Skip to content
July 24, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0
Weekly CVE report dashboard showing 2,060 new vulnerabilities and 4 actively exploited CVEs in CISA KEV
  • Weekly Recap

2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)

Do Son June 22, 2026 0

Tech News

Google Gemini Spark agentic AI assistant running in the Google Workspace sidebar, drafting Gmail replies and Google Docs reports
  • Technology

Google Gemini Spark Expands Access to Pro and Ultra Subscribers

Do Son July 24, 2026 0
Google DMA fine of 890 million euros from the European Commission over search self-preferencing and Play Store steering restrictions
  • Technology

Google DMA Fine of €890 Million Lands in Brussels

Do Son July 24, 2026 0
LG monitor adware warning showing unwanted McAfee pop-ups and bloatware installation
  • Technology

LG Disables McAfee Ad Popups on Monitors After Backlash

Do Son July 24, 2026 0
Google selfie video sign-in setup screen showing guided head movements for account recovery and liveness verification
  • Technology

Google Selfie Video Sign-In Recovers Locked Accounts

Do Son July 23, 2026 0

Vulnerability

Windows AppResolver LPE CVE-2026-50454 UAC bypass chain to a SYSTEM shell and Elevation of Privilege
  • Vulnerability Report

CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM

Do Son July 24, 2026 0
Konnectivity vulnerability CVE-2026-16242 letting an unauthenticated agent join the routing pool and intercept control-plane traffic
  • Vulnerability Report

Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic

Do Son July 24, 2026 0
Tycon authentication bypass CVE-2026-61884 in TPDIN-Monitor-WEB2 rated CVSS 9.8
  • Vulnerability Report

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

Do Son July 24, 2026 0
ADAudit Plus vulnerability CVE-2026-6516 enabling unauthenticated remote code execution on Active Directory audit servers
  • Vulnerability Report

ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10

Do Son July 24, 2026 0

Cyber Security

North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Cybercriminals

North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests

July 24, 2026 0
DOJ Indicts Chinese National Over Gift Card Fraud Scheme in New Hampshire Gift card fraud conspiracy indictment tied to a wire fraud conspiracy charge and a New Hampshire electronics warehouse
  • Cybercriminals

DOJ Indicts Chinese National Over Gift Card Fraud Scheme in New Hampshire

July 24, 2026 0
Dolphin X Stealer Sold on a Cybercrime Forum Uses an AI Profiler to Rank Victims hack
  • Cybercriminals

Dolphin X Stealer Sold on a Cybercrime Forum Uses an AI Profiler to Rank Victims

July 23, 2026 0
HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms HelloNet campaign malware delivered through the ViPNet update system on a Russian workstation
  • Cybercriminals

HelloNet Campaign Abuses ViPNet Update System to Hit Russian Firms

July 23, 2026 0

Malware Alert

NadMesh Botnet Targets AI Services and Cloud Environments NadMesh botnet targeting cloud systems and presenting an AI infrastructure threat.
  • Malware

NadMesh Botnet Targets AI Services and Cloud Environments

July 24, 2026 0
TAG-150 Attack Chain Deploys DenoRAT Malware hack
  • Malware

TAG-150 Attack Chain Deploys DenoRAT Malware

July 24, 2026 0
ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains ACR Stealer infection chain starting with a ClickFix lure to steal browser credentials
  • Malware

ACR Stealer Spreads Through ClickFix Lures in Two Attack Chains

July 24, 2026 0
GST Phishing Campaign Distributes Remcos RAT Malware DPRK IT Workers, APT38 Crypto Forfeiture
  • Malware

GST Phishing Campaign Distributes Remcos RAT Malware

July 23, 2026 0

Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
The Grok Build Privacy Controversy: Unauthorized Repository Uploads Grok Build privacy settings interface showing how to disable automated repository data uploads
  • Data Leak

The Grok Build Privacy Controversy: Unauthorized Repository Uploads

July 14, 2026 0
KDDI Data Breach: Millions of Emails and Passwords Stolen KDDI data breach illustration, KDDI email leak security concept
  • Data Leak

