Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Racing the Zombie: PoC Released for Linux Kernel POSIX Timer Vulnerability (CVE-2025-38352) French Digital Sovereignty Greg Kroah-Hartman AI code review CVE-2025-38352 Linux kernel exploit, Android 32-bit UAF vulnerability CVE-2022-36946 Linux Kernel 6.16, Hardware Support
  • Linux
  • Vulnerability Report

Racing the Zombie: PoC Released for Linux Kernel POSIX Timer Vulnerability (CVE-2025-38352)

Do Son December 24, 2025 0
Read More Read more about Racing the Zombie: PoC Released for Linux Kernel POSIX Timer Vulnerability (CVE-2025-38352)
Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme Malvertising ATO
  • Cybercriminals

Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme

Do Son December 24, 2025 0
Read More Read more about Search Engine “Malvertising” Ring Disrupted: DOJ Seizes Backend of $14.6 Million Bank Fraud Scheme
The Hard-Coded Backdoor: Critical 9.8 Severity NVIDIA Flaws Grant Total Control of AI Systems NVIDIA DGX Cloud restructuring, Dwight Diercks engineering shift NVIDIA Isaac Launchable, Hard-coded Credentials NVIDIA Merlin Deserialization, AI Pipeline RCE Triton DoS Flaws, AI Inference Server Security NVIDIA AI programming AI Chips China 800VDC Data Center, AI Power Architecture CVE-2024-0114 NVIDIA Container Toolkit vulnerability Container escape
  • Vulnerability Report

The Hard-Coded Backdoor: Critical 9.8 Severity NVIDIA Flaws Grant Total Control of AI Systems

Do Son December 24, 2025 0
Read More Read more about The Hard-Coded Backdoor: Critical 9.8 Severity NVIDIA Flaws Grant Total Control of AI Systems
Critical Network Collapse: 9.8 Severity Net-SNMP Buffer Overflow Threatens Global Monitoring Systems Net-SNMP, CVE-2025-68615
  • Vulnerability Report

Critical Network Collapse: 9.8 Severity Net-SNMP Buffer Overflow Threatens Global Monitoring Systems

Do Son December 24, 2025 0
Read More Read more about Critical Network Collapse: 9.8 Severity Net-SNMP Buffer Overflow Threatens Global Monitoring Systems
“Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets APT37 Artemis, Korean TV Casting Phishing
  • Cyber Security
  • Malware

“Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets

Do Son December 24, 2025 0
Read More Read more about “Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets
The Notarized Nightmare: New MacSync Stealer Bypasses Gatekeeper to Hijack Mac Devices OSX/Amos Stealer Electron ASAR Trojan MioLab Malware macOS Security MacSync Stealer macOS Malware ambar-src npm Malware Supply Chain Typosquatting Matryoshka Mac Malware ClickFix Crypto Scam Infostealer Evolution macOS Malware Predator Spyware Intellexa Anti-Analysis XCSSET macOS Malware, Xcode Supply Chain
  • Malware

The Notarized Nightmare: New MacSync Stealer Bypasses Gatekeeper to Hijack Mac Devices

Do Son December 24, 2025 0
Read More Read more about The Notarized Nightmare: New MacSync Stealer Bypasses Gatekeeper to Hijack Mac Devices
“Operation IconCat”: Hackers Masquerade as Security Giants to Target Israeli Firms Operation IconCat, UNG0801 AFP cyberattack -NetWalker Ransomware VShell RAT
  • Cyber Security

“Operation IconCat”: Hackers Masquerade as Security Giants to Target Israeli Firms

Do Son December 24, 2025 0
Read More Read more about “Operation IconCat”: Hackers Masquerade as Security Giants to Target Israeli Firms
APT-36 Uses Fake “WhatsApp Fraud” Advisory to Hack Government Systems TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Cyber Security

APT-36 Uses Fake “WhatsApp Fraud” Advisory to Hack Government Systems

Do Son December 24, 2025 0
Read More Read more about APT-36 Uses Fake “WhatsApp Fraud” Advisory to Hack Government Systems
“Webrat” Trap: Hackers Lure Junior Security Researchers with Fake GitHub Exploits Webrat Malware, Fake PoC Exploits
  • Malware

“Webrat” Trap: Hackers Lure Junior Security Researchers with Fake GitHub Exploits

