Skip to content
July 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs AuraStealer, Scam-Yourself
  • Malware

TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs

Do Son December 22, 2025 0
Read More Read more about TikTok’s “Scam-Yourself” Trap: How AuraStealer Malware Tricks Users into Hacking Their Own PCs
The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools Honeywell CCTV Vulnerability CVE-2026-1670 EagleMsgSpy Spyware Tool ResidentBat Spyware, Belarusian KGB Surveillance
  • Malware

The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools

Do Son December 22, 2025 0
Read More Read more about The KGB’s All-Seeing Eye: How ResidentBat Spyware Turns Seized Phones into Total Surveillance Tools
Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK DPRK Cyber Ecosystem, Unified Hacking Infrastructure
  • Cyber Security

Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK

Do Son December 22, 2025 0
Read More Read more about Shadows of the North: Unmasking the Sprawling Cyber Infrastructure of the DPRK
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk Apache NiFi RCE CVE-2026-39816 Apache NiFi Vulnerability CVE-2026-25903 Apache NiFi Deserialization, GetAsanaObject Vulnerability CVE-2024-52067 - CVE-2024-56512 CVE-2025-27017
  • Vulnerability Report

Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk

Do Son December 22, 2025 0
Read More Read more about Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes Chinese espionage groups APT35 Phishing, Stormshield CTI
  • Malware

North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes

Do Son December 22, 2025 0
Read More Read more about North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
“Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia Iranian Cyber Reconnaissance IP Camera Security NCSC Warning Russian Hacktivists Taiwan Cyberattacks China State-Sponsored Hacking state-sponsored threat actor Ransomware RAT Abuse, AnyDesk
  • Malware

“Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia

Do Son December 22, 2025 0
Read More Read more about “Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky BlueDelta Espionage, UKR.NET Phishing
  • Cyber Security

The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky

Do Son December 22, 2025 0
Read More Read more about The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users Dify API Key Exposure, LLM Security Dify Information Disclosure, LLM Security
  • Vulnerability Report

AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users

Do Son December 22, 2025 0
Read More Read more about AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
PoC Available: Unauthenticated HPE OneView RCE (CVSS 10.0) Exploits Hidden ID Pools API CVE-2025-37164, HPE OneView RCE
  • Vulnerability Report

PoC Available: Unauthenticated HPE OneView RCE (CVSS 10.0) Exploits Hidden ID Pools API

Do Son December 20, 2025 0
Read More Read more about PoC Available: Unauthenticated HPE OneView RCE (CVSS 10.0) Exploits Hidden ID Pools API
VR Vision Shift: Meta Pauses Third-Party Partnerships to Pivot Toward AI Smart Glasses Meta Horizon OS partnership pause, ASUS Lenovo VR headset cancellation
  • Technology

VR Vision Shift: Meta Pauses Third-Party Partnerships to Pivot Toward AI Smart Glasses

Do Son December 20, 2025 0
Read More Read more about VR Vision Shift: Meta Pauses Third-Party Partnerships to Pivot Toward AI Smart Glasses
The Wolf Among TVs: 1.8 Million-Strong Kimwolf Botnet Surpasses Google Traffic to Rule the IoT Kimwolf botnet Android TV, ENS EtherHiding C2
  • Malware

The Wolf Among TVs: 1.8 Million-Strong Kimwolf Botnet Surpasses Google Traffic to Rule the IoT

Do Son December 20, 2025 0
Read More Read more about The Wolf Among TVs: 1.8 Million-Strong Kimwolf Botnet Surpasses Google Traffic to Rule the IoT
The End of SCSI: Windows Server 2025 Unlocks 70% Faster Storage with Native NVMe I/O Windows Server 2025 Native NVMe I/O, SCSI translation layer bypass
  • Windows

The End of SCSI: Windows Server 2025 Unlocks 70% Faster Storage with Native NVMe I/O

Do Son December 20, 2025 0
Read More Read more about The End of SCSI: Windows Server 2025 Unlocks 70% Faster Storage with Native NVMe I/O
110 Milliseconds of Truth: How Amazon Used “Lag” to Catch a North Korean Spy Amazon Redshift JDBC Driver RCE CVE-2026-8178 AWS Bahrain fire 2026 AWS UAE data center fire Amazon North Korean hacker keystroke latency, Arizona laptop farm infiltration
  • Cybercriminals

