Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

CISA flagged 6 actively exploited CVEs this week, from a SharePoint RCE to a Check Point auth bypass. See the full CISA KEV list and patch fast.
  • Weekly Recap

Weekly Threat Intelligence Briefing: Late July 2026

Do Son July 27, 2026 0
actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0

Tech News

Microsoft Project Perception agentic security system with red, blue, and green AI team agents, a security context layer, and actuators for the AI era
  • Technology

Microsoft Unveils Project Perception, an Agentic Security System

Do Son July 28, 2026 0
Moonshot AI Kimi K3 open weights release, the first 3T-class open model, with AgentENV microVM sandbox built after agents caused host kernel panics
  • Technology

Kimi K3 Opens Weights as Agents Push Past Sandbox Boundaries

Do Son July 28, 2026 0
Google native Chrome for Linux Arm64 build running on Raspberry Pi OS desktop with account sync and Widevine DRM support for streaming video
  • Technology

Google Quietly Ships Native Chrome for Linux Arm64 With DRM

Do Son July 28, 2026 0
NVIDIA and Microsoft launch the Open Secure AI Alliance with 27 founding members to strengthen cybersecurity defense after the Hugging Face AI attack
  • Technology

NVIDIA and Microsoft Launch Open Secure AI Alliance After Hack

Do Son July 28, 2026 0

Vulnerability

MiCollab command injection and OpenScape UC vulnerability advisories from Mitel showing CVSS 9.8 and CVSS 8.0 severity ratings
  • Vulnerability Report

Mitel Patches MiCollab Command Injection Flaw (CVSS 9.8) That Lets Attackers Gain Control of the System

Do Son July 28, 2026 0
Panduit IntraVUE vulnerability CVE-2026-42933 CVSS 10 rating enabling OT segmentation bypass in industrial networks
  • Vulnerability Report

Panduit IntraVUE Vulnerability CVE-2026-42933 (CVSS 10) Bypasses OT Segmentation

Do Son July 28, 2026 0
TeamCity RCE vulnerability CVE-2026-63077 in TeamCity On-Premises rated CVSS 9.8
  • Vulnerability Report

TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution

Do Son July 28, 2026 0
CVE-2026-42533 NGINX heap overflow proof-of-concept enabling an ASLR bypass and RCE
  • Vulnerability Report

CVE-2026-42533: NGINX Heap Overflow Enables RCE and ASLR Bypass, Public PoC Released

Do Son July 28, 2026 0

Cyber Security

Insikt Group Finds Four New Golden Chickens Malware Families Golden Chickens malware chain showing ChonkyChicken malware and TinyEgg delivered through ClickFix fake verification pages
  • Cybercriminals

Insikt Group Finds Four New Golden Chickens Malware Families

July 28, 2026 0
JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools ACR Stealer infection chain starting with a ClickFix lure to steal browser credentials
  • Cybercriminals

JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools

July 28, 2026 0
Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers ClickFake Interview campaign delivering PylangGhost RAT and GolangGhost RAT to crypto professionals
  • Cybercriminals

Fake Job Interviews Deliver PylangGhost and GolangGhost RATs to Crypto Workers

July 28, 2026 0
VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub Operation STANDOFF infrastructure map showing a Russian-speaking threat group hiding C2 servers behind GitHub redirects
  • Cybercriminals

VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub

July 27, 2026 0

Malware Alert

RenPy Loader Spreads Amatera Stealer Through Fake Game Downloads RenPy Loader infection chain in fake game installers using MSBuild and EtherHiding to deploy Amatera Stealer
  • Malware

RenPy Loader Spreads Amatera Stealer Through Fake Game Downloads

July 27, 2026 0
Cruciferra Crypter Service Cloaks RATs and Infostealers for Many Threat Actors Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Malware

Cruciferra Crypter Service Cloaks RATs and Infostealers for Many Threat Actors

July 27, 2026 0
NadMesh Botnet Targets AI Services and Cloud Environments NadMesh botnet targeting cloud systems and presenting an AI infrastructure threat.
  • Malware

NadMesh Botnet Targets AI Services and Cloud Environments

July 24, 2026 0
TAG-150 Attack Chain Deploys DenoRAT Malware hack
  • Malware

TAG-150 Attack Chain Deploys DenoRAT Malware

July 24, 2026 0

Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error Claude AI shared conversation links indexed in Google search due to a robots.txt and X-Robots-Tag misconfiguration exposing private chat content
  • Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error

