Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

Weekly CVE report on exploited vulnerabilities from Daily Cybersecurity and CISA KEV, September 28 to October 4, 2026
  • Weekly Recap

Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)

Do Son October 5, 2026 0
Weekly CVE report comparing exploited vulnerabilities from Daily Cybersecurity intelligence with the CISA KEV catalog for September 21-27, 2026
  • Weekly Recap

Weekly CVE Report: 2,825 New Flaws and 9 Exploited Bugs (Sept 21-27, 2026)

Do Son September 28, 2026 0
CVE-2023-50164 AEM Forms
  • Weekly Recap

Weekly CVE Report: 4,378 New Flaws and 10 Exploited Bugs

Do Son September 21, 2026 0
Weekly CVE report chart comparing Daily Cybersecurity exploited vulnerabilities against the CISA KEV catalog
  • Weekly Recap

Daily Cybersecurity Flagged 9 Exploited Flaws Before CISA KEV

Do Son September 14, 2026 0
This weekly CVE report covers 10 exploited vulnerabilities added to CISA KEV and 2,316 new CVEs from Aug 31 to Sep 6, 2026. Patch fast.
  • Weekly Recap

Weekly CVE Report: Daily Cybersecurity Beats CISA KEV on Exploited Flaws

Do Son September 7, 2026 0

Tech News

Cloudflare Clef decision models returning option probability scores for AI agents on the Workers AI platform
  • Technology

Cloudflare Clef Decision Models Speed Up AI Agents

Do Son October 5, 2026 0
OpenAI rogue AI agents reaching beyond their sandbox into third-party systems, part of a wave of AI agent misalignment incidents
  • Technology

OpenAI Rogue AI Agents May Have Hit 100+ Organizations

Do Son October 5, 2026 0
macOS security prompt warning users about granting Full Disk Access to an autonomous AI agent
  • Technology

Apple Restricts Full Disk Access for macOS AI Agents

Do Son October 4, 2026 0
iPhone 18 AT&T issue hardware replacement and iPhone 18 Pro Max cellular network failure
  • Technology

iPhone 18 AT&T Issue: Navigating the Cellular Crisis

Do Son October 4, 2026 0

Vulnerability

Apache Struts vulnerabilities fixed in Struts 7.4.0 including OGNL injection CVE-2026-104711 and REST plugin DoS CVE-2026-104713
  • Vulnerability Report

Apache Struts 7.4.0 Fixes Four Vulnerabilities, Including OGNL Injection and REST Plugin DoS

Do Son October 5, 2026 0
Perforce P4 Search vulnerabilities CVE-2026-100103 default token and CVE-2026-100102 exposed Java debug interface in P4 Search
  • Vulnerability Report

Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw

Do Son October 5, 2026 0
MediaTek security bulletin October 2026 MediaTek modem vulnerability CVE-2026-20519 CVE-2026-20520 rogue base station
  • Vulnerability Report

MediaTek October 2026 Security Bulletin Fixes 31 Flaws, Including Two Critical Modem Bugs

Do Son October 5, 2026 0
macOS HFS+ vulnerability CVE-2026-43682 kernel heap overflow with public proof-of-concept exploit code
  • Vulnerability Report

Researcher Publishes Technical Details and PoC Exploit for macOS HFS+ Kernel Flaw CVE-2026-43682

Do Son October 5, 2026 0

Cyber Security

ShinyHunters Hacker Arrest in Jordan Aids FBI Probe ShinyHunters hacker arrest in Jordan as an alleged member cooperates with the FBI ShinyHunters investigation
  • Cybercriminals

ShinyHunters Hacker Arrest in Jordan Aids FBI Probe

October 5, 2026 0
Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws Warlock ransomware attack chain exploiting SharePoint vulnerabilities to hit critical infrastructure
  • Cybercriminals

Warlock Ransomware Group Hits Water and Telecom Operators Through SharePoint Flaws

October 5, 2026 0
China-Aligned TA419 Credential Phishing Hits AI Experts Diagram showing China-aligned TA419 credential phishing and TA419 credential phishing attack stages
  • Cybercriminals

China-Aligned TA419 Credential Phishing Hits AI Experts

October 2, 2026 0
Phishing Abuses RMM Tools for Persistent Network Access CoreRAT malware decoy PDF used in Core Werewolf phishing attack on Russian defense targets
  • Cybercriminals

Phishing Abuses RMM Tools for Persistent Network Access

October 2, 2026 0

Malware Alert

Moroccan Intelligence Deploys Vast Surveillance Panopticon Amnesty International exposing the Moroccan DGST surveillance network and Pegasus spyware infections
  • Malware

Moroccan Intelligence Deploys Vast Surveillance Panopticon

October 5, 2026 0
DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel DragonForce backdoor using Microsoft Teams TURN relays and MQTT as a fallback command channel
  • Malware

DragonForce Backdoor Adds MQTT Fallback to Microsoft Teams TURN Command Channel

October 5, 2026 0
New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes 2CLoader malware infection chain delivering Vidar and Remus infostealers with anti-VM and evasion checks
  • Malware

