Skip to content
July 29, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
FrostBeacon Hits Russian B2B: Cobalt Strike Deployed via LNK and Chained Legacy Exploits Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Malware

FrostBeacon Hits Russian B2B: Cobalt Strike Deployed via LNK and Chained Legacy Exploits

Do Son December 10, 2025 0
Read More Read more about FrostBeacon Hits Russian B2B: Cobalt Strike Deployed via LNK and Chained Legacy Exploits
Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS ZITADEL Vulnerability CVE-2026-29191 CVE-2025-27507 ZITADEL SSRF, Login UI Hijack
  • Vulnerability Report

Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS

Do Son December 10, 2025 0
Read More Read more about Critical ZITADEL Flaws (CVE-2025-67494, CVSS 9.3) Risk SSRF Internal Breach and Account Hijack via XSS
The 25% Cut: Trump Allows NVIDIA H200 Export to China Under Strict Fee NVIDIA CoreWeave investment NVIDIA H200 China, AI Chip Export Fee
  • Technology

The 25% Cut: Trump Allows NVIDIA H200 Export to China Under Strict Fee

Do Son December 9, 2025 0
Read More Read more about The 25% Cut: Trump Allows NVIDIA H200 Export to China Under Strict Fee
Critical Emby Server Flaw (CVE-2025-64113) Allows Unauthenticated Admin Takeover Emby Auth Bypass, Plugin Quick Fix
  • Vulnerability Report

Critical Emby Server Flaw (CVE-2025-64113) Allows Unauthenticated Admin Takeover

Do Son December 9, 2025 0
Read More Read more about Critical Emby Server Flaw (CVE-2025-64113) Allows Unauthenticated Admin Takeover
Final Patch of 2025: Critical SAP Solution Manager Flaw (CVE-2025-42880, CVSS 9.9) Risks Full System Compromise SAP Security Patch May 2026 CVE-2026-34260 S/4HANA CVE-2024-22127 - CVE-2025-27434 SAP Solution Manager Code Injection, Critical SAP Patch
  • Vulnerability Report

Final Patch of 2025: Critical SAP Solution Manager Flaw (CVE-2025-42880, CVSS 9.9) Risks Full System Compromise

Do Son December 9, 2025 0
Read More Read more about Final Patch of 2025: Critical SAP Solution Manager Flaw (CVE-2025-42880, CVSS 9.9) Risks Full System Compromise
macOS Privilege Escalation Flaw Bypasses Patch for Root Access, Poc Releases! macOS Privilege Escalation, .zprofile Exploit
  • Vulnerability

macOS Privilege Escalation Flaw Bypasses Patch for Root Access, Poc Releases!

Do Son December 9, 2025 0
Read More Read more about macOS Privilege Escalation Flaw Bypasses Patch for Root Access, Poc Releases!
Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568) shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)

Do Son December 9, 2025 0
Read More Read more about Critical Authentication Bypass Flaws Discovered in Ruby SAML Library (CVE-2025-66567 & CVE-2025-66568)
CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack Ivanti EPMM Vulnerability CVE-2026-1340 CISA KEV Catalog CVE-2026-21385 CISA KEV Update CVE-2008-0015 CISA KEV, Array Networks Command Injection CVE-2025-0111 & CVE-2025-23209 CISA, Known Exploited Vulnerabilities
  • Vulnerability Report

CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack

Do Son December 9, 2025 0
Read More Read more about CISA KEV Alert: EOL D-Link and Array Networks Command Injection Under Active Attack
Samsung Foundry Hits 60% 4nm Yield, Secures $100M AI Chip Order from Tsavorite Samsung MagicInfo9 Vulnerability CVE-2026-25202 Galaxy S26 benchmarks Samsung HBM4 NVIDIA certification Samsung Bixby Perplexity integration, One UI 8.5 AI assistant Samsung Taylor 2nm mass production, TSMC 2nm capacity constraint 2026 Samsung SATA SSD Discontinuation, SSD Market Shift Samsung SATA SSD Discontinuation, M.2 Market Shift Samsung Foundry 4nm Yield Tsavorite OPU Chip Order Samsung Project Moohan, Android XR Samsung OpenAI Partnership, AI Infrastructure Samsung Exynos 2600, 2nm GAA Tesla AI Chips, Samsung Foundry Deal Samsung Foldables, Galaxy Unpacked 2025 Samsung AI, Perplexity AI Samsung data breach Q990D firmware US tariffs
  • Technology

Samsung Foundry Hits 60% 4nm Yield, Secures $100M AI Chip Order from Tsavorite

Do Son December 9, 2025 0
Read More Read more about Samsung Foundry Hits 60% 4nm Yield, Secures $100M AI Chip Order from Tsavorite
Ad Code Found in ChatGPT Android Build, OpenAI Denies Current Advertising Tests OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

Ad Code Found in ChatGPT Android Build, OpenAI Denies Current Advertising Tests

Do Son December 9, 2025 0
Read More Read more about Ad Code Found in ChatGPT Android Build, OpenAI Denies Current Advertising Tests
AI Uncovers GhostPenguin: Undetectable Linux Backdoor Used RC5-Encrypted UDP for Covert C2 WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Malware

AI Uncovers GhostPenguin: Undetectable Linux Backdoor Used RC5-Encrypted UDP for Covert C2

