Skip to content
July 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button

Weekly Recap

CISA flagged 6 actively exploited CVEs this week, from a SharePoint RCE to a Check Point auth bypass. See the full CISA KEV list and patch fast.
  • Weekly Recap

Weekly Threat Intelligence Briefing: Late July 2026

Do Son July 27, 2026 0
actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
weekly CVE report actively exploited vulnerabilities
  • Weekly Recap

Weekly CVE Report: 1,571 New Flaws and 6 Actively Exploited Bugs (July 6–12, 2026)

Do Son July 13, 2026 0
Weekly Threat Intelligence Active Vulnerability Report
  • Weekly Recap

Weekly Threat Intelligence: The July 2026 Breaches

Do Son July 6, 2026 0
Weekly CVE report June 2026 1909 new vulnerabilities CISA KEV CVE-2026-20230 exploited
  • Weekly Recap

Weekly CVE Report Logs 1,909 New Vulnerabilities and 6 Exploited Flaws

Do Son June 29, 2026 0

Tech News

Google AI Overviews traffic decline chart and publisher organic search impact
  • Technology

Google AI Overviews Traffic Loss Drives Publisher Backlash

Do Son July 27, 2026 0
Intel hyper-threading return in 2028 Coral Rapids Xeon server CPUs announced by CEO Lip-Bu Tan to reclaim data center CPU market share
  • Technology

Intel to Bring Back Hyper-Threading in 2028 Coral Rapids Xeon

Do Son July 27, 2026 0
EU preliminary findings accuse TikTok of breaching DSA minor-safety rules over public-by-default accounts and For You algorithmic recommendation
  • Technology

EU Says TikTok Breaches DSA Rules on Protecting Minors’ Privacy

Do Son July 27, 2026 0
Qualcomm chip price increase notification letter to OEM customers
  • Technology

Qualcomm Announces Double-Digit Chip Price Increase

Do Son July 27, 2026 0

Vulnerability

CVE-2026-16812 VeloCloud command injection exploited in the wild affecting VeloCloud Orchestrator
  • Vulnerability Report

CVE-2026-16812: VeloCloud Orchestrator OS Command Injection (CVSS 10) Exploited in the Wild

Do Son July 27, 2026 0
Plane authorization bypass CVE-2026-15342 exposing multi-tenant workspace assets
  • Vulnerability Report

Unpatched Plane Authorization Bypass CVE-2026-15342 Exposes Other Workspaces

Do Son July 27, 2026 0
Apache Fory vulnerabilities in Java, C++, and Rust deserialization fixed in version 1.4.0
  • Vulnerability Report

Apache Fory Patches Four Deserialization Flaws Across Java, C++, and Rust

Do Son July 27, 2026 0
CVE-2026-61511 vBulletin preauth RCE proof-of-concept abusing the runMaths eval for remote code execution
  • Vulnerability Report

CVE-2026-61511: vBulletin Preauth RCE with Public PoC Disclosed

Do Son July 27, 2026 0

Cyber Security

VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub Operation STANDOFF infrastructure map showing a Russian-speaking threat group hiding C2 servers behind GitHub redirects
  • Cybercriminals

VMRay Exposes Operation STANDOFF, a Russian-Speaking Intrusion Campaign Hidden Behind GitHub

July 27, 2026 0
Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants Kimsuky Gomir variant attack chain showing the DriveTroy backdoor using Google Drive as a covert C2 channel
  • Cybercriminals

Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants

July 27, 2026 0
TELESHIM Malware Targets Middle East Governments Through Telegram SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Cybercriminals

TELESHIM Malware Targets Middle East Governments Through Telegram

July 27, 2026 0
APT42 TAMECAT Malware Grows with AI-Assisted Phishing Tamecat
  • Cybercriminals

APT42 TAMECAT Malware Grows with AI-Assisted Phishing

July 27, 2026 0

Malware Alert

RenPy Loader Spreads Amatera Stealer Through Fake Game Downloads RenPy Loader infection chain in fake game installers using MSBuild and EtherHiding to deploy Amatera Stealer
  • Malware

RenPy Loader Spreads Amatera Stealer Through Fake Game Downloads

July 27, 2026 0
Cruciferra Crypter Service Cloaks RATs and Infostealers for Many Threat Actors Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Malware

Cruciferra Crypter Service Cloaks RATs and Infostealers for Many Threat Actors

July 27, 2026 0
NadMesh Botnet Targets AI Services and Cloud Environments NadMesh botnet targeting cloud systems and presenting an AI infrastructure threat.
  • Malware

