Skip to content
July 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Hackers Exploit Critical BeyondTrust Flaw to Deploy VShell and SparkRAT Across Multiple Sectors BeyondTrust Vulnerability CVE-2026-1731 UPBIT $369M Hack CVE-2024-55591 Ivanti VPN vulnerability, cyber espionage
  • Malware
  • Vulnerability Report

Hackers Exploit Critical BeyondTrust Flaw to Deploy VShell and SparkRAT Across Multiple Sectors

Do Son February 23, 2026 0
Read More Read more about Hackers Exploit Critical BeyondTrust Flaw to Deploy VShell and SparkRAT Across Multiple Sectors
Poisoned Pages: Critical Calibre Path Traversal Flaws Expose Readers to RCE Calibre Vulnerability CVE-2026-26065 Calibre RCE, FB2 File Flaw
  • Vulnerability Report

Poisoned Pages: Critical Calibre Path Traversal Flaws Expose Readers to RCE

Do Son February 23, 2026 0
Read More Read more about Poisoned Pages: Critical Calibre Path Traversal Flaws Expose Readers to RCE
The CAPTCHA Trap: How a Fake “ClickFix” Prompt Unleashed Latrodectus & Supper Malware ClickFix CAPTCHA Latrodectus Malware
  • Malware

The CAPTCHA Trap: How a Fake “ClickFix” Prompt Unleashed Latrodectus & Supper Malware

Do Son February 23, 2026 0
Read More Read more about The CAPTCHA Trap: How a Fake “ClickFix” Prompt Unleashed Latrodectus & Supper Malware
The Invisible Backdoor: AI Exposes Malicious OAuth Apps Hiding in Microsoft Entra ID Malicious OAuth Apps Entra ID Homoglyph Attack
  • Cybercriminals

The Invisible Backdoor: AI Exposes Malicious OAuth Apps Hiding in Microsoft Entra ID

Do Son February 23, 2026 0
Read More Read more about The Invisible Backdoor: AI Exposes Malicious OAuth Apps Hiding in Microsoft Entra ID
The Startup Stealer: How AI and Discord Powered the Arkanix MaaS Operation Arkanix Stealer Malware-as-a-Service (MaaS)
  • Malware

The Startup Stealer: How AI and Discord Powered the Arkanix MaaS Operation

Do Son February 23, 2026 0
Read More Read more about The Startup Stealer: How AI and Discord Powered the Arkanix MaaS Operation
Cash Out: FBI Warns of $20M ATM ‘Jackpotting’ Surge Driven by Ploutus Malware ATM Jackpotting Ploutus Malware
  • Malware

Cash Out: FBI Warns of $20M ATM ‘Jackpotting’ Surge Driven by Ploutus Malware

Do Son February 23, 2026 0
Read More Read more about Cash Out: FBI Warns of $20M ATM ‘Jackpotting’ Surge Driven by Ploutus Malware
The ‘ClickFix’ Trap: GrayCharlie Hijacks US Law Firms to Deploy NetSupport RAT GrayCharlie Malware ClickFix Attack
  • Malware

The ‘ClickFix’ Trap: GrayCharlie Hijacks US Law Firms to Deploy NetSupport RAT

Do Son February 23, 2026 0
Read More Read more about The ‘ClickFix’ Trap: GrayCharlie Hijacks US Law Firms to Deploy NetSupport RAT
Sandbox Bypassed: jsPDF Flaw Exposes Millions to Object Injection CVE-2026-31938 jsPDF Vulnerability CVE-2026-25755 jsPDF, CVE-2025-68428 jsPDF Vulnerability CVE-2026-24133
  • Vulnerability Report

Sandbox Bypassed: jsPDF Flaw Exposes Millions to Object Injection

Do Son February 23, 2026 0
Read More Read more about Sandbox Bypassed: jsPDF Flaw Exposes Millions to Object Injection
The Fake IT Threat: “TrustConnect” Malware-as-a-Service Masquerades as Legitimate RMM Software TrustConnect Malware Fake RMM MaaS
  • Cybercriminals

The Fake IT Threat: “TrustConnect” Malware-as-a-Service Masquerades as Legitimate RMM Software

Do Son February 23, 2026 0
Read More Read more about The Fake IT Threat: “TrustConnect” Malware-as-a-Service Masquerades as Legitimate RMM Software
Weaponizing Windows Errors: PoC Dropped for Critical Privilege Escalation Flaw in WER Service C Windows SecureBoot folder KB5089549 Windows 11 BSOD Microsoft Windows, Rust programming WINS Service Deprecation Windows Server DNS Migration Windows Driver Standard OEM Kernel Privileges Windows Agentic OS Task Manager Bug, Windows 11 Performance Windows 11, Microsoft, WinRE, Update Bug, Tech Support Windows 11 OOBE, Microsoft Account Mandatory Windows 11, SSD failures Windows 11 Recovery, Black Screen of Death Windows 11 Update Issue, KB5062324 Windows 11, Indicator Bar
  • Vulnerability

Weaponizing Windows Errors: PoC Dropped for Critical Privilege Escalation Flaw in WER Service

Do Son February 23, 2026 0
Read More Read more about Weaponizing Windows Errors: PoC Dropped for Critical Privilege Escalation Flaw in WER Service
Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake ‘Coretax’ Apps Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cybercriminals

Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake ‘Coretax’ Apps

Do Son February 23, 2026 0
Read More Read more about Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake ‘Coretax’ Apps
Streaming Fraud: “Massiv” Android Trojan Uses Fake IPTV Apps for Complete Device Takeover Massiv Android Malware IPTV Banking Trojan
  • Malware

Streaming Fraud: “Massiv” Android Trojan Uses Fake IPTV Apps for Complete Device Takeover

Do Son February 23, 2026 0
Read More Read more about Streaming Fraud: “Massiv” Android Trojan Uses Fake IPTV Apps for Complete Device Takeover
Maintaining the critical minimum through energy monitoring during storm disruptions CVE-2024-31070 & CVE-2024-36491
  • Technique

Maintaining the critical minimum through energy monitoring during storm disruptions

Do Son February 21, 2026 0
Read More Read more about Maintaining the critical minimum through energy monitoring during storm disruptions
Inside the ‘Upworksell’ Syndicate: Hacker Gets 60 Months for Funneling US Tech Jobs to North Korea Romanian hacker sentenced identity theft conviction Pig-Butchering Crackdown Operation Level Up Oleksandr Didenko North Korean IT Workers Coinbase TaskUs insider breach, Hyderabad police Coinbase arrest Scattered Spider, Cybercrime Scattered Spider group
  • Cybercriminals

Inside the ‘Upworksell’ Syndicate: Hacker Gets 60 Months for Funneling US Tech Jobs to North Korea

Do Son February 20, 2026 0
Read More Read more about Inside the ‘Upworksell’ Syndicate: Hacker Gets 60 Months for Funneling US Tech Jobs to North Korea
Exploited in the Wild & PoC Disclosed: Emergency Chrome Zero-Day (CVE-2026-2441) Patched Chrome security update exploit in the wild Chrome Zero-Day CVE-2026-3909 Chrome Zero-Day PoC CVE-2026-2441 Chrome Zero-Day CVE-2026-2441 Chrome Zero-Day, Active Exploitation CVE-2025-10585 Chrome vulnerability, zero-day exploit CVE-2025-6558 Chrome Zero-Day, V8 Vulnerability Chrome Zero-Day, Security Update
  • Vulnerability Report

Exploited in the Wild & PoC Disclosed: Emergency Chrome Zero-Day (CVE-2026-2441) Patched

Do Son February 20, 2026 0
Read More Read more about Exploited in the Wild & PoC Disclosed: Emergency Chrome Zero-Day (CVE-2026-2441) Patched
Bypassing the Bouncer: Apache Tomcat Patches SNI & Legacy Protocol Flaws Tomcat Security Update CVE-2026-24733 CVE-2023-41081 -CVE-2024-56337
  • Vulnerability Report

Bypassing the Bouncer: Apache Tomcat Patches SNI & Legacy Protocol Flaws

Do Son February 20, 2026 0
Read More Read more about Bypassing the Bouncer: Apache Tomcat Patches SNI & Legacy Protocol Flaws
The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws VS Code extension vulnerabilities 2026
  • Vulnerability Report

The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws

Do Son February 20, 2026 0
Read More Read more about The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
Google Unveils Gemini 3.1 Pro with 1 Million Tokens for Deep-Data Mastery Google Gemini Pentagon deal Google AI Pro 5TB storage Gemini 3.1 Pro launch
  • Technology

Google Unveils Gemini 3.1 Pro with 1 Million Tokens for Deep-Data Mastery

Do Son February 20, 2026 0
Read More Read more about Google Unveils Gemini 3.1 Pro with 1 Million Tokens for Deep-Data Mastery
Infoblox Exposes Hybrid Malvertising & “Pig Butchering” Scam Hybrid Crypto Scam Pig Butchering Malvertising
  • Cybercriminals

Infoblox Exposes Hybrid Malvertising & “Pig Butchering” Scam

Do Son February 20, 2026 0
Read More Read more about Infoblox Exposes Hybrid Malvertising & “Pig Butchering” Scam
PoC Publicly Disclosed: Critical Grandstream VoIP Flaw (CVSS 9.3) Grants Stealthy Root Access Grandstream VoIP Zero-Day CVE-2026-2329 PoC
  • Vulnerability Report

PoC Publicly Disclosed: Critical Grandstream VoIP Flaw (CVSS 9.3) Grants Stealthy Root Access

Do Son February 20, 2026 0
Read More Read more about PoC Publicly Disclosed: Critical Grandstream VoIP Flaw (CVSS 9.3) Grants Stealthy Root Access
Trojan Routers: Texas Sues TP-Link Over Alleged CCP Surveillance and Supply Chain Deception TP-Link Lawsuit CCP Surveillance
  • Malware

Trojan Routers: Texas Sues TP-Link Over Alleged CCP Surveillance and Supply Chain Deception

Do Son February 20, 2026 0
Read More Read more about Trojan Routers: Texas Sues TP-Link Over Alleged CCP Surveillance and Supply Chain Deception
How to Secure Multiple Bybit Accounts Without Triggering Suspicious Activity Flags CVE-2025-20059
  • Technique

How to Secure Multiple Bybit Accounts Without Triggering Suspicious Activity Flags

Do Son February 20, 2026 0
Read More Read more about How to Secure Multiple Bybit Accounts Without Triggering Suspicious Activity Flags
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.