Skip to content
June 23, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button

LATEST NEWS

Tinyproxy request smuggling diagram showing CVE-2026-54388 vulnerabilities
  • Vulnerability Report

Tinyproxy Request Smuggling Flaws Expose Networks

Do Son June 23, 2026 0
libssh2 vulnerability CVE-2026-55200 enabling remote code execution via out-of-bounds write
  • Vulnerability Report

Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution

Do Son June 23, 2026 0
MariaDB server vulnerabilities diagram showing shell command execution risks
  • Vulnerability Report

MariaDB Server Vulnerabilities Allow CVSS 10 Attacks

Do Son June 23, 2026 0
Mitel MiCollab vulnerabilities MISA-2026-0005 command injection flaws rated CVSS 10.0
  • Vulnerability Report

Mitel Patches 12 Critical MiCollab Vulnerabilities Rated Up to CVSS 10.0

Do Son June 23, 2026 0
vendor-signed UEFI applications Secure Boot bypass via BYOVD attack and UEFI DBX revocation
  • Vulnerability Report

Vendor-Signed UEFI Applications Allow Secure Boot Bypass

Do Son June 23, 2026 0

Tech News

Apple AirPort Utility deprecated notice on legacy wireless routers AFP protocol macOS 27, SMB3 protocol, Apple Filing Protocol, file sharing protocol Apple WWDC 2026 announcements
  • Technology

Apple AirPort Utility Deprecated in iOS 27 & macOS 27

Do Son June 23, 2026 0
iOS 27 Developer Beta 2 new features including Write with Siri keyboard button and RCS inline replies
  • Technology

iOS 27 Developer Beta 2 Adds Write with Siri and RCS Replies

Do Son June 23, 2026 0
Codex v0.142.0 update addressing the SSD wear issue and SQLite logging optimizations
  • Technology

Resolving the Codex SSD Wear Issue

Do Son June 23, 2026 0
Microsoft Edge Google account login interface and synchronization settings Browser Choice Alliance letter Microsoft Edge cleartext credentials memory dump Microsoft Edge auto-startup Microsoft Edge Collections sunset, export Edge Collections CSV Edge IE Mode Zero-Day, Chakra Exploit Windows Search, Microsoft Edge AI video translation, Edge browser Microsoft Editor, Edge Edge Developer tools Windows 10 ESU, Microsoft Edge Microsoft Edge, FCP Optimization CVE-2023-36735 Edge, AI Search
  • Technology

Microsoft Edge Google Account Login Coming Soon

Do Son June 22, 2026 0

Vulnerability

FreeBSD privilege escalation CVE-2026-49413, Linuxulator vulnerability
  • Vulnerability

FreeBSD Privilege Escalation Flaw CVE-2026-49413 Hits the Linuxulator

Do Son June 15, 2026 0
CVE-2022-35951 Redis DarkReplica exploit CVE-2026-23631 public disclosure
  • Vulnerability

Redis DarkReplica Exploit: Full PoC Code and Technical Details Released

Do Son June 8, 2026 0
Mautic security vulnerabilities critical RCE flaws
  • Vulnerability

Critical RCE Flaws Fixed in Mautic Marketing Platform

Do Son June 4, 2026 0
Drupal SQL injection exploit wild exploit PoC
  • Vulnerability

Drupal SQL Injection Exploit: Critical Flaw Exploited in the Wild with Public PoC

Do Son June 3, 2026 0

Cyber Security

GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages GitBait phishing campaign abusing GitHub Pages and SheetBest API to steal Mexican banking credentials
  • Cybercriminals

GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages

June 23, 2026 0
Cloud DNS Takeover Powers Thai Gambling Campaign hacking
  • Cybercriminals

Cloud DNS Takeover Powers Thai Gambling Campaign

June 23, 2026 0
FBI Warns of Traffic Distribution Systems in Cyber Attacks Diagram showing how cyber criminals use traffic distribution systems to redirect users to malicious websites.
  • Cybercriminals

FBI Warns of Traffic Distribution Systems in Cyber Attacks

June 22, 2026 0
Google Uncovers UNC6508 Cyber Espionage Campaign Diagram showing UNC6508 cyber espionage attack flow and INFINITERED malware.
  • Cybercriminals