KDDI Data Breach: Millions of Emails and Passwords Stolen

July 9, 2026 0
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments GoSerpent backdoor cyber espionage attack chain against Southeast Asian government networks
  • Cyber Security

GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments

Do Son July 24, 2026 0
Read More Read more about GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers ChatGPT_Image_Jul_24_2026_11_58_11_AM_1784887099UOeFRyUzMz
  • Press Release

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

cybernewswire July 24, 2026 0
Read More Read more about Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw Knot Resolver RCE through a DNS-over-QUIC heap overflow with publicly disclosed PoC exploit code
  • Vulnerability Report

Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw

Do Son July 24, 2026 0
Read More Read more about Public Exploit Code Released for Knot Resolver DNS-over-QUIC Remote Code Execution Flaw
CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling Logto vulnerabilities enabling SSO authentication bypass across OIDC, OAuth 2.1, and SAML sign-in flows
  • Vulnerability Report

CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling

Do Son July 24, 2026 0
Read More Read more about CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling
Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs Chrome security update patching a Codecs sandbox escape and use-after-free flaws in Chrome 150
  • Vulnerability Report

Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs

Do Son July 24, 2026 0
Read More Read more about Google Ships Chrome 150 Update Fixing Four High-Severity Memory Bugs
HTTP/2 DoS Vulnerability Lets Attackers Exhaust Server Memory via Stalled Flow Control HTTP/2 DoS vulnerability caused by stalled flow control exhausting server memory across multiple HTTP/2 implementations
  • Vulnerability Report

HTTP/2 DoS Vulnerability Lets Attackers Exhaust Server Memory via Stalled Flow Control

Do Son July 23, 2026 0
Read More Read more about HTTP/2 DoS Vulnerability Lets Attackers Exhaust Server Memory via Stalled Flow Control
TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits Half-click exploits chain showing webmail zero-days used by TA488 and TA458 against Zimbra, SOGo and Roundcube mailservers
  • Cyber Security

TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits

Do Son July 23, 2026 0
Read More Read more about TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
JetBrains Patches 18 Flaws, Including Two CVSS 10 Bugs in IntelliJ IDEA Remote Development JetBrains vulnerabilities across IntelliJ IDEA, WebStorm and TeamCity, including CVE-2026-64812 remote development flaws enabling arbitrary code execution
  • Vulnerability Report

JetBrains Patches 18 Flaws, Including Two CVSS 10 Bugs in IntelliJ IDEA Remote Development

Do Son July 23, 2026 0
Read More Read more about JetBrains Patches 18 Flaws, Including Two CVSS 10 Bugs in IntelliJ IDEA Remote Development
Apache Syncope Patches SQL Injection and Privilege Escalation Flaws Apache Syncope vulnerabilities including a privilege escalation flaw fixed in CVE-2026-57308 and CVE-2026-62183
  • Vulnerability Report

Apache Syncope Patches SQL Injection and Privilege Escalation Flaws

Do Son July 23, 2026 0
Read More Read more about Apache Syncope Patches SQL Injection and Privilege Escalation Flaws
CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges Foxit PDF Reader vulnerability CVE-2026-57239 exploited for SYSTEM privileges via local privilege escalation
  • Vulnerability Report

CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges

Do Son July 23, 2026 0
Read More Read more about CVE-2026-57239: Public PoC Exploits Foxit PDF Reader Vulnerability for SYSTEM Privileges
Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware Next.js vulnerabilities diagram showing Server-Side Request Forgery through rewrites and Server Actions in CVE-2026-64645 and CVE-2026-64649
  • Vulnerability Report

Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware

Do Son July 23, 2026 0
Read More Read more about Next.js Patches Three CVSS 8.3 Flaws in Rewrites, Server Actions, and Middleware
Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution SGLang vulnerability CVE-2026-14890 enabling unauthenticated remote code execution via pickle deserialization
  • Vulnerability Report

Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution

Do Son July 23, 2026 0
Read More Read more about Unpatched SGLang Flaw CVE-2026-14890 Allows Unauthenticated Remote Code Execution
Canonical Launches the Enterprise Store for Air-Gapped Networks Canonical Enterprise Store architecture diagram showing software distribution in air-gapped enterprise environments
  • Linux

