Skip to content
June 22, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button

LATEST NEWS

QNAP QuMagie vulnerabilities allowing unauthenticated information disclosure of media files in QSA-26-35
  • Vulnerability Report

QNAP Patches QuMagie Flaws Exposing Private Media Files

Do Son June 22, 2026 0
Apache Doris SQL injection diagram showing CVE-2025-66336 metadata query path bypass
  • Vulnerability Report

Apache Doris SQL Injection Vulnerability CVE-2025-66336

Do Son June 22, 2026 0
undici vulnerabilities in the Node.js HTTP client affecting a package with 133M weekly downloads
  • Vulnerability Report

Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads

Do Son June 22, 2026 0
Avo authorization bypass CVE-2026-55518 enabling privilege escalation in a Ruby on Rails admin panel
  • Vulnerability Report

Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps

Do Son June 22, 2026 0
pgAdmin 4 vulnerabilities CVE-2026-12046 stored XSS and RCE in PostgreSQL admin tool
  • Vulnerability Report

Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi

Do Son June 22, 2026 0

Tech News

Microsoft Edge Google account login interface and synchronization settings Browser Choice Alliance letter Microsoft Edge cleartext credentials memory dump Microsoft Edge auto-startup Microsoft Edge Collections sunset, export Edge Collections CSV Edge IE Mode Zero-Day, Chakra Exploit Windows Search, Microsoft Edge AI video translation, Edge browser Microsoft Editor, Edge Edge Developer tools Windows 10 ESU, Microsoft Edge Microsoft Edge, FCP Optimization CVE-2023-36735 Edge, AI Search
  • Technology

Microsoft Edge Google Account Login Coming Soon

Do Son June 22, 2026 0
reCAPTCHA hand gesture verification scanning process and biometric CAPTCHA security reCAPTCHA Data
  • Technology

Google Tests reCAPTCHA Hand Gesture Verification

Do Son June 22, 2026 0
Gemini CLI deprecation notice as Google moves developers to the Antigravity CLI terminal tool Google Antigravity 2.0 release
  • Technology

Gemini CLI Deprecation: Google Moves Developers to Antigravity CLI

Do Son June 22, 2026 0
Google Calendar custom colors RGB picker event organization
  • Technology

Google Calendar Adds 200 Custom Colors and a Full RGB Picker

Do Son June 19, 2026 0

Vulnerability

FreeBSD privilege escalation CVE-2026-49413, Linuxulator vulnerability
  • Vulnerability

FreeBSD Privilege Escalation Flaw CVE-2026-49413 Hits the Linuxulator

Do Son June 15, 2026 0
CVE-2022-35951 Redis DarkReplica exploit CVE-2026-23631 public disclosure
  • Vulnerability

Redis DarkReplica Exploit: Full PoC Code and Technical Details Released

Do Son June 8, 2026 0
Mautic security vulnerabilities critical RCE flaws
  • Vulnerability

Critical RCE Flaws Fixed in Mautic Marketing Platform

Do Son June 4, 2026 0
Drupal SQL injection exploit wild exploit PoC
  • Vulnerability

Drupal SQL Injection Exploit: Critical Flaw Exploited in the Wild with Public PoC

Do Son June 3, 2026 0

Cyber Security

FBI Warns of Traffic Distribution Systems in Cyber Attacks Diagram showing how cyber criminals use traffic distribution systems to redirect users to malicious websites.
  • Cybercriminals

FBI Warns of Traffic Distribution Systems in Cyber Attacks

June 22, 2026 0
Google Uncovers UNC6508 Cyber Espionage Campaign Diagram showing UNC6508 cyber espionage attack flow and INFINITERED malware.
  • Cybercriminals

Google Uncovers UNC6508 Cyber Espionage Campaign

June 22, 2026 0
Critical ArcGIS Account Recovery Targeted in Active Attacks Illustration of ArcGIS Account Recovery attacks highlighted in the latest security bulletin
  • Cybercriminals

Critical ArcGIS Account Recovery Targeted in Active Attacks

June 20, 2026 0
Device Code Phishing: Microsoft 365 Attack That Steals No Passwords hack
  • Cybercriminals

Device Code Phishing: Microsoft 365 Attack That Steals No Passwords

June 20, 2026 0

Malware Alert

Malicious Steam Wallpapers Spread Malware to Gamers Malicious Steam wallpapers targeting the Wallpaper Engine app
  • Malware

Malicious Steam Wallpapers Spread Malware to Gamers

June 22, 2026 0
SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control security-de
  • Malware

SHEETCREEP Malware Abuses Google Sheets API for Command-and-Control

June 22, 2026 0
DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays digital-hacker
  • Malware

DragonForce Hides Backdoor C2 Inside Microsoft Teams TURN Relays

June 22, 2026 0
ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites hacker-security
  • Malware

ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites

June 22, 2026 0

Data Leak

Novo Nordisk Breach Exposes AI Models and Patient Data Novo Nordisk data breach Novo Nordisk hack, AI training data theft, clinical trial data leak
  • Data Leak

