Skip to content
July 29, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
China APT UNC5174 Hijacks Discord API as Covert C2 Channel to Evade Detection and Conduct Espionage Discord C2, UNC5174 Espionage
  • Cybercriminals
  • Malware

China APT UNC5174 Hijacks Discord API as Covert C2 Channel to Evade Detection and Conduct Espionage

Do Son December 6, 2025 0
Read More Read more about China APT UNC5174 Hijacks Discord API as Covert C2 Channel to Evade Detection and Conduct Espionage
Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing G2_PR_Winter_1764779986pS3XAjIIlK
  • Press Release

Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing

cybernewswire December 5, 2025 0
Read More Read more about Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing
Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM webinar_sns2_1764913495pMKY77PH7j
  • Press Release

Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM

cybernewswire December 5, 2025 0
Read More Read more about Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM
Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations

Do Son December 5, 2025 0
Read More Read more about Honesty is the Best Policy: OpenAI Trains AI Models to ‘Confess’ Errors and Hallucinations
New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use Android Call Scam Protection 30-Second Fraud Delay
  • Android

New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use

Do Son December 5, 2025 0
Read More Read more about New Android Call Scam Protection Pauses Calls for 30 Seconds During Financial App Use
Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime Apple HomePad delay Tesla CarPlay integration 2026 Apple CarPlay AI integration 2026 Apple 2026 product roadmap rumors, foldable iPhone release date Apple Vision Pro sales slump, Vision Pro production cut Russia FaceTime Ban Network Blockade Apple Apple 2026 Roadmap, iPhone Foldable, Apple Intelligence Apple Maps ads, iOS monetization Apple, Digital Markets Act FCC Leak, iPhone 16e Schematics iPhone Fold Apple Made in India Apple US Investment, Indian Tariffs Apple Leadership, Tim Cook Tenure Siri Redesign, Apple AI Apple App Store Apple EU, Digital Markets Act CVE-2022-32898 Third-Party iOS Apps Apple Antitrust, DOJ Lawsuit
  • Technology

Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime

Do Son December 5, 2025 0
Read More Read more about Russia Imposes Network-Level Blockade on Apple’s End-to-End Encrypted FaceTime
Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass CVE-2024-40725 & CVE-2024-40898 Apache SSRF NTLM Leak, suexec Bypass
  • Vulnerability Report

Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass

Do Son December 5, 2025 0
Read More Read more about Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion USB LNK Cryptominer, Smart Mining Evasion
  • Malware

Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion

Do Son December 5, 2025 0
Read More Read more about Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core Apache Tika XXE, Malicious PDF Exploit Apache Tika, XXE vulnerability CVE-2025-54988
  • Vulnerability Report

The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core

Do Son December 5, 2025 0
Read More Read more about The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
“React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure Check Point VPN vulnerability exploited in the wild Check Point VPN exploit CVE-2026-50751 zero-day Checkmarx Breach Supply Chain Attack Ivanti EPMM RCE CVE-2026-1281 Modular DS Vulnerability CVE-2026-23550 D-Link RCE Vulnerability CVE-2026-0625 Christmas 2025 GreyNoise Campaign, Japan-Based Initial Access Broker React2Shell Zero-Day, APT Active Exploitation WordPress vulnerability, authentication bypass FreePBX, zero-day Trend Micro Apex One, Remote Code Execution BitoPro Hack, Crypto Theft UNC5337 - CVE-2022-47945 Safe{Wallet} hack Fortinet vulnerability, CVE-2024-21762, FortiGate attack Balloonfly, Play ransomware Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
  • Vulnerability Report

“React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure

Do Son December 5, 2025 0
Read More Read more about “React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Malware

Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection

Do Son December 5, 2025 0
Read More Read more about Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows Splunk Enterprise vulnerabilities, CVSS 9.8 flaw, CVE-2026-20253, CVE-2026-20251, CVE-2026-20258 Splunk Enterprise Vulnerabilities CVE-2026-20240 Splunk RCE CVE-2026-20204 Splunk RCE Vulnerability CVE-2026-20163 Splunk Enterprise Vulnerabilities CVE-2026-20140 Splunk Permission Flaw, Local Privilege Escalation Splunk Vulnerabilities CVE-2024-53247 - Splunk Secure Gateway App CVE-2025-20229 & CVE-2025-20231
  • Vulnerability Report

High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows

Do Son December 5, 2025 0
Read More Read more about High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows
High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection CVE-2024-25641 Cacti SNMP RCE, Command Injection
  • Vulnerability Report