NadMesh Botnet Targets AI Services and Cloud Environments

July 24, 2026 0
TAG-150 Attack Chain Deploys DenoRAT Malware hack
  • Malware

TAG-150 Attack Chain Deploys DenoRAT Malware

July 24, 2026 0

Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error Claude AI shared conversation links indexed in Google search due to a robots.txt and X-Robots-Tag misconfiguration exposing private chat content
  • Data Leak

Claude AI Shared Chats Surfaced in Google Over a Config Error

July 27, 2026 0
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

July 18, 2026 0
Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It Grok Build repository upload controversy, SpaceXAI privacy mode response
  • Data Leak

Grok Build Repository Upload Scandal: Researcher Confirms Privacy Mode Cannot Stop It

July 14, 2026 0
The Grok Build Privacy Controversy: Unauthorized Repository Uploads Grok Build privacy settings interface showing how to disable automated repository data uploads
  • Data Leak

The Grok Build Privacy Controversy: Unauthorized Repository Uploads

July 14, 2026 0
Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards Joe_Channel_Awards_2_1785157894FHsYNffOlZ
  • Press Release

Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards

cybernewswire July 27, 2026 0
Read More Read more about Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards
Samsung One UI 9 Locks the Phone Forever After 13 Wrong Codes Samsung One UI 9 lockscreen security on Android 17 permanently locks the device after 13 failed passcode attempts, requiring a factory reset
  • Android

Samsung One UI 9 Locks the Phone Forever After 13 Wrong Codes

Do Son July 27, 2026 0
Read More Read more about Samsung One UI 9 Locks the Phone Forever After 13 Wrong Codes
Windows 11 File Explorer Now Deletes Large Fragmented Files Faster Windows 11 File Explorer faster deletion of large fragmented files in Build 26300.8935, a rare NTFS performance win from Microsoft
  • Windows

Windows 11 File Explorer Now Deletes Large Fragmented Files Faster

Do Son July 27, 2026 0
Read More Read more about Windows 11 File Explorer Now Deletes Large Fragmented Files Faster
Weekly Threat Intelligence Briefing: Late July 2026 CISA flagged 6 actively exploited CVEs this week, from a SharePoint RCE to a Check Point auth bypass. See the full CISA KEV list and patch fast.
  • Weekly Recap

Weekly Threat Intelligence Briefing: Late July 2026

Do Son July 27, 2026 0
Read More Read more about Weekly Threat Intelligence Briefing: Late July 2026
CVE-2026-49176 Windows WalletService Elevation of Privilege Flaw Gets Public PoC Exploit CVE-2026-49176 Windows WalletService elevation of privilege exploit escalating to SYSTEM
  • Vulnerability Report

CVE-2026-49176 Windows WalletService Elevation of Privilege Flaw Gets Public PoC Exploit

Do Son July 27, 2026 0
Read More Read more about CVE-2026-49176 Windows WalletService Elevation of Privilege Flaw Gets Public PoC Exploit
Microsoft Fortifies KMS Activation with TPM Hardware Trust Microsoft China AI business growth via OpenAI and ByteDance partnership
  • Technology

Microsoft Fortifies KMS Activation with TPM Hardware Trust

Do Son July 26, 2026 0
Read More Read more about Microsoft Fortifies KMS Activation with TPM Hardware Trust
Google Weighs Restricting Local ADB, Threatening Shizuku on Android Google proposal to restrict local ADB loopback connections on Android, potentially breaking Shizuku and aShell no-root tools over security concerns
  • Android

Google Weighs Restricting Local ADB, Threatening Shizuku on Android

Do Son July 26, 2026 0
Read More Read more about Google Weighs Restricting Local ADB, Threatening Shizuku on Android
India Orders GitHub to Block BitChat Repository Within 3 Hours India orders GitHub to block the BitChat repository, targeting Jack Dorsey decentralized Bluetooth mesh messaging app used without internet
  • Technology

India Orders GitHub to Block BitChat Repository Within 3 Hours

Do Son July 26, 2026 0
Read More Read more about India Orders GitHub to Block BitChat Repository Within 3 Hours
Google Pixel 11 Price Increase Confirmed Amid Memory Cost Surge Google Pixel 11 lineup price increase analysis and memory cost impact
  • Android

Google Pixel 11 Price Increase Confirmed Amid Memory Cost Surge

Do Son July 26, 2026 0
Read More Read more about Google Pixel 11 Price Increase Confirmed Amid Memory Cost Surge
Meta Seller App Brings Pro Tools and Meta AI to Marketplace Meta Seller App dashboard for Facebook Marketplace showing Meta AI listing, unified inbox, inventory management, and performance analytics
  • Technology