Google Uncovers UNC6508 Cyber Espionage Campaign

June 22, 2026 0

Malware Alert

macOS ClickFix AppleScript Stealer Hijacks Crypto Wallets macOS ClickFix AppleScript stealer diagram showing the Meow macOS stealer infection chain
  • Malware

macOS ClickFix AppleScript Stealer Hijacks Crypto Wallets

June 23, 2026 0
Dropping Elephant Malware: China-Themed Loader Campaign Analyzed Dropping Elephant malware China-themed loader and in-memory RAT diagram
  • Malware

Dropping Elephant Malware: China-Themed Loader Campaign Analyzed

June 23, 2026 0
AryStinger Malware Attacks Routers via CVE-2013-3307 AryStinger malware infection chain exploiting CVE-2013-3307
  • Malware

AryStinger Malware Attacks Routers via CVE-2013-3307

June 23, 2026 0
Malicious Steam Wallpapers Spread Malware to Gamers Malicious Steam wallpapers targeting the Wallpaper Engine app
  • Malware

Malicious Steam Wallpapers Spread Malware to Gamers

June 22, 2026 0

Data Leak

Tata Electronics Data Breach Exposes Apple and Tesla Files Tata Electronics data breach leaking Apple and Tesla component design and specification files on a dark web site
  • Data Leak

Tata Electronics Data Breach Exposes Apple and Tesla Files

June 23, 2026 0
Novo Nordisk Breach Exposes AI Models and Patient Data Novo Nordisk data breach Novo Nordisk hack, AI training data theft, clinical trial data leak
  • Data Leak

Novo Nordisk Breach Exposes AI Models and Patient Data

June 16, 2026 0
Uncanny Automator Breach: Backdoored Plugin Build Hit WordPress Sites Uncanny Automator breach WordPress supply chain attack, plugin backdoor, data breach
  • Data Leak

Uncanny Automator Breach: Backdoored Plugin Build Hit WordPress Sites

June 15, 2026 0
Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AI Siri AI system prompt Siri AI iOS 27
  • Data Leak

Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AI

June 10, 2026 0
Android Developer Verification: Google Reveals the Full Timeline Android developer verification timeline showing the September 30 2026 sideloading enforcement and 24-hour advanced flow
  • Android

Android Developer Verification: Google Reveals the Full Timeline

Do Son June 23, 2026 0
Google announced its Android developer verification program in 2025. The plan requires a valid developer signature, even...
Read More Read more about Android Developer Verification: Google Reveals the Full Timeline
8.1 Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution libssh2 vulnerability CVE-2026-55200 enabling remote code execution via out-of-bounds write
  • Vulnerability Report

8.1 Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution

Do Son June 23, 2026 0
  TL;DR A serious libssh2 vulnerability now puts SSH clients at risk. Researchers track it as CVE-2026-55200,...
Read More Read more about <span class="dcs-sev-badge" style="background:#f97316;">8.1</span> Critical libssh2 Vulnerability CVE-2026-55200 Enables Remote Code Execution
10 MariaDB Server Vulnerabilities Allow CVSS 10 Attacks MariaDB server vulnerabilities diagram showing shell command execution risks
  • Vulnerability Report

10 MariaDB Server Vulnerabilities Allow CVSS 10 Attacks

Do Son June 23, 2026 0
]   TL;DR Three serious MariaDB server vulnerabilities threaten database environments. The most severe flaw carries a...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">10</span> MariaDB Server Vulnerabilities Allow CVSS 10 Attacks
10.0 Mitel Patches 12 Critical MiCollab Vulnerabilities Rated Up to CVSS 10.0 Mitel MiCollab vulnerabilities MISA-2026-0005 command injection flaws rated CVSS 10.0
  • Vulnerability Report

10.0 Mitel Patches 12 Critical MiCollab Vulnerabilities Rated Up to CVSS 10.0

Do Son June 23, 2026 0
TL;DR Mitel disclosed 12 security flaws in MiCollab and the MiVoice Business Solution Virtual Instance (MiVB SVI)....
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">10.0</span> Mitel Patches 12 Critical MiCollab Vulnerabilities Rated Up to CVSS 10.0
Vendor-Signed UEFI Applications Allow Secure Boot Bypass vendor-signed UEFI applications Secure Boot bypass via BYOVD attack and UEFI DBX revocation
  • Vulnerability Report