Do Son December 24, 2025 0
Read More Read more about “Webrat” Trap: Hackers Lure Junior Security Researchers with Fake GitHub Exploits
Operation PCPcat: 60,000 Next.js Servers Hijacked in Just 48 Hours Knowledge Deliver RCE vulnerability FortiClient EMS Vulnerability CVE-2026-35616 Cisco SD-WAN Vulnerability CVE-2026-20122 PCPcat, Next.js RCE Salesloft breach, Salesforce CRM WIREFIRE web shell
  • Vulnerability Report

Operation PCPcat: 60,000 Next.js Servers Hijacked in Just 48 Hours

Do Son December 24, 2025 0
Read More Read more about Operation PCPcat: 60,000 Next.js Servers Hijacked in Just 48 Hours
The Final Countdown: Valve Moves Steam to 64-Bit and Sets January 2026 Cutoff Steam 64-bit Windows transition, Steam 32-bit end of life January 2026 SteamOS Steam Windows 10 32-bit
  • Technology

The Final Countdown: Valve Moves Steam to 64-Bit and Sets January 2026 Cutoff

Do Son December 24, 2025 0
Read More Read more about The Final Countdown: Valve Moves Steam to 64-Bit and Sets January 2026 Cutoff
The Great Rewrite: Microsoft’s Radical 2030 Vision to Kill C/C++ with AI-Powered Rust Microsoft 2030 Rust migration, AI-driven code refactoring
  • Technology

The Great Rewrite: Microsoft’s Radical 2030 Vision to Kill C/C++ with AI-Powered Rust

Do Son December 24, 2025 0
Read More Read more about The Great Rewrite: Microsoft’s Radical 2030 Vision to Kill C/C++ with AI-Powered Rust
Bypassing the Bottleneck: How Microsoft’s Native NVMe Driver Delivers an 80% IOPS Surge Windows Native NVMe driver, Windows Server 2025 SSD performance
  • Windows

Bypassing the Bottleneck: How Microsoft’s Native NVMe Driver Delivers an 80% IOPS Surge

Do Son December 24, 2025 0
Read More Read more about Bypassing the Bottleneck: How Microsoft’s Native NVMe Driver Delivers an 80% IOPS Surge
The PowerShell Pivot: MAS Roadmap Reveals End of Batch Scripting Era MAS PowerShell migration, Windows activation roadmap
  • Technology

The PowerShell Pivot: MAS Roadmap Reveals End of Batch Scripting Era

Do Son December 24, 2025 0
Read More Read more about The PowerShell Pivot: MAS Roadmap Reveals End of Batch Scripting Era
Why a High Speed VPN Makes the Internet Better tech-vpn
  • Technique

Why a High Speed VPN Makes the Internet Better

Do Son December 23, 2025 0
Read More Read more about Why a High Speed VPN Makes the Internet Better
Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS Hardware-accelerated BitLocker, Windows 11 encryption performance
  • Windows

Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS

Do Son December 23, 2025 0
Read More Read more about Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS
The Android Toll: Google to Charge $2.85 Per Install for External App Links Low carbon cloud computing Smartphone clusters, Green technology, Data centers, Google research Google Agentic AI search G Suite legacy free commercial reclassification 2026 Agent Payments Protocol AP2 Back-Button Hijacking Google Search AI headlines Google Play Store fee reduction Google Antigravity account recovery Google Advanced Air-Cooling Alphabet $185 billion CapEx 2026 Google Aluminum OS 2026 ai-disclosure HTML attribute, Chrome AI content transparency 2026 Google monopoly appeal 2026, Search data sharing stay Change @gmail.com address, Gmail email alias feature 2025 Google Play Store external download fees, Epic vs Google 2026 billing Google Dark Web Report Retirement, Data Breach Monitoring Google Antitrust One-Year Limit Default Search Contract Term Google AI Headlines Discover Headline Distortion Aluminium OS Android ChromeOS Merge Google Accelerator Impact $31.2 Billion Funding Google Texas Investment AI Data Center Expansion Google Play payments, external billing Gmail HIBP leak Privacy Sandbox Termination, Third-Party Cookies Google Strategic Market Status, CMA Antitrust ICEBlock Removal, DOJ Pressure Google Logo, AI Branding
  • Technology