Canonical Launches the Enterprise Store for Air-Gapped Networks

Do Son July 23, 2026 0
Read More Read more about Canonical Launches the Enterprise Store for Air-Gapped Networks
New 10-Inch Raspberry Pi Touch Display 2 Costs $80 Raspberry Pi Touch Display 2 in the 10-inch size showing its 1200x1920 portrait panel connected to a Raspberry Pi 5
  • Technology

New 10-Inch Raspberry Pi Touch Display 2 Costs $80

Do Son July 23, 2026 0
Read More Read more about New 10-Inch Raspberry Pi Touch Display 2 Costs $80
Google’s Nuvem Subsea Cable Links US and Portugal Nuvem subsea cable route linking Myrtle Beach South Carolina to Sines Portugal via Bermuda and the Azores with 384 Tbps capacity
  • Technology

Google’s Nuvem Subsea Cable Links US and Portugal

Do Son July 23, 2026 0
Read More Read more about Google’s Nuvem Subsea Cable Links US and Portugal
Apple Patches Hide My Email Vulnerability at Last Hide My Email vulnerability in Apple iCloud+ exposing real email addresses behind randomly generated forwarding aliases
  • Vulnerability Report

Apple Patches Hide My Email Vulnerability at Last

Do Son July 23, 2026 0
Read More Read more about Apple Patches Hide My Email Vulnerability at Last
GitHub Overhauls Bug Bounty Program with New VIP Tier GitHub bug bounty program restructuring flowchart, VIP security researcher reward tiers
  • Technology

GitHub Overhauls Bug Bounty Program with New VIP Tier

Do Son July 23, 2026 0
Read More Read more about GitHub Overhauls Bug Bounty Program with New VIP Tier
Google Enhances iOS to Android Migration Tool Upgraded Google iOS to Android migration tool interface displaying eSIM data transfer options
  • Android

Google Enhances iOS to Android Migration Tool

Do Son July 23, 2026 0
Read More Read more about Google Enhances iOS to Android Migration Tool
DoNot APT Targets Bangladesh Military With a Fake Officer Biography CRussian Market, "Fly" (Flyded) hange Healthcare Cyberattack - CVE-2024-50603 Exploit
  • Cybercriminals

DoNot APT Targets Bangladesh Military With a Fake Officer Biography

Do Son July 23, 2026 0
Read More Read more about DoNot APT Targets Bangladesh Military With a Fake Officer Biography
GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Cybercriminals

GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign

Do Son July 23, 2026 0
Read More Read more about GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
ISC Patches 9 BIND 9 Vulnerabilities, Including a DNSSEC Cache Poisoning Flaw BIND vulnerability advisory chart listing nine DNSSEC flaws including CVE-2026-13321 cache poisoning fixed in BIND 9.20.26 and 9.21.24
  • Vulnerability Report

ISC Patches 9 BIND 9 Vulnerabilities, Including a DNSSEC Cache Poisoning Flaw

Do Son July 23, 2026 0
Read More Read more about ISC Patches 9 BIND 9 Vulnerabilities, Including a DNSSEC Cache Poisoning Flaw
600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3 Ninja Forms vulnerability dashboard showing CVE-2026-65048 unauthenticated stored XSS with a CVSS 9.3 score across 600K WordPress sites
  • Vulnerability Report

600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3

Do Son July 23, 2026 0
Read More Read more about 600K Sites at Risk: Ninja Forms Stored XSS Flaw CVE-2026-65048 Hits CVSS 9.3
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-15704CVSS 9.8
    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled...
  • CVE-2026-62825CVSS 10.0
    Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate...
  • CVE-2026-58275CVSS 10.0
    Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges...
  • CVE-2026-56191CVSS 10.0
    Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform...
  • CVE-2026-56165CVSS 9.8
    Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute...
  • CVE-2026-56160CVSS 9.1
    Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker...
  • CVE-2026-54120CVSS 9.9
    Improper input validation in Microsoft Surface allows an authorized attacker to execute...
  • CVE-2026-50517CVSS 9.9
    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to...
  • CVE-2026-63359CVSS 9.8
    The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an...
  • CVE-2026-6516CVSS 10.0
    Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.