New 2CLoader Malware Delivers Vidar and Remus Infostealers While Dodging Sandboxes

October 5, 2026 0
BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices BPFDoor backdoor and AVERAT implant disguised as mail traffic on telecom and network edge appliances
  • Malware

BPFDoor Backdoor and New AVERAT Implant Hide in SMTP Traffic on Telecom Edge Devices

October 5, 2026 0

Data Leak

Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People Denmark CPR data breach - CPR numbers exposed for 8.8 million people in the national register
  • Data Leak

Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People

October 5, 2026 0
AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos AI agent screenshot leak in PixelLeak research showing internal images pushed to public GitHub repos
  • Data Leak

AI Coding Agents Leak 13,000 Internal Screenshots to Public GitHub Repos

September 30, 2026 0
Meta Muse Secretly Used Humans for AI Phone Calls Meta Muse AI agent phone calling feature secretly handed off to human contractors
  • Data Leak

Meta Muse Secretly Used Humans for AI Phone Calls

September 24, 2026 0
ShinyHunters Syndicate Alleges Major FBI Network Compromise Bling Libra
  • Data Leak

ShinyHunters Syndicate Alleges Major FBI Network Compromise

September 24, 2026 0
CVE Watchtower User Guide CVE Watchtower User Guide
  • How To

CVE Watchtower User Guide

Do Son October 2, 2026 0
Read More Read more about CVE Watchtower User Guide
Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams DCMTK vulnerabilities enabling path traversal file write in the DICOM toolkit (CVE-2026-50003)
  • Technique

Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams

Do Son October 5, 2026 0
Read More Read more about Who Can Actually Compel Your Hosting Provider: A Jurisdiction Guide for Security Teams
Google Fortifies Android Advanced Protection Google Android Advanced Protection shield icon over smartphone interface showing security updates
  • Android

Google Fortifies Android Advanced Protection

Do Son October 5, 2026 0
Read More Read more about Google Fortifies Android Advanced Protection
8 Top Tools to Discover Shadow Agents Diagram illustrating Langflow OSS vulnerabilities and CVE-2026-10134 execution paths
  • Technique

8 Top Tools to Discover Shadow Agents

Do Son October 5, 2026 0
Read More Read more about 8 Top Tools to Discover Shadow Agents
Windows 11 26H2 Update Arrives With a Single Restart Windows 11 26H2 update installing through Windows Update with an enablement package, the Windows 11 2026 Update
  • Windows

Windows 11 26H2 Update Arrives With a Single Restart

Do Son October 5, 2026 0
Read More Read more about Windows 11 26H2 Update Arrives With a Single Restart
Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users Ubuntu 26.04 upgrade offered in Update Manager to Ubuntu 24.04 LTS users, showing the Resolute Raccoon desktop
  • Linux

Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users

Do Son October 5, 2026 0
Read More Read more about Ubuntu 26.04 Upgrade Now Open to 24.04 LTS Users
Socket Links Popular VS Code Color Themes to the GlassWorm Supply Chain Campaign GlassWorm VS Code themes cluster of malicious VS Code extensions posing as color themes
  • Malware

Socket Links Popular VS Code Color Themes to the GlassWorm Supply Chain Campaign

Do Son October 5, 2026 0
Read More Read more about Socket Links Popular VS Code Color Themes to the GlassWorm Supply Chain Campaign
Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026) Weekly CVE report on exploited vulnerabilities from Daily Cybersecurity and CISA KEV, September 28 to October 4, 2026
  • Weekly Recap

Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)

Do Son October 5, 2026 0
Read More Read more about Weekly CVE Report Tracks 2,652 New Flaws and Seven Exploited Vulnerabilities (Sept. 28 – Oct. 4, 2026)
Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline Citrix NetScaler CVE-2026-88779 exploited in the wild against NetScaler SAML authentication deployments
  • Vulnerability Report

Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline

Do Son October 4, 2026 0
Read More Read more about Citrix NetScaler CVE-2026-88779 Exploited in the Wild to Knock SAML Gateways Offline
OpenAI AI Safety Whistleblower Warns of Culture Collapse David Robinson OpenAI safety whistleblower warns of AI alignment failures and corporate governance collapse
  • Technology

OpenAI AI Safety Whistleblower Warns of Culture Collapse

Do Son October 4, 2026 0
Read More Read more about OpenAI AI Safety Whistleblower Warns of Culture Collapse
Gemini Free Tier Limits: Flash-Lite Only From Oct 9 Gemini free tier limits showing the Gemini app restricted to the Gemini Flash-Lite model for free personal accounts
  • Technology

Gemini Free Tier Limits: Flash-Lite Only From Oct 9

Do Son October 4, 2026 0
Read More Read more about Gemini Free Tier Limits: Flash-Lite Only From Oct 9
Meta Muse Gadgets: Open-Source Hardware for the Muse AI Meta Muse Gadgets open-source project showing a Muse Home Link dongle and maker-built hardware running the Muse AI agent
  • Technology