Vendor-Signed UEFI Applications Allow Secure Boot Bypass

Do Son June 23, 2026 0
TL;DR CERT/CC disclosed a Secure Boot bypass that affects many vendor-signed UEFI applications. ESET researcher Martin Smolar...
Read More Read more about Vendor-Signed UEFI Applications Allow Secure Boot Bypass
HAProxy Vulnerabilities Expose Reverse-Proxy Servers HAProxy vulnerabilities diagram showing reverse-proxy security risks
  • Vulnerability Report

HAProxy Vulnerabilities Expose Reverse-Proxy Servers

Do Son June 23, 2026 0
  TL;DR Two critical flaws affect the HAProxy software. First, an integer overflow bug allows response smuggling....
Read More Read more about HAProxy Vulnerabilities Expose Reverse-Proxy Servers
QNAP Patches QuMagie Flaws Exposing Private Media Files QNAP QuMagie vulnerabilities allowing unauthenticated information disclosure of media files in QSA-26-35
  • Vulnerability Report

QNAP Patches QuMagie Flaws Exposing Private Media Files

Do Son June 22, 2026 0
  TL;DR QNAP has patched four QNAP QuMagie vulnerabilities, three of which need no login at all....
Read More Read more about QNAP Patches QuMagie Flaws Exposing Private Media Files
Pre-emptive AI cybersecurity: what it takes to prioritize risk before attackers act Salesforce vulnerability CVE-2025-9844 Salt Typhoon cyberattack
  • Technique

Pre-emptive AI cybersecurity: what it takes to prioritize risk before attackers act

Joe Pettit June 22, 2026 0
There is no shortage of vulnerabilities for security teams to deal with. FIRST forecasts up to 59,000...
Read More Read more about Pre-emptive AI cybersecurity: what it takes to prioritize risk before attackers act
Apache Doris SQL Injection Vulnerability CVE-2025-66336 Apache Doris SQL injection diagram showing CVE-2025-66336 metadata query path bypass
  • Vulnerability Report

Apache Doris SQL Injection Vulnerability CVE-2025-66336

Do Son June 22, 2026 0
TL;DR Apache Doris version 0.6.1 patches a severe security flaw in its MCP Server. Specifically, an Apache...
Read More Read more about Apache Doris SQL Injection Vulnerability CVE-2025-66336
SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control security-de
  • Malware

SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control

Do Son June 22, 2026 0
At a glance Malware family SHEETCREEP (SHEET#CREEP), C# .NET RAT Threat actor APT36 / Transparent Tribe (suspected,...
Read More Read more about SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control
Google Tests reCAPTCHA Hand Gesture Verification reCAPTCHA hand gesture verification scanning process and biometric CAPTCHA security reCAPTCHA Data
  • Technology

Google Tests reCAPTCHA Hand Gesture Verification

Do Son June 22, 2026 0
Combatting Advanced Bots with Hand Gestures Google initiated a limited beta test for its reCAPTCHA hand gesture...
Read More Read more about Google Tests reCAPTCHA Hand Gesture Verification
Microsoft Details Support Lifecycle for Windows 11 Version 26H2 Windows 11 version 26H2 support lifecycle and deployment roadmap for enterprise environments Windows 11 update anomaly Windows 11 context menu Windows 11 KB5089549 update error 0x800f0922 Windows 11 taskbar relocation
  • Windows

Microsoft Details Support Lifecycle for Windows 11 Version 26H2

Do Son June 22, 2026 0
Microsoft recently unveiled the early preview of Windows 11 version 26H2. The official release will likely debut...
Read More Read more about Microsoft Details Support Lifecycle for Windows 11 Version 26H2
Gemini CLI Deprecation: Google Moves Developers to Antigravity CLI Gemini CLI deprecation notice as Google moves developers to the Antigravity CLI terminal tool Google Antigravity 2.0 release
  • Technology

