Skip to content
September 23, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Main Types of Malware and Tools to Protect Yourself Online Better
  • Technique

Main Types of Malware and Tools to Protect Yourself Online Better

Do Son December 8, 2022 3 minutes read
tech-security

Today technology is an inevitable part of modern life. Computers changed how we receive information, communicate, and impact spending habits. According to statistics, more than a quarter of the world’s population shop online.

It doesn’t take Sherlock Holmes to correlate online financial transactions with increased cybercrime rates. Currently, the Internet is plagued by cybercrime, and it’s not improving. It is getting worse. In this article, you will find the most common types of malware in 2022, with tools to protect your online valuables.

Phishing

Phishing is an old hacking and social engineering technique dating back to the early 90s. In 2021, more than 80% of reported security issues involved Phishing. Most often, Phishing is carried out via fraudulent emails. Cybercriminals send thousands of emails asking to confirm banking details, call a specific number, or click on an infectious link.

Cybercriminals successfully exploited the Covid-19 crisis to improve email legitimacy and pose a sense of urgency regarding healthcare. Social networks do not help by providing hackers with personalized data to use in Phishing scams.

Paradoxically, the best defense against Phishing does not involve software. Cybersecurity training focused on identifying Phishing scams is the first line of defense. Participants will learn to identify fraudulent emails, infectious backlinks, most common Phishing tactics, mobile device security, and more. Phishing heavily relies on human error. If people become more aware of online dangers, they will be less likely to fall victim to social engineering.

Ransomware

In 2022, ransomware is by far the most damaging cyber threat. In the last couple of years, ransomware managed to paralyze Ireland’s healthcare sector, halt U.S. Colonial Pipeline operations, breach Baltimore’s government servers, and more. These relatively recent attacks are against crucial public sectors. However, the most prominent WannaCry ransomware attack infected over 200,000 devices running Microsoft Windows, whether a business or a casual Internet user.

Ransomware is frequently delivered via Phishing scams, so the discussed Phishing protection training applies here as well. However, it is essential to back up data regularly. Ransomware encrypts data on a device and then blackmails the user for ransom. You can restore the data and report the incident to the local authorities if you have a secure and recent backup.

Regarding backups, apply the golden 3-2-1 rule. Have one primary backup and two copies of your data, and save them on two different media with one backup file offsite and offline. This will make ransomware attacks less likely to damage your data.

Online Account Security

One of the most common threats casual Internet users face is the security of their online accounts. Social media accounts store a lot of private information, Steam accounts can be worth thousands of dollars, and Instagram accounts are a primary source of income for many people. In 2021, a spike in Credential Stuffing Attacks attempted to take over named accounts and extract valuable information.

The best way to protect your online accounts is to improve password management habits. First, choose a reliable password manager to store dozens of unique and strong passwords. Avoid using the same password twice, and don’t use easy-to-guess passwords. Whenever possible, enable two or multi-factor authentication. These easy steps will protect against most password-hacking attempts.

This list is by no means exhaustive, but it focuses on the most common cyber threats in 2022. Discussed software and cybersecurity training will significantly decrease the chances of getting hacked because most people still don’t use any online protection.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
  • CVE-2026-58138CVSS 9.8
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute...
    Admin intel📅 Updated: Sep 20, 2026
  • CVE-2026-86124CVSS 9.8
    AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and...
    Admin intel📅 Updated: Sep 19, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-84082CVSS 9.8
    IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper...
    📅 Updated: Sep 23, 2026
  • CVE-2026-84064CVSS 9.9
    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to...
    📅 Updated: Sep 23, 2026
  • CVE-2026-82967CVSS 9.8
    IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to...
    📅 Updated: Sep 23, 2026
  • CVE-2026-82340CVSS 9.8
    IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the...
    📅 Updated: Sep 23, 2026
  • CVE-2026-82000CVSS 9.6
    Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in...
    📅 Updated: Sep 23, 2026
  • CVE-2026-81995CVSS 9.1
    Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary...
    📅 Updated: Sep 23, 2026
  • CVE-2026-81657CVSS 9.8
    IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system...
    📅 Updated: Sep 23, 2026
  • CVE-2026-80442CVSS 9.9
    IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality....
    📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.