Skip to content
June 19, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Malware

ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading

Do Son December 8, 2025 0
A sophisticated malware campaign traditionally focused on Chinese-speaking targets has expanded its scope, now aggressively targeting English-speaking...
Read More Read more about ValleyRAT Targets English Job Seekers by Trojanizing Foxit PDF Reader with DLL Sideloading
Coordinated Reconnaissance: 7,000+ IPs Target Palo Alto GlobalProtect and SonicWall API Endpoints Palo Alto SonicWall Scanning, Coordinated Reconnaissance
  • Cybercriminals

Coordinated Reconnaissance: 7,000+ IPs Target Palo Alto GlobalProtect and SonicWall API Endpoints

Do Son December 6, 2025 0
A sudden surge in mass scanning activity has targeted two major enterprise security vendors, Palo Alto Networks...
Read More Read more about Coordinated Reconnaissance: 7,000+ IPs Target Palo Alto GlobalProtect and SonicWall API Endpoints
Key AI Solutions in Cybersecurity for 2026 WD Discovery Vulnerability CVE-2025-30248 binary-parser Vulnerability CVE-2026-1245 H3C RCE Vulnerability CVE-2025-60262 Telenium RCE, CVE-2025-10659 Fuel station security, ICS vulnerabilities FreePBX vulnerability CVE-2024-9478 & CVE-2024-9479 SysTrack Vulnerability, Privilege Escalation
  • Technique

Key AI Solutions in Cybersecurity for 2026

Do Son December 6, 2025
As we move further into the digital age, the importance of robust cybersecurity measures has never been...
Read More Read more about Key AI Solutions in Cybersecurity for 2026
Critical Step CA Flaw (CVE-2025-44005, CVSS 10.0) Allows Unauthenticated Bypass to Issue Fraudulent Certificates Step CA Auth Bypass, Critical ACME Flaw
  • Vulnerability Report

Critical Step CA Flaw (CVE-2025-44005, CVSS 10.0) Allows Unauthenticated Bypass to Issue Fraudulent Certificates

Do Son December 6, 2025 0
A critical security vulnerability has been identified in Step CA, a popular online Certificate Authority tool used...
Read More Read more about Critical Step CA Flaw (CVE-2025-44005, CVSS 10.0) Allows Unauthenticated Bypass to Issue Fraudulent Certificates
China APT UNC5174 Hijacks Discord API as Covert C2 Channel to Evade Detection and Conduct Espionage Discord C2, UNC5174 Espionage
  • Cybercriminals
  • Malware

China APT UNC5174 Hijacks Discord API as Covert C2 Channel to Evade Detection and Conduct Espionage

Do Son December 6, 2025 0
A sophisticated cyber-espionage campaign linked to the Chinese state-sponsored threat group UNC5174 has been discovered utilizing the...
Read More Read more about China APT UNC5174 Hijacks Discord API as Covert C2 Channel to Evade Detection and Conduct Espionage
Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing G2_PR_Winter_1764779986pS3XAjIIlK
  • Press Release

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing

cybernewswire December 5, 2025 0
Madison, United States, 5th December 2025, CyberNewsWire
Read More Read more about Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing
Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM webinar_sns2_1764913495pMKY77PH7j
  • Press Release

Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM

cybernewswire December 5, 2025 0
Torrance, California, USA, 5th December 2025, CyberNewsWire
Read More Read more about Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM
Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations

Do Son December 5, 2025 0
To enhance transparency in artificial intelligence and curb the problem of confidently delivering nonsense, OpenAI has revealed...
Read More Read more about Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations
New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use Android Call Scam Protection 30-Second Fraud Delay
  • Android

New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use

Do Son December 5, 2025 0
Google is now expanding Android’s call-scam protection through Google Play Services, enhancing the system’s ability to safeguard...
Read More Read more about New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use
Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime Apple HomePad delay Tesla CarPlay integration 2026 Apple CarPlay AI integration 2026 Apple 2026 product roadmap rumors, foldable iPhone release date Apple Vision Pro sales slump, Vision Pro production cut Russia FaceTime Ban Network Blockade Apple Apple 2026 Roadmap, iPhone Foldable, Apple Intelligence Apple Maps ads, iOS monetization Apple, Digital Markets Act FCC Leak, iPhone 16e Schematics iPhone Fold Apple Made in India Apple US Investment, Indian Tariffs Apple Leadership, Tim Cook Tenure Siri Redesign, Apple AI Apple App Store Apple EU, Digital Markets Act CVE-2022-32898 Third-Party iOS Apps Apple Antitrust, DOJ Lawsuit
  • Technology

Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime

Do Son December 5, 2025 0
Russia has recently imposed a network-level blockade on Apple’s video-calling service FaceTime, which is developed and operated...
Read More Read more about Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime
Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass CVE-2024-40725 & CVE-2024-40898 Apache SSRF NTLM Leak, suexec Bypass
  • Vulnerability Report

Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass

Do Son December 5, 2025 0
The Apache Software Foundation has rolled out a crucial update for the ubiquitous Apache HTTP Server, addressing...
Read More Read more about Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion USB LNK Cryptominer, Smart Mining Evasion
  • Malware

Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion

Do Son December 5, 2025 0
In an era dominated by cloud vulnerabilities and phishing emails, a classic threat vector has made a...
Read More Read more about Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core Apache Tika XXE, Malicious PDF Exploit Apache Tika, XXE vulnerability CVE-2025-54988
  • Vulnerability Report

The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core

Do Son December 5, 2025 0
The Apache Tika toolkit, the industry standard for detecting and extracting metadata from over a thousand file...
Read More Read more about The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
“React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure Check Point VPN vulnerability exploited in the wild Check Point VPN exploit CVE-2026-50751 zero-day Checkmarx Breach Supply Chain Attack Ivanti EPMM RCE CVE-2026-1281 Modular DS Vulnerability CVE-2026-23550 D-Link RCE Vulnerability CVE-2026-0625 Christmas 2025 GreyNoise Campaign, Japan-Based Initial Access Broker React2Shell Zero-Day, APT Active Exploitation WordPress vulnerability, authentication bypass FreePBX, zero-day Trend Micro Apex One, Remote Code Execution BitoPro Hack, Crypto Theft UNC5337 - CVE-2022-47945 Safe{Wallet} hack Fortinet vulnerability, CVE-2024-21762, FortiGate attack Balloonfly, Play ransomware Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
  • Vulnerability Report

“React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure

Do Son December 5, 2025 0
Only hours after the public disclosure of a critical vulnerability in the React ecosystem, state-sponsored cyber espionage...
Read More Read more about “React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Malware

Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection

Do Son December 5, 2025 0
A new, highly targeted espionage campaign dubbed Operation DUPEHIKE has been uncovered targeting corporate entities within the...
Read More Read more about Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows Splunk Enterprise vulnerabilities, CVSS 9.8 flaw, CVE-2026-20253, CVE-2026-20251, CVE-2026-20258 Splunk Enterprise Vulnerabilities CVE-2026-20240 Splunk RCE CVE-2026-20204 Splunk RCE Vulnerability CVE-2026-20163 Splunk Enterprise Vulnerabilities CVE-2026-20140 Splunk Permission Flaw, Local Privilege Escalation Splunk Vulnerabilities CVE-2024-53247 - Splunk Secure Gateway App CVE-2025-20229 & CVE-2025-20231
  • Vulnerability Report

High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows

Do Son December 5, 2025 0
Splunk administrators managing Windows environments are being urged to patch immediately following the discovery of two high-severity...
Read More Read more about High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows
High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection CVE-2024-25641 Cacti SNMP RCE, Command Injection
  • Vulnerability Report

High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection

Do Son December 5, 2025 0
A high-severity security flaw has been uncovered in Cacti, the popular open-source network graphing solution. The vulnerability,...
Read More Read more about High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection
Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure Calisto RSF Espionage, AiTM Phishing Lure
  • Cyber Security

Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure

Do Son December 5, 2025 0
A fresh wave of cyber-espionage attacks has struck the international non-profit sector, with Russian state-sponsored hackers zeroing...
Read More Read more about Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure
NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption NVIDIA DGX Cloud restructuring, Dwight Diercks engineering shift NVIDIA Isaac Launchable, Hard-coded Credentials NVIDIA Merlin Deserialization, AI Pipeline RCE Triton DoS Flaws, AI Inference Server Security NVIDIA AI programming AI Chips China 800VDC Data Center, AI Power Architecture CVE-2024-0114 NVIDIA Container Toolkit vulnerability Container escape
  • Vulnerability Report

NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption

Do Son December 5, 2025 0
NVIDIA has issued a security bulletin regarding its Triton Inference Server, a cornerstone tool used by MLOps...
Read More Read more about NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption
Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage Patchwork StreamSpy, WebSocket C2
  • Cyber Security
  • Malware

Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage

Do Son December 5, 2025 0
The Patchwork APT group (also known as Bai Xiang or “White Elephant”), a cyberespionage actor believed to...
Read More Read more about Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-56209CVSS 9.1
    An arbitrary address write vulnerability was found in libaom, the reference AV1...
  • CVE-2026-55884
    ## Summary The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints...
  • CVE-2026-9142CVSS 9.1
    There is an insecure default credentials vulnerability in NI grpc-device when TLS...
  • CVE-2026-54051CVSS 9.9
    ## Summary The agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`),...
  • CVE-2026-48137CVSS 9.1
    There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband...
  • CVE-2026-50242CVSS 10.0
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass...
  • CVE-2026-56142CVSS 9.6
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation...
  • CVE-2026-56141CVSS 9.8
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover...
  • CVE-2026-54414CVSS 9.8
    FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload...
  • CVE-2026-7515CVSS 9.8
    The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.