Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data Apache Struts 2 Vulnerability CVE-2025-68493 CVE-2021-31805 Struts DoS, File Upload Leak
  • Vulnerability Report

The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data

Do Son January 12, 2026 0
Read More Read more about The XML Trap: Critical Struts 2 Flaw CVE-2025-68493 Exposes Data
CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping Apache Uniffle Vulnerability CVE-2025-68637
  • Vulnerability Report

CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping

Do Son January 12, 2026 0
Read More Read more about CVE-2025-68637: Critical Apache Uniffle Flaw Exposes Clusters to Eavesdropping
“Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cybercriminals

“Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign

Do Son January 12, 2026 0
Read More Read more about “Boto Cor-de-Rosa”: Banking Malware Astaroth Pivots to WhatsApp in New Campaign
Pig Butchering-as-a-Service: How “Penguin” Industrialized Global Fraud Pig Butchering-as-a-Service (PBaaS) Crypto Fraud Economy
  • Cybercriminals

Pig Butchering-as-a-Service: How “Penguin” Industrialized Global Fraud

Do Son January 12, 2026 0
Read More Read more about Pig Butchering-as-a-Service: How “Penguin” Industrialized Global Fraud
CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow zlib Vulnerability CVE-2026-22184
  • Vulnerability Report

CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow

Do Son January 12, 2026 0
Read More Read more about CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow
RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants axios Supply Chain Attack WAVESHAPER.V2 SnappyBee Malware Salt Typhoon Stately Taurus ScoringMathTea RAT, Lazarus Reflective DLL
  • Cyber Security
  • Malware

RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants

Do Son January 12, 2026 0
Read More Read more about RustyWater Rising: MuddyWater Drops PowerShell for Stealthy Rust Implants
Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All Fortra BoKS vulnerability OS command injection, CVE-2026-9862 Altium Enterprise Server Vulnerability CVE-2026-9129 Path Traversal Patreon OAuth Vulnerability Identity Collision DRC INSIGHT Vulnerability Exam Data Hijacking Horner Automation PLC Industrial Brute Force Honeywell IQ4x Vulnerability CVE-2026-3611 DJI Romo vacuum security flaw Python Cryptography Vulnerability CVE-2026-26007 Open5GS Vulnerability CVE-2026-0622 Vivotek IP7137 Vulnerabilities CVE-2025-66049 Forcepoint DLP Vulnerability CVE-2025-14026 Cellopoint Secure Email Gateway - CVE-2024-9043
  • Vulnerability Report

Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All

Do Son January 12, 2026 0
Read More Read more about Unpatched & Exposed: Legacy Vivotek Cameras Broadcast Live Video to All
China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe illegal streaming networks complex criminal enterprises UAT-7290 China-nexus Espionage Adversarial Misuse of Generative AI
  • Cyber Security

China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe

Do Son January 12, 2026 0
Read More Read more about China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe
Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking InputPlumber Vulnerability CVE-2025-66005
  • Vulnerability Report

Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking

Do Son January 12, 2026 0
Read More Read more about Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking
Does Password Strength Matter In The Days of AI Cyber Attacks? cybersecurity Advertise
  • Technique

Does Password Strength Matter In The Days of AI Cyber Attacks?

Do Son January 10, 2026 0
Read More Read more about Does Password Strength Matter In The Days of AI Cyber Attacks?
The Atomic Engine: Meta Secures 6.6 GW of Nuclear Power to Fuel its AI Future Meta nuclear energy deals 6.6GW, Prometheus supercluster Ohio power
  • Technology

The Atomic Engine: Meta Secures 6.6 GW of Nuclear Power to Fuel its AI Future

Do Son January 10, 2026 0
Read More Read more about The Atomic Engine: Meta Secures 6.6 GW of Nuclear Power to Fuel its AI Future
The Frictionless Frontier: Microsoft Launches “Copilot Checkout” at NRF 2026 Microsoft Copilot Checkout NRF 2026, agentic commerce AI shopping
  • Technology

The Frictionless Frontier: Microsoft Launches “Copilot Checkout” at NRF 2026

Do Son January 10, 2026 0
Read More Read more about The Frictionless Frontier: Microsoft Launches “Copilot Checkout” at NRF 2026
The Gemini Overhaul: Google Unlocks Free AI Writing and “AI Inbox” for Gmail Gmail Gemini 3 update January 2026, Gmail AI Inbox free vs premium
  • Technology

The Gemini Overhaul: Google Unlocks Free AI Writing and “AI Inbox” for Gmail

Do Son January 10, 2026 0
Read More Read more about The Gemini Overhaul: Google Unlocks Free AI Writing and “AI Inbox” for Gmail
No Manifesto Needed: Linus Torvalds Blasts “AI Slop” Fearmongering Linux Kernel 7.1 release Linux Kernel update, AMD ZEN 6 support, Linux driver fixes Linux Kernel 7.1 i486 support Linux 7.0 HIPPI support removal, legacy networking protocol retirement Linus Torvalds AI slop Linux kernel, Lorenzo Stoakes AI tool debate Linux Kernel Rust CVE-2025-68260, Android Binder Rust Race Condition TSEM Security Module Controversy, Linus Torvalds LSM Dispute Kernel Panic, PoC released Linux Kernel 6.16, File System Fixes CVE-2023-42753 - Linux Kernel Developers
  • Linux