July 27, 2026 0
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
The Grok Build Privacy Controversy: Unauthorized Repository Uploads Grok Build privacy settings interface showing how to disable automated repository data uploads
  • Data Leak

The Grok Build Privacy Controversy: Unauthorized Repository Uploads

July 14, 2026 0
Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability result_Aembit-Snowflake-Revised_1785251578w6w40xbGlY
  • Press Release

Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability

cybernewswire July 28, 2026 0
Read More Read more about Aembit Joins Snowflake to Tackle AI’s Next Security Frontier: Trusted Agent Interoperability
Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public Fraggap Linux kernel vulnerability CVE-2026-53362 enabling local privilege escalation through a UDPv6 out-of-bounds write
  • Vulnerability Report

Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public

Do Son July 28, 2026 0
Read More Read more about Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed OVSwrap local root vulnerability CVE-2026-64531 in the Linux kernel Open vSwitch datapath
  • Vulnerability Report

OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed

Do Son July 28, 2026 0
Read More Read more about OVSwrap Local Root Vulnerability (CVE-2026-64531): Exploit Details and PoC Publicly Disclosed
Windows 11 Experimental Builds Face a Time Bomb on August 11 Windows 11 Experimental Future Platforms time bomb expiring on August 11 with forced full-screen expiration popups, fixed by updating to Build 29634.1000
  • Windows

Windows 11 Experimental Builds Face a Time Bomb on August 11

Do Son July 28, 2026 0
Read More Read more about Windows 11 Experimental Builds Face a Time Bomb on August 11
Debian Debates Whether to Allow AI-Assisted Code Contributions Debian AI contribution vote debating four proposals on generative AI assisted code, from an outright ban to allowing AI with disclosure requirements
  • Linux

Debian Debates Whether to Allow AI-Assisted Code Contributions

Do Son July 28, 2026 0
Read More Read more about Debian Debates Whether to Allow AI-Assisted Code Contributions
libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory libssh2 vulnerabilities let a malicious SSH server corrupt heap memory in SSH and SFTP clients
  • Vulnerability Report

libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory

Do Son July 28, 2026 0
Read More Read more about libssh2 Flaws Let Malicious SSH Servers Corrupt Client Memory
Progress Patches Five Kemp LoadMaster Vulnerabilities Kemp LoadMaster vulnerabilities warning covering OS command injection and privilege escalation flaws
  • Vulnerability Report

Progress Patches Five Kemp LoadMaster Vulnerabilities

Do Son July 28, 2026 0
Read More Read more about Progress Patches Five Kemp LoadMaster Vulnerabilities
Apache ActiveMQ Patches Authorization Bypass and DoS Flaws Apache ActiveMQ vulnerability alert covering authorization bypass and AMQP denial-of-service flaws
  • Vulnerability Report

Apache ActiveMQ Patches Authorization Bypass and DoS Flaws

Do Son July 28, 2026 0
Read More Read more about Apache ActiveMQ Patches Authorization Bypass and DoS Flaws
CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited CISA KEV additions listing two known exploited vulnerabilities in Arista VeloCloud and FortiOS
  • Vulnerability Report

CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited

Do Son July 27, 2026 0
Read More Read more about CISA KEV Additions: Arista VeloCloud and FortiOS Flaws Now Exploited
CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild CVE-2026-16812 VeloCloud command injection exploited in the wild affecting VeloCloud Orchestrator
  • Vulnerability Report

CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild

Do Son July 27, 2026 0
Read More Read more about CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild
Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants Kimsuky Gomir variant attack chain showing the DriveTroy backdoor using Google Drive as a covert C2 channel
  • Cybercriminals

Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants

Do Son July 27, 2026 0
Read More Read more about Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants
Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards Joe_Channel_Awards_2_1785157894FHsYNffOlZ
  • Press Release

Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards

cybernewswire July 27, 2026 0
Read More Read more about Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards
Unpatched Plane Authorization Bypass CVE-2026-15342 Exposes Other Workspaces Plane authorization bypass CVE-2026-15342 exposing multi-tenant workspace assets
  • Vulnerability Report