Gemini CLI Deprecation: Google Moves Developers to Antigravity CLI

Do Son June 22, 2026 0
Google gave developers an early warning about the Gemini CLI deprecation. Now the change has arrived. The...
Read More Read more about Gemini CLI Deprecation: Google Moves Developers to Antigravity CLI
Windows Recycle Bin Bug Surfaces After the June 2026 Update Windows Recycle Bin bug showing an internal $Rxxxxx filename in the delete confirmation dialog after the June 2026 update
  • Windows

Windows Recycle Bin Bug Surfaces After the June 2026 Update

Do Son June 22, 2026 0
Microsoft released its June 2026 Patch Tuesday updates on June 9. Within days, users began reporting odd...
Read More Read more about Windows Recycle Bin Bug Surfaces After the June 2026 Update
DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays digital-hacker
  • Malware

DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays

Do Son June 22, 2026 0
At a glance Malware family Backdoor.Turn (Go-based RAT) Threat actor DragonForce ransomware, developed by Hackledorb (Symantec attribution)...
Read More Read more about DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays
2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026) Weekly CVE report dashboard showing 2,060 new vulnerabilities and 4 actively exploited CVEs in CISA KEV
  • Weekly Recap

2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)

Do Son June 22, 2026 0
TL;DR This weekly CVE report covers 2,060 new vulnerabilities disclosed between June 15 and 21, 2026. Among...
Read More Read more about 2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)
Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads undici vulnerabilities in the Node.js HTTP client affecting a package with 133M weekly downloads
  • Vulnerability Report

Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads

Do Son June 22, 2026 0
TL;DR Maintainers have disclosed four undici vulnerabilities in the widely used Node.js HTTP client. The package draws...
Read More Read more about Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites hacker-security
  • Malware

ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites

Do Son June 22, 2026 0
At a glance Malware family ErrTraffic (ClickFix distribution framework / TDS, sold as MaaS) Threat actor Sold...
Read More Read more about ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites
9.6 Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps Avo authorization bypass CVE-2026-55518 enabling privilege escalation in a Ruby on Rails admin panel
  • Vulnerability Report

9.6 Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps

Do Son June 22, 2026 0
At a glance CVE CVE-2026-55518 CVSS 9.6 (Critical) Product / vendor Avo admin panel framework / Avo...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.6</span> Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps
Critical Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi pgAdmin 4 vulnerabilities CVE-2026-12046 stored XSS and RCE in PostgreSQL admin tool
  • Vulnerability Report

Critical Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi

Do Son June 22, 2026 0
Database administrators have urgent patching to do. The pgAdmin team has fixed three critical pgAdmin 4 vulnerabilities,...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">Critical</span> Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-56315CVSS 9.8
    picklescan before 1.0.4 fails to block at least seven Python standard library...
  • CVE-2026-56274CVSS 9.9
    Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom...
  • CVE-2026-11374CVSS 9.0
    In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus,...
  • CVE-2026-12866CVSS 9.8
    All versions of the package expr-eval are vulnerable to Code Execution via...
  • CVE-2026-54352CVSS 9.6
    ## Summary `POST /api/pwa/process-zip` at `packages/server/src/api/routes/static.ts:24` accepts a builder-uploaded `.zip`, extracts it...
  • CVE-2026-48746CVSS 9.1
    vLLM is an inference and serving engine for large language models (LLMs)....
  • CVE-2026-48170CVSS 9.1
    ## Summary `scim-patch` performs prototype pollution when applying a SCIM PATCH operation...
  • CVE-2026-46495
    ## Summary **Description** A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ's...
  • CVE-2026-56348CVSS 9.1
    n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options...
  • CVE-2026-46488
    ### Summary An authentication bypass vulnerability exists due to improper trust in...
Powered by CVE WATCHTOWER

🚨 Active Exploits in the Wild

  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-10735
    Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated attackers to...
  • CVE-2026-20262CVSS 6.5
    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,...
  • CVE-2026-54420CVSS 8.5
    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a...
  • CVE-2026-53435CVSS 8.8
    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize...
  • CVE-2026-10795CVSS 8.1
    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions...
  • CVE-2026-11645
    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
  • CVE-2026-50751CVSS 9.3
    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows...
  • CVE-2026-20245CVSS 7.8
    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local...
Powered by CVE Watchtower

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.