No Manifesto Needed: Linus Torvalds Blasts “AI Slop” Fearmongering

Do Son January 10, 2026 0
Read More Read more about No Manifesto Needed: Linus Torvalds Blasts “AI Slop” Fearmongering
The Exit Strategy: Microsoft Finally Grants Admins a Way to Uninstall Copilot Windows 11 Build 26220.7535 Copilot removal, Remove Microsoft Copilot App Group Policy
  • Windows

The Exit Strategy: Microsoft Finally Grants Admins a Way to Uninstall Copilot

Do Son January 10, 2026 0
Read More Read more about The Exit Strategy: Microsoft Finally Grants Admins a Way to Uninstall Copilot
Iran Tests Academic “Whitelists” Amid Nationwide 2026 Blackout Iran internet blackout 2026, academic ASN connectivity surge
  • Technology

Iran Tests Academic “Whitelists” Amid Nationwide 2026 Blackout

Do Son January 10, 2026 0
Read More Read more about Iran Tests Academic “Whitelists” Amid Nationwide 2026 Blackout
The End of Offline Era: Microsoft Kills Phone Activation After 24 Years HTTP.sys RCE vulnerability, Windows HTTP stack exploit, CVE-2026-47291 Netlogon RCE vulnerability Exploited in the wild Secure Boot certificate renewal 2026, Windows 11 UEFI update Community-First AI Infrastructure, Microsoft self-funding energy mandate aka.ms/aoh online portal CVE-2025-55681, Windows DWM Elevation Windows Administrator Protection, CVE-2025-60718 Microsoft AI Compute, IREN Infrastructure Microsoft Japan PPA, Renewable Energy Microsoft AI Investment, Cloud Expansion Microsoft Azure, Startup Credits Infinite Workday, AI in Work Microsoft Russia, Bankruptcy AI code generation, Microsoft AI Microsoft Layoffs, Restructuring
  • Windows

The End of Offline Era: Microsoft Kills Phone Activation After 24 Years

Do Son January 9, 2026 0
Read More Read more about The End of Offline Era: Microsoft Kills Phone Activation After 24 Years
Collateral Damage: Microsoft Defender Blocks Official MAS Script in Malware War Microsoft Activation Scripts block, Trojan:PowerShell/FakeMas.DA!MTB
  • Malware

Collateral Damage: Microsoft Defender Blocks Official MAS Script in Malware War

Do Son January 9, 2026 0
Read More Read more about Collateral Damage: Microsoft Defender Blocks Official MAS Script in Malware War
The AI Physician: OpenAI Launches “ChatGPT Health” to Sync Your Medical Records ChatGPT Health portal integration, AI medical data privacy 2026
  • Technology

The AI Physician: OpenAI Launches “ChatGPT Health” to Sync Your Medical Records

Do Son January 9, 2026 0
Read More Read more about The AI Physician: OpenAI Launches “ChatGPT Health” to Sync Your Medical Records
The $20B Handover: Apple Card Dumps Goldman Sachs for JPMorgan Chase Apple Card JPMorgan Chase transition, Goldman Sachs Apple Card exit 2026 Apple Wallet Digital Passport TSA Digital ID
  • Technology

The $20B Handover: Apple Card Dumps Goldman Sachs for JPMorgan Chase

Do Son January 9, 2026 0
Read More Read more about The $20B Handover: Apple Card Dumps Goldman Sachs for JPMorgan Chase
Public Exploit Released: Critical Trend Micro Flaw Grants SYSTEM Access libheif Vulnerability CVE-2025-65586 Trend Micro RCE CVE-2025-69258 SessionReaper CVE-2025-54236 VS Code Marketplace, supply chain attack npm Supply Chain, Toptal Compromise Ruckus AP Vulnerability
  • Vulnerability Report

Public Exploit Released: Critical Trend Micro Flaw Grants SYSTEM Access

Do Son January 9, 2026 0
Read More Read more about Public Exploit Released: Critical Trend Micro Flaw Grants SYSTEM Access
Bluetooth Broken? Apache NimBLE Flaws Enable Spoofing & Eavesdropping Apache NimBLE Vulnerabilities Bluetooth Spoofing
  • Vulnerability Report

Bluetooth Broken? Apache NimBLE Flaws Enable Spoofing & Eavesdropping

Do Son January 9, 2026 0
Read More Read more about Bluetooth Broken? Apache NimBLE Flaws Enable Spoofing & Eavesdropping
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-55579CVSS 9.8
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-48030CVSS 9.9
    Pheditor is a single-file editor and file manager written in PHP. From...
  • CVE-2026-63077CVSS 9.8
    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible...
  • CVE-2026-17191CVSS 9.1
    An input validation vulnerability exists in an API component of the orchestrator....
  • CVE-2026-51303CVSS 9.8
    A use-after-free (UAF) vulnerability was discovered in the core parsing component of...
  • CVE-2025-50455CVSS 9.1
    SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint...
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may...
  • CVE-2026-66395CVSS 9.6
    SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the...
  • CVE-2026-59550CVSS 9.3
    Unauthenticated SQL Injection in AWP Classifieds
  • CVE-2026-59549CVSS 9.3
    Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.