Meta Seller App Brings Pro Tools and Meta AI to Marketplace

Do Son July 25, 2026 0
Read More Read more about Meta Seller App Brings Pro Tools and Meta AI to Marketplace
25 Tech Firms Sign Open-Weight AI Letter Backing US Leadership Open-weight AI open letter signed by NVIDIA, Microsoft, and Meta defending open models for US AI leadership amid US-China competition
  • Technology

25 Tech Firms Sign Open-Weight AI Letter Backing US Leadership

Do Son July 25, 2026 0
Read More Read more about 25 Tech Firms Sign Open-Weight AI Letter Backing US Leadership
Facebook Verified Adds Free Real-Person Badge to Fight AI Fakes Facebook Verified real-person badge verification using a face-scan selfie to confirm a genuine human user against AI-generated fake accounts
  • Technology

Facebook Verified Adds Free Real-Person Badge to Fight AI Fakes

Do Son July 25, 2026 0
Read More Read more about Facebook Verified Adds Free Real-Person Badge to Fight AI Fakes
Anthropic Claude Opus 5 Rivals Fable 5 at Half the Price Anthropic Claude Opus 5 model overview showing knowledge work, coding gains, relaxed safety classifiers, and the new effort setting
  • Technology

Anthropic Claude Opus 5 Rivals Fable 5 at Half the Price

Do Son July 25, 2026 0
Read More Read more about Anthropic Claude Opus 5 Rivals Fable 5 at Half the Price
FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public FastJson RCE vulnerability CVE-2026-16723 remote code execution attacks by industry pie chart across financial services and healthcare
  • Vulnerability Report

FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public

Do Son July 25, 2026 0
Read More Read more about FastJson RCE CVE-2026-16723 Exploited in the Wild as Details and PoC Exploit Code Go Public
OTA Firmware Updates: The Hardest Part of Shipping an IoT Product tech-security
  • Technique

OTA Firmware Updates: The Hardest Part of Shipping an IoT Product

Do Son July 25, 2026 0
Read More Read more about OTA Firmware Updates: The Hardest Part of Shipping an IoT Product
CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM Windows AppResolver LPE CVE-2026-50454 UAC bypass chain to a SYSTEM shell and Elevation of Privilege
  • Vulnerability Report

CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM

Do Son July 24, 2026 0
Read More Read more about CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM
Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic Konnectivity vulnerability CVE-2026-16242 letting an unauthenticated agent join the routing pool and intercept control-plane traffic
  • Vulnerability Report

Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic

Do Son July 24, 2026 0
Read More Read more about Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic
Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8 Tycon authentication bypass CVE-2026-61884 in TPDIN-Monitor-WEB2 rated CVSS 9.8
  • Vulnerability Report

Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8

Do Son July 24, 2026 0
Read More Read more about Tycon Power Monitor Authentication Bypass CVE-2026-61884 Rated CVSS 9.8
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments GoSerpent backdoor cyber espionage attack chain against Southeast Asian government networks
  • Cyber Security

GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments

Do Son July 24, 2026 0
Read More Read more about GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers ChatGPT_Image_Jul_24_2026_11_58_11_AM_1784887099UOeFRyUzMz
  • Press Release

Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers

cybernewswire July 24, 2026 0
Read More Read more about Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Google Gemini Spark Expands Access to Pro and Ultra Subscribers Google Gemini Spark agentic AI assistant running in the Google Workspace sidebar, drafting Gmail replies and Google Docs reports
  • Technology

Google Gemini Spark Expands Access to Pro and Ultra Subscribers

Do Son July 24, 2026 0
Read More Read more about Google Gemini Spark Expands Access to Pro and Ultra Subscribers
Google DMA Fine of €890 Million Lands in Brussels Google DMA fine of 890 million euros from the European Commission over search self-preferencing and Play Store steering restrictions
  • Technology

Google DMA Fine of €890 Million Lands in Brussels

Do Son July 24, 2026 0
Read More Read more about Google DMA Fine of €890 Million Lands in Brussels
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intel📅 Updated: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-59550CVSS 9.3
    Unauthenticated SQL Injection in AWP Classifieds
  • CVE-2026-59549CVSS 9.3
    Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
  • CVE-2026-59538CVSS 9.3
    Unauthenticated SQL Injection in GamiPress
  • CVE-2026-59533CVSS 9.3
    Unauthenticated SQL Injection in Relevanssi Light
  • CVE-2026-59527CVSS 9.3
    Unauthenticated SQL Injection in MapSVG
  • CVE-2026-61511CVSS 9.8
    vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection...
  • CVE-2026-64530CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api:...
  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-64523CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.