Skip to content
June 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access Storm-0249 EDR Abuse, DLL Sideloading
  • Cybercriminals

Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access

Do Son December 15, 2025 0
A notorious initial access broker (IAB) known as “Storm-0249” has radically shifted its tactics, moving from broad...
Read More Read more about Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
ImageMagick Flaw Risks Arbitrary Memory Disclosure via PSX TIM File Integer Overflow on 32-bit Systems ImageMagick Vulnerability CVE-2026-23876 ImageMagick TIM Overflow, Memory Disclosure Flaw ImageMagick vulnerabilities, memory corruption CVE-2023-34152
  • Vulnerability Report

ImageMagick Flaw Risks Arbitrary Memory Disclosure via PSX TIM File Integer Overflow on 32-bit Systems

Do Son December 15, 2025 0
A high-severity vulnerability has been uncovered in ImageMagick, the ubiquitous open-source image processing suite used by millions...
Read More Read more about ImageMagick Flaw Risks Arbitrary Memory Disclosure via PSX TIM File Integer Overflow on 32-bit Systems
VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan vs-c
  • Malware

VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan

Do Son December 15, 2025 0
A sophisticated malware campaign has been uncovered within the Visual Studio Code (VS Code) Marketplace, exposing a...
Read More Read more about VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners React2Shell RCE, Widespread Exploitation
  • Cybercriminals
  • Vulnerability Report

React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners

Do Son December 13, 2025 0
The cybersecurity landscape was jolted this month by the disclosure of a catastrophic vulnerability in one of...
Read More Read more about React2Shell: Max-Score RCE (CVSS 10.0) Triggers Widespread Exploitation by Espionage Groups & Miners
Linux Kernel io_uring UAF Flaw Used to Cheat BPF Verifier and Achieve Container Escape, PoC Releases Linux io_uring UAF, Kernel Exploit Primitive
  • Vulnerability

Linux Kernel io_uring UAF Flaw Used to Cheat BPF Verifier and Achieve Container Escape, PoC Releases

Do Son December 13, 2025 0
Two security researchers, known by the handles st424204 and d4em0n, have published a deep-dive analysis of a...
Read More Read more about Linux Kernel io_uring UAF Flaw Used to Cheat BPF Verifier and Achieve Container Escape, PoC Releases
Apache Airflow Flaws Leak Sensitive Credentials in UI via DAG Tracebacks & Template Rendering Airflow Credential Leak, UI Redaction Failure CVE-2024-39877 & CVE-2024-45784 Airflow Connection Leak, CVE-2025-54831
  • Vulnerability Report

Apache Airflow Flaws Leak Sensitive Credentials in UI via DAG Tracebacks & Template Rendering

Do Son December 13, 2025 0
The maintainers of Apache Airflow, the industry-standard platform for programmatic workflow authoring, have released a crucial security...
Read More Read more about Apache Airflow Flaws Leak Sensitive Credentials in UI via DAG Tracebacks & Template Rendering
Urgent: Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation Against High-Risk Targets Apple Zero-Day CVE-2025-43529 WebKit Zero-Day, Targeted iOS Spyware Apple spyware alerts, zero-click attacks Apple, trademark lawsuit CVE-2024-54527 PoC exploit Apple, App Store
  • Vulnerability Report

Urgent: Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation Against High-Risk Targets

Do Son December 13, 2025 0
Apple has issued an urgent security intervention for iPhone and iPad users, releasing patches for two critical...
Read More Read more about Urgent: Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation Against High-Risk Targets
Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide Critical_React2Shell_CVE-2025-55182____RSC______3_1765504077YqYq0hVYdr
  • Press Release

Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide

cybernewswire December 12, 2025 0
Torrance, United States / California, 12th December 2025, CyberNewsWire
Read More Read more about Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide
OpenAI Fights Back: GPT-5.2 Unveiled to Rival Google’s Gemini 3 Pro OpenAI GPT-5.2, Gemini 3 Pro Rival
  • Technology

OpenAI Fights Back: GPT-5.2 Unveiled to Rival Google’s Gemini 3 Pro

Do Son December 12, 2025 0
On the very same day it announced its historic partnership with Disney, OpenAI finally unveiled the model...
Read More Read more about OpenAI Fights Back: GPT-5.2 Unveiled to Rival Google’s Gemini 3 Pro
The IP Wall Falls: Disney Invests $1B in OpenAI to License 200+ Characters for AI Disney OpenAI $1B, AI Character Licensing
  • Technology

The IP Wall Falls: Disney Invests $1B in OpenAI to License 200+ Characters for AI

Do Son December 12, 2025 0
Long regarded as the “most formidable legal department in the Western Hemisphere,” Disney has historically guarded its...
Read More Read more about The IP Wall Falls: Disney Invests $1B in OpenAI to License 200+ Characters for AI
The AI Super-App Rises: Photoshop & Adobe Express Integrate into ChatGPT OpenAI Adobe Integration, ChatGPT Super-App
  • Technology