Do Son December 9, 2025 0
Read More Read more about AI Uncovers GhostPenguin: Undetectable Linux Backdoor Used RC5-Encrypted UDP for Covert C2
Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR Shanya Crypter, EDR Killer
  • Malware

Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR

Do Son December 9, 2025 0
Read More Read more about Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR
Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites Beima PHP Webshell, Cybercrime Freelancing
  • Malware

Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites

Do Son December 9, 2025 0
Read More Read more about Undetectable Beima Webshell Sold by College Student for Tuition Hijacks 5,200+ Gov/Edu Websites
Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected Go Typosquatting, Pastebin Exfiltration
  • Malware

Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected

Do Son December 9, 2025 0
Read More Read more about Silent Supply Chain Attack: Malicious Go Typosquat Siphoned Data to Pastebin for Four Years Undetected
Silver Fox APT Uses Cyrillic False Flag in Teams SEO Poisoning to Deploy ValleyRAT Silver Fox False Flag, Cyrillic SEO Poisoning
  • Cyber Security
  • Malware

Silver Fox APT Uses Cyrillic False Flag in Teams SEO Poisoning to Deploy ValleyRAT

Do Son December 9, 2025 0
Read More Read more about Silver Fox APT Uses Cyrillic False Flag in Teams SEO Poisoning to Deploy ValleyRAT
Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys Android zero day flaw June 2026 security bulletin RuTaxi Trojan Android Banking Malware Pixel 9 zero-click exploit, Dolby UDC vulnerability CVE-2025-54957 NexusRoute Android RAT, India E-Challan Phishing ClayRat Self-Defense, Android Accessibility Abuse Android Trojan, AntiDot Android Malware "BadPack"
  • Malware

Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys

Do Son December 9, 2025 0
Read More Read more about Evolved ClayRat Spyware Gains Self-Defense, Using Accessibility Abuse to Block Uninstallation and Steal Keys
New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming FvncBot Android Trojan, HVNC Screen Streaming
  • Malware

New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming

Do Son December 9, 2025 0
Read More Read more about New FvncBot Android Trojan Targets mBank Users with HVNC and H.264 Screen Streaming
JS#SMUGGLER Malware Evades EDR Using “Junk Code” JavaScript and Fileless PowerShell to Deploy NetSupport RAT JS#SMUGGLER, Junk Code Obfuscation
  • Malware

JS#SMUGGLER Malware Evades EDR Using “Junk Code” JavaScript and Fileless PowerShell to Deploy NetSupport RAT

Do Son December 9, 2025 0
Read More Read more about JS#SMUGGLER Malware Evades EDR Using “Junk Code” JavaScript and Fileless PowerShell to Deploy NetSupport RAT
Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage CastleRAT, Steam C2 Resolver
  • Malware

Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage

Do Son December 9, 2025 0
Read More Read more about Sophisticated CastleRAT Backdoor Uses Steam Community Pages as Covert C2 Resolver for Espionage
LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption LockBit LockBit 5.0 Resurgence, ETW Blinding Ransomware
  • Malware

LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption

Do Son December 9, 2025 0
Read More Read more about LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu Windows 11 AI Clutter File Explorer Context Menu
  • Windows

AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu

Do Son December 9, 2025 0
Read More Read more about AI Clutter Solved? Windows 11 Adds Setting to Disable AI Actions in File Explorer Menu
Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term Low carbon cloud computing Smartphone clusters, Green technology, Data centers, Google research Google Agentic AI search G Suite legacy free commercial reclassification 2026 Agent Payments Protocol AP2 Back-Button Hijacking Google Search AI headlines Google Play Store fee reduction Google Antigravity account recovery Google Advanced Air-Cooling Alphabet $185 billion CapEx 2026 Google Aluminum OS 2026 ai-disclosure HTML attribute, Chrome AI content transparency 2026 Google monopoly appeal 2026, Search data sharing stay Change @gmail.com address, Gmail email alias feature 2025 Google Play Store external download fees, Epic vs Google 2026 billing Google Dark Web Report Retirement, Data Breach Monitoring Google Antitrust One-Year Limit Default Search Contract Term Google AI Headlines Discover Headline Distortion Aluminium OS Android ChromeOS Merge Google Accelerator Impact $31.2 Billion Funding Google Texas Investment AI Data Center Expansion Google Play payments, external billing Gmail HIBP leak Privacy Sandbox Termination, Third-Party Cookies Google Strategic Market Status, CMA Antitrust ICEBlock Removal, DOJ Pressure Google Logo, AI Branding
  • Technology

Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term

Do Son December 9, 2025 0
Read More Read more about Google Antitrust Remedy: Judge Limits Default Search Contracts to One-Year Term
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64863CVSS 9.1
    goshs is a feature-rich single-binary file server for red teamers and developers....
  • CVE-2026-62325CVSS 9.1
    goshs is a feature-rich single-binary file server for red teamers and developers....
  • CVE-2026-54658CVSS 9.8
    Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue()...
  • CVE-2026-14973CVSS 9.3
    IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can...
  • CVE-2026-14959CVSS 9.1
    IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated...
  • CVE-2026-14958CVSS 9.1
    IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated...
  • CVE-2026-14512CVSS 9.8
    IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication...
  • CVE-2026-14446CVSS 9.8
    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access...
  • CVE-2026-6881CVSS 9.4
    A SQL Injection in the Giving Reports functionality in Ellucian Advance Web...
  • CVE-2026-16498CVSS 10.0
    The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.