The Android Toll: Google to Charge $2.85 Per Install for External App Links

Do Son December 23, 2025 0
Read More Read more about The Android Toll: Google to Charge $2.85 Per Install for External App Links
The Grid is the Goal: Alphabet’s $4.75B Bet to Own the Power Plants Behind Gemini Alphabet Intersect Power acquisition, Google AI data center energy
  • Technology

The Grid is the Goal: Alphabet’s $4.75B Bet to Own the Power Plants Behind Gemini

Do Son December 23, 2025 0
Read More Read more about The Grid is the Goal: Alphabet’s $4.75B Bet to Own the Power Plants Behind Gemini
“Tax Compliance” Trap: Hackers Mimic Indian Income Tax Department to Deploy China-Linked Malware Income Tax Phishing, China-Linked APT
  • Cybercriminals

“Tax Compliance” Trap: Hackers Mimic Indian Income Tax Department to Deploy China-Linked Malware

Do Son December 23, 2025 0
Read More Read more about “Tax Compliance” Trap: Hackers Mimic Indian Income Tax Department to Deploy China-Linked Malware
Windows DWM Flaw Lets Local Users Paint Their Way to SYSTEM Privileges, PoC Publishes HTTP.sys RCE vulnerability, Windows HTTP stack exploit, CVE-2026-47291 Netlogon RCE vulnerability Exploited in the wild Secure Boot certificate renewal 2026, Windows 11 UEFI update Community-First AI Infrastructure, Microsoft self-funding energy mandate aka.ms/aoh online portal CVE-2025-55681, Windows DWM Elevation Windows Administrator Protection, CVE-2025-60718 Microsoft AI Compute, IREN Infrastructure Microsoft Japan PPA, Renewable Energy Microsoft AI Investment, Cloud Expansion Microsoft Azure, Startup Credits Infinite Workday, AI in Work Microsoft Russia, Bankruptcy AI code generation, Microsoft AI Microsoft Layoffs, Restructuring
  • Vulnerability

Windows DWM Flaw Lets Local Users Paint Their Way to SYSTEM Privileges, PoC Publishes

Do Son December 23, 2025 0
Read More Read more about Windows DWM Flaw Lets Local Users Paint Their Way to SYSTEM Privileges, PoC Publishes
Anna’s Archive Claims 300TB Spotify Mirror, Forcing an Investigation Into a Massive Music Data Leak Spotify data leak, Anna’s Archive CVE-2025-27154
  • Data Leak

Anna’s Archive Claims 300TB Spotify Mirror, Forcing an Investigation Into a Massive Music Data Leak

Do Son December 23, 2025 0
Read More Read more about Anna’s Archive Claims 300TB Spotify Mirror, Forcing an Investigation Into a Massive Music Data Leak
Critical Unauthenticated MongoDB Flaw Leaks Sensitive Data via zlib Compression MongoDB Vulnerability CVE-2026-25611 MongoDB zlib vulnerability, CVE-2025-14847 MongoDB Vulnerabilities, Data Access CVE-2024-6376 CVE-2025-0755
  • Vulnerability Report

Critical Unauthenticated MongoDB Flaw Leaks Sensitive Data via zlib Compression

Do Son December 23, 2025 0
Read More Read more about Critical Unauthenticated MongoDB Flaw Leaks Sensitive Data via zlib Compression
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-11841CVSS 9.4
    An attacker may perform unauthenticated read and write operations on sensitive filesystem...
  • CVE-2026-16462CVSS 9.8
    In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows...
  • CVE-2026-11756CVSS 10.0
    A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE...
  • CVE-2026-15014CVSS 9.8
    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications &...
  • CVE-2026-14545CVSS 9.8
    The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when...
  • CVE-2026-64771CVSS 9.8
    A buffer overflow was addressed with improved bounds checking. This issue is...
  • CVE-2026-64770CVSS 9.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue...
  • CVE-2026-64767CVSS 9.8
    A buffer overflow was addressed with improved bounds checking. This issue is...
  • CVE-2026-64751CVSS 9.8
    A use after free issue was addressed with improved memory management. This...
  • CVE-2026-64740CVSS 9.8
    A parsing issue in the handling of directory paths was addressed with...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.