The AI Super-App Rises: Photoshop & Adobe Express Integrate into ChatGPT

Do Son December 12, 2025 0
Following earlier integrations with Spotify and Canva, OpenAI has taken yet another decisive step toward its ambition...
Read More Read more about The AI Super-App Rises: Photoshop & Adobe Express Integrate into ChatGPT
The “USB-C of AI” is Here: Google Launches Managed Servers for MCP Protocol Google MCP Protocol, Agentic AI Managed Servers Google Cloud Meta Google Cloud UniSuper
  • Technology

The “USB-C of AI” is Here: Google Launches Managed Servers for MCP Protocol

Do Son December 12, 2025 0
Following the Linux Foundation’s establishment of the Agentic AI Foundation (AAIF) and its designation of the Model...
Read More Read more about The “USB-C of AI” is Here: Google Launches Managed Servers for MCP Protocol
YouTube TV’s New Subscription Bundles: Is Streaming Becoming Cable All Over Again? YouTube TV Gemini Ask YouTube TV Bundles, Streaming Cable Model
  • Technology

YouTube TV’s New Subscription Bundles: Is Streaming Becoming Cable All Over Again?

Do Son December 12, 2025 0
Streaming television appears to be retracing the path once taken by traditional cable. YouTube TV has announced...
Read More Read more about YouTube TV’s New Subscription Bundles: Is Streaming Becoming Cable All Over Again?
Farewell, Tabs: Google’s Experimental Disco Browser Generates Web Apps with AI Google Disco Browser, Gemini PWA Generation
  • Technology

Farewell, Tabs: Google’s Experimental Disco Browser Generates Web Apps with AI

Do Son December 12, 2025 0
The race among artificial intelligence models has entered a fevered, white-hot phase—and AI-driven browsers have now gained...
Read More Read more about Farewell, Tabs: Google’s Experimental Disco Browser Generates Web Apps with AI
React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure React Server Components Vulnerability CVE-2026-23870 React Server Components Server-Side DoS React DoS Vulnerability CVE-2026-23864 React Server Components DoS, Source Code Disclosure React RCE, Server Components Deserialization CVE-2025-55182
  • Vulnerability Report

React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure

Do Son December 12, 2025 0
The security saga surrounding React Server Components continues this week. Just days after the React team patched...
Read More Read more about React Patches Two New Flaws Risking Server-Crashing DoS and Source Code Disclosure
Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access CVE-2024-32838 Apache Fineract IDOR, Core Banking Bypass
  • Vulnerability Report

Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access

Do Son December 12, 2025 0
A trio of security vulnerabilities has been disclosed in Apache Fineract, the open-source core banking system that...
Read More Read more about Core Banking System Flaw: Apache Fineract IDOR Risks Authorization Bypass & Customer Data Access
New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2 01flip Rust Ransomware, Cross-Platform APAC
  • Malware

New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2

Do Son December 12, 2025 0
A new and sophisticated ransomware player has entered the cybercrime arena, targeting critical infrastructure in the Asia-Pacific...
Read More Read more about New 01flip Ransomware Hits APAC Critical Infra: Cross-Platform Rust Weapon Uses Sliver C2
CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning CISA active exploit catalog known exploited vulnerabilities ActiveMQ RCE CVE-2026-34197 CISA KEV Catalog Actively Exploited Vulnerabilities CISA KEV Catalog CVE-2025-37164 GeoServer XXE, CISA KEV FortiWeb SQLi, CISA KEV Critical Vulnerabilities CVE-2024-20953
  • Vulnerability Report

CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning

Do Son December 12, 2025 0
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the widely used OSGeo...
Read More Read more about CISA KEV Alert: GeoServer XXE Flaw Under Active Attack Risks Data Theft & Internal Network Scanning
Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge ValleyRAT Builder Leak, Kernel Rootkit Comoditization
  • Malware

Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge

Do Son December 12, 2025 0
A sophisticated cyber weapon previously linked to targeted espionage has gone rogue, flooding the threat landscape after...
Read More Read more about Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge
Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures UAT-8099 BadIIS Malware Pacific Islands Forum Cyberattack
  • Cybercriminals

Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures

Do Son December 12, 2025 0
Just as employees begin anticipating their year-end performance reviews, a sophisticated new phishing campaign has emerged, turning...
Read More Read more about Sophisticated Okta SSO Phishing Bypasses Defenses to Steal Session Tokens With Salary Review Lures
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
  • CVE-2026-45480CVSS 10.0
    Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate...
  • CVE-2026-55255CVSS 9.9
    ## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/responses` endpoint allows...
  • CVE-2026-54782CVSS 10.0
    ### Impact Full impersonation of any principal the trusted STS could have...
  • CVE-2026-48773CVSS 9.8
    ProxySQL is a proxy for MySQL and its forks, as well as...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.