Novo Nordisk Breach Exposes AI Models and Patient Data

June 16, 2026 0
Uncanny Automator Breach: Backdoored Plugin Build Hit WordPress Sites Uncanny Automator breach WordPress supply chain attack, plugin backdoor, data breach
  • Data Leak

Uncanny Automator Breach: Backdoored Plugin Build Hit WordPress Sites

June 15, 2026 0
Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AI Siri AI system prompt Siri AI iOS 27
  • Data Leak

Architectural Exposure: Developers Extract Apple’s Subterranean Core Prompts for Siri AI

June 10, 2026 0
Cybercriminals Deploy Malicious AI Extensions to Steal Private Chat Data malicious AI extensions browser data exfiltration
  • Data Leak
  • Malware

Cybercriminals Deploy Malicious AI Extensions to Steal Private Chat Data

June 10, 2026 0
Pre-emptive AI cybersecurity: what it takes to prioritize risk before attackers act Salesforce vulnerability CVE-2025-9844 Salt Typhoon cyberattack
  • Technique

Pre-emptive AI cybersecurity: what it takes to prioritize risk before attackers act

Joe Pettit June 22, 2026 0
There is no shortage of vulnerabilities for security teams to deal with. FIRST forecasts up to 59,000...
Read More Read more about Pre-emptive AI cybersecurity: what it takes to prioritize risk before attackers act
Apache Doris SQL Injection Vulnerability CVE-2025-66336 Apache Doris SQL injection diagram showing CVE-2025-66336 metadata query path bypass
  • Vulnerability Report

Apache Doris SQL Injection Vulnerability CVE-2025-66336

Do Son June 22, 2026 0
TL;DR Apache Doris version 0.6.1 patches a severe security flaw in its MCP Server. Specifically, an Apache...
Read More Read more about Apache Doris SQL Injection Vulnerability CVE-2025-66336
Microsoft Details Support Lifecycle for Windows 11 Version 26H2 Windows 11 version 26H2 support lifecycle and deployment roadmap for enterprise environments Windows 11 update anomaly Windows 11 context menu Windows 11 KB5089549 update error 0x800f0922 Windows 11 taskbar relocation
  • Windows

Microsoft Details Support Lifecycle for Windows 11 Version 26H2

Do Son June 22, 2026 0
Microsoft recently unveiled the early preview of Windows 11 version 26H2. The official release will likely debut...
Read More Read more about Microsoft Details Support Lifecycle for Windows 11 Version 26H2
Windows Recycle Bin Bug Surfaces After the June 2026 Update Windows Recycle Bin bug showing an internal $Rxxxxx filename in the delete confirmation dialog after the June 2026 update
  • Windows

Windows Recycle Bin Bug Surfaces After the June 2026 Update

Do Son June 22, 2026 0
Microsoft released its June 2026 Patch Tuesday updates on June 9. Within days, users began reporting odd...
Read More Read more about Windows Recycle Bin Bug Surfaces After the June 2026 Update
2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026) Weekly CVE report dashboard showing 2,060 new vulnerabilities and 4 actively exploited CVEs in CISA KEV
  • Weekly Recap

2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)

Do Son June 22, 2026 0
TL;DR This weekly CVE report covers 2,060 new vulnerabilities disclosed between June 15 and 21, 2026. Among...
Read More Read more about 2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)
Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads undici vulnerabilities in the Node.js HTTP client affecting a package with 133M weekly downloads
  • Vulnerability Report

Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads

Do Son June 22, 2026 0
TL;DR Maintainers have disclosed four undici vulnerabilities in the widely used Node.js HTTP client. The package draws...
Read More Read more about Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
9.6 Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps Avo authorization bypass CVE-2026-55518 enabling privilege escalation in a Ruby on Rails admin panel
  • Vulnerability Report

9.6 Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps

Do Son June 22, 2026 0
At a glance CVE CVE-2026-55518 CVSS 9.6 (Critical) Product / vendor Avo admin panel framework / Avo...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.6</span> Avo Flaw CVE-2026-55518 Enables Privilege Escalation in Rails Apps
Critical Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi pgAdmin 4 vulnerabilities CVE-2026-12046 stored XSS and RCE in PostgreSQL admin tool
  • Vulnerability Report

Critical Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi

Do Son June 22, 2026 0
Database administrators have urgent patching to do. The pgAdmin team has fixed three critical pgAdmin 4 vulnerabilities,...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">Critical</span> Three Critical pgAdmin 4 Vulnerabilities Patched: XSS, Auth Bypass, and AI Assistant SQLi
Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257 FreeBSD kTLS vulnerability CVE-2026-45257 public PoC exploit enabling local privilege escalation to root
  • Vulnerability Report

Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257

Do Son June 22, 2026 0
TL;DR FreeBSD has patched a kernel flaw, CVE-2026-45257, that hands local root to any unprivileged user. This...
Read More Read more about Public Exploit Released for FreeBSD kTLS Local Root Flaw CVE-2026-45257
QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices QNAP NAS vulnerabilities in QTS and QuTS hero firmware including command injection flaws from QSA-26-10
  • Vulnerability Report

QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices

Do Son June 21, 2026 0
TL;DR QNAP has patched 14 vulnerabilities affecting its QTS, QuTS hero, QuTS cloud, and QVP systems. The...
Read More Read more about QNAP Patches 14 Vulnerabilities in QTS, QuTS hero, and QVP Devices
NPM Package Tests AI Malware Scanner Evasion hacker-security
  • Malware

NPM Package Tests AI Malware Scanner Evasion

Do Son June 21, 2026 0
At a glance Malware Family: shai_hulululud (Protestware/Testing) Threat Actor: Unknown (Suspected researcher or troll) Targets: AI-based malware...
Read More Read more about NPM Package Tests AI Malware Scanner Evasion
GlassWASM Malware Hidden in Open VSX Extensions code
  • Malware

GlassWASM Malware Hidden in Open VSX Extensions

Do Son June 20, 2026 0
Security researchers have uncovered GlassWASM malware, a stealthy threat hiding inside trojanized Visual Studio Code extensions. Socket’s...
Read More Read more about GlassWASM Malware Hidden in Open VSX Extensions
Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections fi_5_e3ed09ff94_1_1781877042S8sPtX4e3f
  • Press Release

Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections

cybernewswire June 19, 2026 0
Luxembourg, Luxembourg, 19th June 2026, CyberNewswire
Read More Read more about Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections
eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks ChatGPT_Image_12__2026__14_15_31_1781266554PR1huQkj8c
  • Press Release

eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks

cybernewswire June 19, 2026 0
New York, USA, 19th June 2026, CyberNewswire
Read More Read more about eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks
UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes UNC1151 Gmail phishing fake Google login page stealing 2FA codes by Ghostwriter
  • Cybercriminals

UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes

Do Son June 19, 2026 0
Poland’s national cyber team has sounded the alarm. A fresh UNC1151 Gmail phishing campaign is hunting credentials...
Read More Read more about UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem malware
  • Malware

Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem

Do Son June 19, 2026 0
A two-year look at a shared ransomware ecosystem IBM X-Force has released long-term research into the Interlock...
Read More Read more about Interlock and Rhysida Ransomware: IBM X-Force Maps a Shared Ecosystem
9.1 1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1) Avada Builder vulnerability CVE-2026-8713 unauthenticated arbitrary file deletion in WordPress
  • Vulnerability Report

9.1 1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)

Do Son June 19, 2026 0
  Around one million WordPress sites just got an urgent reason to patch. A critical Avada Builder...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.1</span> 1M WordPress Sites at Risk: Critical Unauthenticated Arbitrary File Deletion in Avada Builder (CVSS 9.1)
APT37 NarwhalRAT Malware: A Python Backdoor Threat APT37 NarwhalRAT malware diagram
  • Malware

APT37 NarwhalRAT Malware: A Python Backdoor Threat

Do Son June 19, 2026 0
Genians Security Center recently confirmed the continued distribution of compiled Python-based malware. This threat targets Korean users...
Read More Read more about APT37 NarwhalRAT Malware: A Python Backdoor Threat
Claude Code Quota Reset Follows Morning Outage Claude Code quota reset notification displayed on a developer workstation screen
  • Technology

Claude Code Quota Reset Follows Morning Outage

Do Son June 19, 2026 0
On the morning of June 19, a server anomaly within Claude Code erroneously obscured users’ weekly quotas....
Read More Read more about Claude Code Quota Reset Follows Morning Outage
Chrome Extension Vulnerabilities: Millions at Risk Illustration of Chrome extension vulnerabilities and hacker exploiting MaXSS and Spyder flaws
  • Vulnerability Report

Chrome Extension Vulnerabilities: Millions at Risk

Do Son June 19, 2026 0
Rebora Security Research recently uncovered severe Chrome extension vulnerabilities. These critical flaws impact two widely used AI...
Read More Read more about Chrome Extension Vulnerabilities: Millions at Risk
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-28381CVSS 9.6
    The Snowflake datasource allows for GET/PUT commands, which can allow any user...
  • CVE-2026-10561CVSS 10.0
    IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an...
  • CVE-2026-7664CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access...
  • CVE-2026-56395CVSS 9.6
    SiYuan before v3.6.1 fails to sanitize package metadata and README content in...
  • CVE-2026-56265CVSS 9.8
    Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded...
  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
Powered by CVE WATCHTOWER

🚨 Active Exploits in the Wild

  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-10735
    Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated attackers to...
  • CVE-2026-20262CVSS 6.5
    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,...
  • CVE-2026-54420CVSS 8.5
    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a...
  • CVE-2026-53435CVSS 8.8
    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize...
  • CVE-2026-10795CVSS 8.1
    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions...
  • CVE-2026-11645
    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
  • CVE-2026-50751CVSS 9.3
    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows...
  • CVE-2026-20245CVSS 7.8
    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local...
Powered by CVE Watchtower

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.