vulncheck.com/raw/blog/zyxel-http-vuln.md): As a follow-up to our previous Zyxel Telnet Vulnerabilities blog, VulnCheck examines CVE-2024-40890, a recently disclosed vulnerability in the HTTP interface of many end-of-life Zyxel CPE routers. - [Zyxel Telnet Vulnerabilities](https://www.vulncheck.com/raw/blog/zyxel-telnet-vulns.md): VulnCheck and partner GreyNoise discovered Zyxel-related vulnerabilities being targeted in the wild. In this blog, VulnCheck describes the vulnerabilities CVE-2024-40891 and CVE-2025-0890. ## Policy - [Cookie Policy](https://www.vulncheck.com/raw/policy/cookies.md): How VulnCheck uses cookies and similar technologies on our website - [Privacy Policy](https://www.vulncheck.com/raw/policy/privacy.md): VulnCheck, Inc. Privacy Policy - [Service Terms](https://www.vulncheck.com/raw/policy/service-terms.md): The terms and conditions that govern the use of VulnCheck's services. - [Terms and Conditions](https://www.vulncheck.com/raw/policy/terms.md): Terms and Conditions of use for VulnCheck.com - [Vulnerability Disclosure Policy](https://www.vulncheck.com/raw/policy/vuln-disclosure/en.md) - [سیاست افشای آسیب‌پذیری - VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/fa_ir.md) - [Politique de divulgation des vulnérabilités - VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/fr.md) - [취약점 공개 정책 - VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/ko.md) - [Beleid voor het Melden van Kwetsbaarheden - VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/nl.md) - [Политика раскрытия уязвимостей — VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/ru.md) - [漏洞披露政策 - VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/zh_cn.md) - [漏洞揭露政策 - VulnCheck](https://www.vulncheck.com/raw/policy/vuln-disclosure/zh_tw.md) ## Join - [CUSTOM Ready to get Started?](https://www.vulncheck.com/raw/internal/join/custom.md): CUSTOM Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter. - [Ready to get Started?](https://www.vulncheck.com/raw/internal/join/default.md): Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter. - [Ready to get Started?](https://www.vulncheck.com/raw/internal/join/events.md): VulnCheck, The Exploit Intelligence Company, powers the global intelligence infrastructure for vulnerability and exploitation response and is trusted by the security programs that protect hundreds of millions of systems worldwide. - [Ready to get Started?](https://www.vulncheck.com/raw/internal/join/isac.md): VulnCheck, The Exploit Intelligence Company, powers the global intelligence infrastructure for vulnerability and exploitation response and is trusted by the security programs that protect hundreds of millions of systems worldwide. - [A Faster, More Complete Source for NVD Data](https://www.vulncheck.com/raw/internal/join/nvd-plusplus.md): VulnCheck NVD++ publishes CVEs 14 days ahead of NIST NVD on average with global coverage and CPE mapping NIST doesn't provide. - [See Every Actively Exploited CVE, Free](https://www.vulncheck.com/raw/internal/join/vulncheck-kev.md): VulnCheck KEV tracks 3X more known exploited vulnerabilities than CISA KEV, and surfaces them 27 days earlier on average. - [Prioritize What's Actually Being Exploited](https://www.vulncheck.com/raw/internal/join/vulnerability-management.md): VulnCheck, The Exploit Intelligence Company, powers the global intelligence infrastructure for vulnerability and exploitation response and is trusted by the security programs that protect hundreds of millions of systems worldwide.