Unpatched Plane Authorization Bypass CVE-2026-15342 Exposes Other Workspaces

Do Son July 27, 2026 0
Read More Read more about Unpatched Plane Authorization Bypass CVE-2026-15342 Exposes Other Workspaces
Apache Fory Patches Four Deserialization Flaws Across Java, C++, and Rust Apache Fory vulnerabilities in Java, C++, and Rust deserialization fixed in version 1.4.0
  • Vulnerability Report

Apache Fory Patches Four Deserialization Flaws Across Java, C++, and Rust

Do Son July 27, 2026 0
Read More Read more about Apache Fory Patches Four Deserialization Flaws Across Java, C++, and Rust
CVE-2026-61511: vBulletin Preauth RCE with Public PoC Disclosed CVE-2026-61511 vBulletin preauth RCE proof-of-concept abusing the runMaths eval for remote code execution
  • Vulnerability Report

CVE-2026-61511: vBulletin Preauth RCE with Public PoC Disclosed

Do Son July 27, 2026 0
Read More Read more about CVE-2026-61511: vBulletin Preauth RCE with Public PoC Disclosed
TELESHIM Malware Targets Middle East Governments Through Telegram SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Cybercriminals

TELESHIM Malware Targets Middle East Governments Through Telegram

Do Son July 27, 2026 0
Read More Read more about TELESHIM Malware Targets Middle East Governments Through Telegram
APT42 TAMECAT Malware Grows with AI-Assisted Phishing Tamecat
  • Cybercriminals

APT42 TAMECAT Malware Grows with AI-Assisted Phishing

Do Son July 27, 2026 0
Read More Read more about APT42 TAMECAT Malware Grows with AI-Assisted Phishing
Google AI Overviews Traffic Loss Drives Publisher Backlash Google AI Overviews traffic decline chart and publisher organic search impact
  • Technology

Google AI Overviews Traffic Loss Drives Publisher Backlash

Do Son July 27, 2026 0
Read More Read more about Google AI Overviews Traffic Loss Drives Publisher Backlash
Samsung One UI 9 Locks the Phone Forever After 13 Wrong Codes Samsung One UI 9 lockscreen security on Android 17 permanently locks the device after 13 failed passcode attempts, requiring a factory reset
  • Android

Samsung One UI 9 Locks the Phone Forever After 13 Wrong Codes

Do Son July 27, 2026 0
Read More Read more about Samsung One UI 9 Locks the Phone Forever After 13 Wrong Codes
Windows 11 File Explorer Now Deletes Large Fragmented Files Faster Windows 11 File Explorer faster deletion of large fragmented files in Build 26300.8935, a rare NTFS performance win from Microsoft
  • Windows

Windows 11 File Explorer Now Deletes Large Fragmented Files Faster

Do Son July 27, 2026 0
Read More Read more about Windows 11 File Explorer Now Deletes Large Fragmented Files Faster
Intel to Bring Back Hyper-Threading in 2028 Coral Rapids Xeon Intel hyper-threading return in 2028 Coral Rapids Xeon server CPUs announced by CEO Lip-Bu Tan to reclaim data center CPU market share
  • Technology

Intel to Bring Back Hyper-Threading in 2028 Coral Rapids Xeon

Do Son July 27, 2026 0
Read More Read more about Intel to Bring Back Hyper-Threading in 2028 Coral Rapids Xeon
EU Says TikTok Breaches DSA Rules on Protecting Minors’ Privacy EU preliminary findings accuse TikTok of breaching DSA minor-safety rules over public-by-default accounts and For You algorithmic recommendation
  • Technology

EU Says TikTok Breaches DSA Rules on Protecting Minors’ Privacy

Do Son July 27, 2026 0
Read More Read more about EU Says TikTok Breaches DSA Rules on Protecting Minors’ Privacy
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-11841CVSS 9.4
    An attacker may perform unauthenticated read and write operations on sensitive filesystem...
  • CVE-2026-16462CVSS 9.8
    In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows...
  • CVE-2026-11756CVSS 10.0
    A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE...
  • CVE-2026-15014CVSS 9.8
    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications &...
  • CVE-2026-55579CVSS 9.8
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-48030CVSS 9.9
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-63077CVSS 9.8
    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible...
  • CVE-2026-17191CVSS 9.1
    An input validation vulnerability exists in an API component of the orchestrator....
  • CVE-2026-51303CVSS 9.8
    A use-after-free (UAF) vulnerability was discovered in the core parsing component of...
  • CVE-2025-50455CVSS 9.1
    SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.