High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection

Do Son December 5, 2025 0
Read More Read more about High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection
Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure Calisto RSF Espionage, AiTM Phishing Lure
  • Cyber Security

Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure

Do Son December 5, 2025 0
Read More Read more about Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure
NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption NVIDIA DGX Cloud restructuring, Dwight Diercks engineering shift NVIDIA Isaac Launchable, Hard-coded Credentials NVIDIA Merlin Deserialization, AI Pipeline RCE Triton DoS Flaws, AI Inference Server Security NVIDIA AI programming AI Chips China 800VDC Data Center, AI Power Architecture CVE-2024-0114 NVIDIA Container Toolkit vulnerability Container escape
  • Vulnerability Report

NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption

Do Son December 5, 2025 0
Read More Read more about NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption
Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage Patchwork StreamSpy, WebSocket C2
  • Cyber Security
  • Malware

Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage

Do Son December 5, 2025 0
Read More Read more about Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
AI Demand Struggles: Microsoft Slashes Enterprise AI Sales Quotas by Up to 50% Microsoft Strategic Market Status investigation Dell CES 2026 AI PC marketing, Microsoft Copilot+ PC consumer apathy Microsoft AI Sales Quota Enterprise AI Demand Edge Copilot, AI browsing
  • Technology

AI Demand Struggles: Microsoft Slashes Enterprise AI Sales Quotas by Up to 50%

Do Son December 5, 2025 0
Read More Read more about AI Demand Struggles: Microsoft Slashes Enterprise AI Sales Quotas by Up to 50%
No More SMS: Telegram is Developing Passkey Authentication for Secure Login Telegram Bot Formatting HTML formatting, Markdown update, bot development Telegram Passkey SMS Login Replacement Telegram Zero-Click Vulnerability
  • Technology

No More SMS: Telegram is Developing Passkey Authentication for Secure Login

Do Son December 5, 2025 0
Read More Read more about No More SMS: Telegram is Developing Passkey Authentication for Secure Login
SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware SpyCloud_wordmark_square_1764614423dsLEchjEU4
  • Press Release

SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware

cybernewswire December 4, 2025 0
Read More Read more about SpyCloud Data Shows Corporate Users 3x More Likely to Be Targeted by Phishing Than by Malware
Policy U-Turn: India Drops Mandatory Sanchar Saathi App After Fierce Opposition Sanchar Saathi Mandatory Reversal India App U-Turn
  • Technology

Policy U-Turn: India Drops Mandatory Sanchar Saathi App After Fierce Opposition

Do Son December 4, 2025 0
Read More Read more about Policy U-Turn: India Drops Mandatory Sanchar Saathi App After Fierce Opposition
AWS Trainium Chip Business Hits Multi-Billion Revenue, Challenging NVIDIA’s Pricing AWS Trainium Revenue AI Chip Price-Performance
  • Technology

AWS Trainium Chip Business Hits Multi-Billion Revenue, Challenging NVIDIA’s Pricing

Do Son December 4, 2025 0
Read More Read more about AWS Trainium Chip Business Hits Multi-Billion Revenue, Challenging NVIDIA’s Pricing
Design Wars: Meta Hires Apple Veteran Alan Dye to Lead New Reality Labs Creative Studio Meta Reality Labs restructuring, AI wearables pivot Meta Alan Dye Hire Apple Design Defection smart glasses, Ray-Ban Display
  • Technology

Design Wars: Meta Hires Apple Veteran Alan Dye to Lead New Reality Labs Creative Studio

Do Son December 4, 2025 0
Read More Read more about Design Wars: Meta Hires Apple Veteran Alan Dye to Lead New Reality Labs Creative Studio
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-64863CVSS 9.1
    goshs is a feature-rich single-binary file server for red teamers and developers....
  • CVE-2026-62325CVSS 9.1
    goshs is a feature-rich single-binary file server for red teamers and developers....
  • CVE-2026-54658CVSS 9.8
    Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue()...
  • CVE-2026-14973CVSS 9.3
    IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can...
  • CVE-2026-14959CVSS 9.1
    IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated...
  • CVE-2026-14958CVSS 9.1
    IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated...
  • CVE-2026-14512CVSS 9.8
    IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication...
  • CVE-2026-14446CVSS 9.8
    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access...
  • CVE-2026-6881CVSS 9.4
    A SQL Injection in the Giving Reports functionality in Ellucian Advance Web...
  • CVE-2026-16498CVSS 10.0
    The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.