Skip to content
July 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
The “Illogical” Threat: Why Jensen Huang is Betting $45 Billion That ASICs Can’t Catch NVIDIA NVIDIA acquisition rumors NVIDIA AI Security AI Framework Vulnerabilities Nvidia 595.76 Hotfix NVIDIA Megatron Bridge vulnerability GPU vs ASIC AI battle NVIDIA Driver Vulnerability CVE-2025-33217 NVIDIA biggest TSMC customer 2026, NVIDIA vs Apple TSMC revenue share NVIDIA CUDA Toolkit CVE-2025-33228 Groq NVIDIA licensing deal, Jonathan Ross acquihire 2025 NeMo Code Injection, AI Framework RCE NVIDIA App Privilege Escalation, CVE-2025-23358 NVIDIA Security Update, DLS Vulnerability CVE-2025-23316 NVIDIA NVDebug, vulnerabilities NVIDIA Driver Vulnerabilities, vGPU Security Nvidia Jetson, UEFI Vulnerabilities CVE-2024-0130 - CVE-2024-0136 CVE-2024-0148 NVIDIA Driver Support, Windows 10 EOL
  • Technology

The “Illogical” Threat: Why Jensen Huang is Betting $45 Billion That ASICs Can’t Catch NVIDIA

Do Son February 2, 2026 0
Read More Read more about The “Illogical” Threat: Why Jensen Huang is Betting $45 Billion That ASICs Can’t Catch NVIDIA
Linear Freedom: Apple Overhauls the Mac Store to Unleash Bespoke M5 AI Powerhouses Apple Mac configuration update
  • Technology

Linear Freedom: Apple Overhauls the Mac Store to Unleash Bespoke M5 AI Powerhouses

Do Son February 2, 2026 0
Read More Read more about Linear Freedom: Apple Overhauls the Mac Store to Unleash Bespoke M5 AI Powerhouses
Notepad++ Hijacked: State-Sponsored Actors Poisoned Updates for Months FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Cyber Security

Notepad++ Hijacked: State-Sponsored Actors Poisoned Updates for Months

Do Son February 2, 2026 0
Read More Read more about Notepad++ Hijacked: State-Sponsored Actors Poisoned Updates for Months
IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants UAT-8099 BadIIS Malware Pacific Islands Forum Cyberattack
  • Cyber Security
  • Malware

IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants

Do Son February 2, 2026 0
Read More Read more about IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants
The “Fix” is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI ConsentFix Phishing OAuth Token Theft
  • Cybercriminals

The “Fix” is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI

Do Son February 2, 2026 0
Read More Read more about The “Fix” is a Trap: ConsentFix Phishing Bypasses MFA via Azure CLI
Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice Xloader Malware Information Stealer Phantom Stealer v3.5.0 DLL Sideloading Attack
  • Malware

Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice

Do Son February 2, 2026 0
Read More Read more about Signed & Stolen: “Phantom Stealer” Hijacks Java App via Fake DHL Invoice
New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web ICS Offensive Framework APT IRAN
  • Cybercriminals

New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web

Do Son February 2, 2026 0
Read More Read more about New Offensive OT Framework Targeting Energy Infrastructure Emerges on Dark Web
Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems EncystPHP Web Shell FreePBX Vulnerability
  • Cybercriminals
  • Vulnerability Report

Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems

Do Son February 2, 2026 0
Read More Read more about Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems
“Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected Exfil Out&Look Microsoft 365 Logging Gap Outlook Classic KB5074109 freeze, January 2026 POP3 PST bug Outlook Classic POP3 freeze, KB5074109 Windows 11 bug Outlook, CPU Usage Outlook lag Outlook Lite discontinued
  • Vulnerability Report

“Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected

Do Son February 2, 2026 0
Read More Read more about “Exfil Out&Look” Flaw Lets Spies Steal Emails via OWA Undetected
Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys TA584 Tsundere Bot Invisible Registry Persistence
  • Cybercriminals

Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys

Do Son February 2, 2026 0
Read More Read more about Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
Wrapped in Stealth: Python RAT Hides Inside ELF Binary to Evade Detection Python-based RAT Adaptive Beaconing
  • Malware

Wrapped in Stealth: Python RAT Hides Inside ELF Binary to Evade Detection

Do Son February 2, 2026 0
Read More Read more about Wrapped in Stealth: Python RAT Hides Inside ELF Binary to Evade Detection
AI-Coded Malware: Vietnamese “Huna” Actor Targets Job Seekers with PureRAT AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Malware

AI-Coded Malware: Vietnamese “Huna” Actor Targets Job Seekers with PureRAT

Do Son February 2, 2026 0
Read More Read more about AI-Coded Malware: Vietnamese “Huna” Actor Targets Job Seekers with PureRAT
EdTech startups and the role of LMS in their growth tech
  • Technique