110 Milliseconds of Truth: How Amazon Used “Lag” to Catch a North Korean Spy

Do Son December 20, 2025 0
Read More Read more about 110 Milliseconds of Truth: How Amazon Used “Lag” to Catch a North Korean Spy
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response Unofficial_Website_1_1765876312JkHKOgrPlO
  • Press Release

Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response

cybernewswire December 19, 2025 0
Read More Read more about Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
Pay to Post: Meta Tests 2-Link Monthly Limit for Unverified Facebook Creators Meta Paid Link Sharing, Facebook Two-Link Limit
  • Technology

Pay to Post: Meta Tests 2-Link Monthly Limit for Unverified Facebook Creators

Do Son December 19, 2025 0
Read More Read more about Pay to Post: Meta Tests 2-Link Monthly Limit for Unverified Facebook Creators
The AI Super App Arrives: OpenAI Launches ChatGPT App Directory to Rule Your Digital Life ChatGPT App Directory Launch, OpenAI AI Super App
  • Technology

The AI Super App Arrives: OpenAI Launches ChatGPT App Directory to Rule Your Digital Life

Do Son December 19, 2025 0
Read More Read more about The AI Super App Arrives: OpenAI Launches ChatGPT App Directory to Rule Your Digital Life
Fusion of Power: Trump Media Inks $6 Billion Merger to Build World’s First Fusion Power Plant Fractile AI inference chip AI Market Trends 2025, Similarweb AI Report
  • Technology

Fusion of Power: Trump Media Inks $6 Billion Merger to Build World’s First Fusion Power Plant

Do Son December 19, 2025 0
Read More Read more about Fusion of Power: Trump Media Inks $6 Billion Merger to Build World’s First Fusion Power Plant
FIFA’s Post-EA Comeback: Netflix to Launch a Reimagined Football Game for the 2026 World Cup FIFA Netflix game FIFA post-EA era
  • Technology

FIFA’s Post-EA Comeback: Netflix to Launch a Reimagined Football Game for the 2026 World Cup

Do Son December 19, 2025 0
Read More Read more about FIFA’s Post-EA Comeback: Netflix to Launch a Reimagined Football Game for the 2026 World Cup
The Grand Divorce: TikTok Signs Landmark Deal to Hand U.S. Control to Oracle-Led Group TikTok USDS Joint Venture LLC, TikTok U.S. divestment 2026 TikTok Deal, ByteDance Divestment U.S. ban TikTok TikTok Sale, Trump Announcement TikTok lawsuit Trump Amazon Acquisition
  • Technology

The Grand Divorce: TikTok Signs Landmark Deal to Hand U.S. Control to Oracle-Led Group

Do Son December 19, 2025 0
Read More Read more about The Grand Divorce: TikTok Signs Landmark Deal to Hand U.S. Control to Oracle-Led Group
Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel Linux Kernel 7.1 release Linux Kernel update, AMD ZEN 6 support, Linux driver fixes Linux Kernel 7.1 i486 support Linux 7.0 HIPPI support removal, legacy networking protocol retirement Linus Torvalds AI slop Linux kernel, Lorenzo Stoakes AI tool debate Linux Kernel Rust CVE-2025-68260, Android Binder Rust Race Condition TSEM Security Module Controversy, Linus Torvalds LSM Dispute Kernel Panic, PoC released Linux Kernel 6.16, File System Fixes CVE-2023-42753 - Linux Kernel Developers
  • Linux
  • Vulnerability Report

Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel

Do Son December 19, 2025 0
Read More Read more about Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel
Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts Kibana Vega XSS, Elastic Stack Security CVE-2024-37287 - Kibana security update
  • Vulnerability Report

Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts

Do Son December 19, 2025 0
Read More Read more about Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts
Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption CVE-2022-23307 Log4j TLS Bypass, Socket Appender Vulnerability
  • Vulnerability Report

Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption

Do Son December 19, 2025 0
Read More Read more about Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-16498CVSS 10.0
    The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse...
  • CVE-2026-66713CVSS 9.8
    Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache...
  • CVE-2026-11841CVSS 9.4
    An attacker may perform unauthenticated read and write operations on sensitive filesystem...
  • CVE-2026-16462CVSS 9.8
    In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows...
  • CVE-2026-11756CVSS 10.0
    A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE...
  • CVE-2026-15014CVSS 9.8
    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications &...
  • CVE-2026-14545CVSS 9.8
    The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when...
  • CVE-2021-32088CVSS 9.8
    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273....
  • CVE-2021-32086CVSS 9.8
    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273....
  • CVE-2021-32084CVSS 9.8
    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273....
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.