Meta Muse Gadgets: Open-Source Hardware for the Muse AI

Do Son October 4, 2026 0
Read More Read more about Meta Muse Gadgets: Open-Source Hardware for the Muse AI
Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server Apache OpenOffice vulnerability CVE-2026-59265 alongside Apache Directory LDAP API flaw CVE-2026-103877 and Traffic Server CVE-2026-102795
  • Vulnerability Report

Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server

Do Son October 3, 2026 0
Read More Read more about Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server
Microsoft Reissues September 2026 Exchange Server Security Updates to Add CVE-2026-96940 Exchange Server security updates September 2026 V2 adding CVE-2026-96940 for Exchange SE, Exchange 2019 and Exchange 2016
  • Vulnerability Report

Microsoft Reissues September 2026 Exchange Server Security Updates to Add CVE-2026-96940

Do Son October 3, 2026 0
Read More Read more about Microsoft Reissues September 2026 Exchange Server Security Updates to Add CVE-2026-96940
AWS Fixes Loom for AWS Admin Takeover and SageMaker Unified Studio Code Execution Flaws Loom for AWS authentication bypass CVE-2026-103956 and SageMaker Unified Studio command injection 
  • Vulnerability Report

AWS Fixes Loom for AWS Admin Takeover and SageMaker Unified Studio Code Execution Flaws

Do Son October 2, 2026 0
Read More Read more about AWS Fixes Loom for AWS Admin Takeover and SageMaker Unified Studio Code Execution Flaws
Digi DAL OS Vulnerability Lets Unauthenticated Attackers Run Root Commands Digi DAL OS vulnerability CVE-2026-75937 command injection in Digi Accelerated Linux web administration on IX, EX and TX routers
  • Vulnerability Report

Digi DAL OS Vulnerability Lets Unauthenticated Attackers Run Root Commands

Do Son October 2, 2026 0
Read More Read more about Digi DAL OS Vulnerability Lets Unauthenticated Attackers Run Root Commands
Chrome Security Update Fixes Critical WebGL Flaw and 10 Other Bugs Chrome security update for Chrome 154 fixing CVE-2026-103628 WebGL sandbox escape and CVE-2026-103631 WebRTC flaw
  • Vulnerability Report

Chrome Security Update Fixes Critical WebGL Flaw and 10 Other Bugs

Do Son October 2, 2026 0
Read More Read more about Chrome Security Update Fixes Critical WebGL Flaw and 10 Other Bugs
GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands GitLab AI Gateway vulnerability CVE-2026-90970 lets Duo Agent Platform users escape the prompt template sandbox
  • Vulnerability Report

GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands

Do Son October 2, 2026 0
Read More Read more about GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands
Patched NetScaler Appliances Keep Rebooting as Citrix Flags SAML Authentication Issue NetScaler SAML authentication issue causing patched NetScaler appliances to reboot after CVE-2026-88771 and CVE-2026-88772 exploitation
  • Vulnerability Report

Patched NetScaler Appliances Keep Rebooting as Citrix Flags SAML Authentication Issue

Do Son October 2, 2026 0
Read More Read more about Patched NetScaler Appliances Keep Rebooting as Citrix Flags SAML Authentication Issue
Seven TP-Link Vulnerabilities Hit Tapo Cameras, Archer and Deco Routers TP-Link vulnerabilities and Tapo camera vulnerabilities CVE-2026-102369 in Tapo C200, Archer AX90 and Deco M9 Plus
  • Vulnerability Report

Seven TP-Link Vulnerabilities Hit Tapo Cameras, Archer and Deco Routers

Do Son October 2, 2026 0
Read More Read more about Seven TP-Link Vulnerabilities Hit Tapo Cameras, Archer and Deco Routers
Moxa MGate Vulnerabilities Put Industrial Protocol Gateways at Risk Moxa MGate vulnerabilities CVE-2026-86325 and CVE-2026-86326 in MGate protocol gateway firmware
  • Vulnerability Report

Moxa MGate Vulnerabilities Put Industrial Protocol Gateways at Risk

Do Son October 2, 2026 0
Read More Read more about Moxa MGate Vulnerabilities Put Industrial Protocol Gateways at Risk
Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed Stirling PDF RCE CVE-2026-85714 proof-of-concept publicly disclosed
  • Vulnerability Report

Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed

Do Son October 2, 2026 0
Read More Read more about Stirling PDF RCE CVE-2026-85714: Details and PoC Publicly Disclosed
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-100781CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105293CVSS 9.2
    Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100551CVSS 9.0
    OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105218CVSS 9.1
    gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider...
    📅 Updated: Oct 5, 2026
  • CVE-2026-82042CVSS 9.3
    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access...
    📅 Updated: Oct 5, 2026
  • CVE-2026-79820CVSS 9.0
    A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
    📅 Updated: Oct 5, 2026
  • CVE-2026-105223CVSS 9.1
    maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data,...
    📅 Updated: Oct 5, 2026
  • CVE-2025-6544CVSS 9.8
    A deserialization vulnerability exists in h2oai/h2o-3 versions
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.