EdTech startups and the role of LMS in their growth

Do Son January 31, 2026 0
Read More Read more about EdTech startups and the role of LMS in their growth
VPNs & Fake Updates: Google Dismantles Massive IPIDEA Proxy Network IPIDEA Proxy Network Residential Proxy Disruption
  • Cybercriminals

VPNs & Fake Updates: Google Dismantles Massive IPIDEA Proxy Network

Do Son January 31, 2026 0
Read More Read more about VPNs & Fake Updates: Google Dismantles Massive IPIDEA Proxy Network
From User to SYSTEM: PoC Released for Zabbix Privilege Escalation CVE-2024-42330 Zabbix Privilege Escalation CVE-2025-27237
  • Vulnerability

From User to SYSTEM: PoC Released for Zabbix Privilege Escalation

Do Son January 30, 2026 0
Read More Read more about From User to SYSTEM: PoC Released for Zabbix Privilege Escalation
“Update” to Nightmare: eScan Antivirus Hacked to Distribute Malware TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Malware

“Update” to Nightmare: eScan Antivirus Hacked to Distribute Malware

Do Son January 30, 2026 0
Read More Read more about “Update” to Nightmare: eScan Antivirus Hacked to Distribute Malware
Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection

Do Son January 30, 2026 0
Read More Read more about Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack Check Point VPN vulnerability exploited in the wild Check Point VPN exploit CVE-2026-50751 zero-day Checkmarx Breach Supply Chain Attack Ivanti EPMM RCE CVE-2026-1281 Modular DS Vulnerability CVE-2026-23550 D-Link RCE Vulnerability CVE-2026-0625 Christmas 2025 GreyNoise Campaign, Japan-Based Initial Access Broker React2Shell Zero-Day, APT Active Exploitation WordPress vulnerability, authentication bypass FreePBX, zero-day Trend Micro Apex One, Remote Code Execution BitoPro Hack, Crypto Theft UNC5337 - CVE-2022-47945 Safe{Wallet} hack Fortinet vulnerability, CVE-2024-21762, FortiGate attack Balloonfly, Play ransomware Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
  • Vulnerability Report

Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack

Do Son January 30, 2026 0
Read More Read more about Exploited in the Wild: Critical Ivanti EPMM RCE Flaws (CVSS 9.8) Under Attack
Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation Kyverno SSRF Kubernetes Policy Engine Kyverno Privilege Escalation CVE-2026-22039
  • Vulnerability Report

Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation

Do Son January 30, 2026 0
Read More Read more about Cluster Admin for All: Critical Kyverno Flaw (CVSS 10) Shatters Isolation
“SessionReaper” Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Cybercriminals
  • Vulnerability Report

“SessionReaper” Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites

Do Son January 30, 2026 0
Read More Read more about “SessionReaper” Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites
Scam Alert: “Amazon Ads Blocker” Extension Hijacks Creator Commissions Amazon Ads Blocker Affiliate Link Hijacking Malicious browser extensions
  • Cybercriminals

Scam Alert: “Amazon Ads Blocker” Extension Hijacks Creator Commissions

Do Son January 30, 2026 0
Read More Read more about Scam Alert: “Amazon Ads Blocker” Extension Hijacks Creator Commissions
Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws NVIDIA acquisition rumors NVIDIA AI Security AI Framework Vulnerabilities Nvidia 595.76 Hotfix NVIDIA Megatron Bridge vulnerability GPU vs ASIC AI battle NVIDIA Driver Vulnerability CVE-2025-33217 NVIDIA biggest TSMC customer 2026, NVIDIA vs Apple TSMC revenue share NVIDIA CUDA Toolkit CVE-2025-33228 Groq NVIDIA licensing deal, Jonathan Ross acquihire 2025 NeMo Code Injection, AI Framework RCE NVIDIA App Privilege Escalation, CVE-2025-23358 NVIDIA Security Update, DLS Vulnerability CVE-2025-23316 NVIDIA NVDebug, vulnerabilities NVIDIA Driver Vulnerabilities, vGPU Security Nvidia Jetson, UEFI Vulnerabilities CVE-2024-0130 - CVE-2024-0136 CVE-2024-0148 NVIDIA Driver Support, Windows 10 EOL
  • Vulnerability Report

Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws

Do Son January 30, 2026 0
Read More Read more about Guest-to-Host Escape: NVIDIA Patches Critical vGPU & Driver Flaws
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64530CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api:...
  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-64523CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take...
  • CVE-2026-64459CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: tcp: restore...
  • CVE-2026-64450CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: tipc: fix...
  • CVE-2026-64439CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: crypto: krb5...
  • CVE-2026-64410CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable:...
  • CVE-2026-64399CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ksmbd: add...
  • CVE-2026-64397CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.