Skip to content
July 29, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Google Phone App Gets ‘Call Reason’: Mark Calls as Urgent to Ensure a Pick-Up Google Phone Call Reason Urgent Call Feature
  • Android

Google Phone App Gets ‘Call Reason’: Mark Calls as Urgent to Ensure a Pick-Up

Do Son December 3, 2025 0
Read More Read more about Google Phone App Gets ‘Call Reason’: Mark Calls as Urgent to Ensure a Pick-Up
Microsoft Update Breaks Dark Mode: File Explorer Now Flashes White on Launch KB5083769 Update Windows 11 24H2 end of support File Explorer White Flash Windows 11 Dark Mode Bug Windows 11 SE, End of Support Windows Update, Automatic Upgrade CVE-2023-38146 Windows 10
  • Windows

Microsoft Update Breaks Dark Mode: File Explorer Now Flashes White on Launch

Do Son December 3, 2025 0
Read More Read more about Microsoft Update Breaks Dark Mode: File Explorer Now Flashes White on Launch
Security Tightens: Let’s Encrypt Will Cap Certificate Validity at 45 Days by 2028 Let's Encrypt subscriber agreement Let's Encrypt OCSP Support 45-Day Certificate Limit Let's Encrypt Automation
  • Technology

Security Tightens: Let’s Encrypt Will Cap Certificate Validity at 45 Days by 2028

Do Son December 3, 2025 0
Read More Read more about Security Tightens: Let’s Encrypt Will Cap Certificate Validity at 45 Days by 2028
Red Alert at OpenAI: Ad Plans Dropped to Focus on ChatGPT Quality Amid Gemini Threat OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

Red Alert at OpenAI: Ad Plans Dropped to Focus on ChatGPT Quality Amid Gemini Threat

Do Son December 3, 2025 0
Read More Read more about Red Alert at OpenAI: Ad Plans Dropped to Focus on ChatGPT Quality Amid Gemini Threat
India Mandates SIM-Binding: WhatsApp and Telegram Users Must Re-verify Every 6 Hours WhatsApp antitrust API probe India SIM-Binding Mandate Messaging App KYC WhatsApp DMA Interoperability BirdyChat Haiket Denmark Social Media Ban CVE-2025-55177 WhatsApp vulnerability, zero-click flaw npm Malware, System Wipe WhatsApp Windows App, WebView2 Downgrade WhatsApp Ban, US House NSO WhatsApp, Pegasus Spyware WhatsApp iPad iPadOS app
  • Technology

India Mandates SIM-Binding: WhatsApp and Telegram Users Must Re-verify Every 6 Hours

Do Son December 3, 2025 0
Read More Read more about India Mandates SIM-Binding: WhatsApp and Telegram Users Must Re-verify Every 6 Hours
Critical cPanel Flaw (CVSS 9.3) Allows Directory Traversal LPE for Full Server Takeover cPanel WHM Vulnerabilities 2026 CVE-2026-29205 Arbitrary File Read cPanel Security Vulnerability Perl Injection Exploit cPanel Authentication WHM Security cPanel Privilege Escalation, Directory Traversal LPE
  • Vulnerability

Critical cPanel Flaw (CVSS 9.3) Allows Directory Traversal LPE for Full Server Takeover

Do Son December 3, 2025 0
Read More Read more about Critical cPanel Flaw (CVSS 9.3) Allows Directory Traversal LPE for Full Server Takeover
Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites ACF Extended RCE, Unauthenticated Code Execution
  • Vulnerability Report

Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites

Do Son December 3, 2025 0
Read More Read more about Critical ACF Extended Flaw (CVE-2025-13486, CVSS 9.8) Allows Unauthenticated RCE on 100K WordPress Sites
CISA Warns: Critical Longwatch RCE Flaw (CVE-2025-13658, CVSS 9.8) Allows Unauthenticated SYSTEM Takeover of OT Surveillance Longwatch Unauthenticated RCE, Industrial Video & Control
  • Vulnerability Report

CISA Warns: Critical Longwatch RCE Flaw (CVE-2025-13658, CVSS 9.8) Allows Unauthenticated SYSTEM Takeover of OT Surveillance

Do Son December 3, 2025 0
Read More Read more about CISA Warns: Critical Longwatch RCE Flaw (CVE-2025-13658, CVSS 9.8) Allows Unauthenticated SYSTEM Takeover of OT Surveillance
Malicious Rust Package ‘evm-units’ Exposes Crypto Developers to Stealth Attacks Rust Crates.io Backdoor, EVM Stealth Loader
  • Malware

Malicious Rust Package ‘evm-units’ Exposes Crypto Developers to Stealth Attacks

Do Son December 3, 2025 0
Read More Read more about Malicious Rust Package ‘evm-units’ Exposes Crypto Developers to Stealth Attacks
DOJ Seizes Domain of Burma’s Notorious Tai Chang Scam Compound to Disrupt ‘Pig Butchering’ Fraud Pig Butchering Takedown, Tai Chang Compound
  • Cybercriminals

DOJ Seizes Domain of Burma’s Notorious Tai Chang Scam Compound to Disrupt ‘Pig Butchering’ Fraud

Do Son December 3, 2025 0
Read More Read more about DOJ Seizes Domain of Burma’s Notorious Tai Chang Scam Compound to Disrupt ‘Pig Butchering’ Fraud
Chrome 143 Stable Fixes 13 Flaws: High-Severity V8 Type Confusion Earns $11,000 Bounty Chrome 148 lazy loading Chrome for Linux ARM64 Chrome 145 Update Chrome Security Fixes Chrome Security Update CVE-2026-1220 Chrome 144 Security Update CVE-2026-0899 Chrome Memory Safety, WebGPU UAF Chrome V8 Type Confusion, Google Updater Flaw Chrome V8 Flaw, CVE-2025-13042 Chrome V8, Type Confusion, Chrome 142 Update Chrome V8 Flaw, CVE-2025-12036 Chrome 141, WebGPU Overflow Google Chrome preloading Chrome, V8 vulnerability CVE-2025-9132 Chrome Security Update, Use-After-Free Chrome V8, Type Confusion Chrome Telemetry, Windows 10 EOL Microsoft Family Safety, Chrome Blocking Chrome Security Update, High-Severity Google Chrome, Antitrust CVE-2024-10487 and CVE-2024-10488 Google Chrome Root Program Chrome Update, CVE-2025-3619 Chrome Acquisition, Perplexity.ai
  • Vulnerability Report

Chrome 143 Stable Fixes 13 Flaws: High-Severity V8 Type Confusion Earns $11,000 Bounty

Do Son December 3, 2025 0
Read More Read more about Chrome 143 Stable Fixes 13 Flaws: High-Severity V8 Type Confusion Earns $11,000 Bounty
Django Flaw (CVE-2025-13372) Allows SQL Injection in PostgreSQL FilteredRelation Django Security Update CVE-2026-25673 Django Security Update SQL Injection Vulnerability Django SQL Injection, PostgreSQL Flaw CVE-2022-34265 PoC Django, SQL injection
  • Vulnerability Report

Django Flaw (CVE-2025-13372) Allows SQL Injection in PostgreSQL FilteredRelation

Do Son December 3, 2025 0
Read More Read more about Django Flaw (CVE-2025-13372) Allows SQL Injection in PostgreSQL FilteredRelation
CISA Warns: Critical Iskra iHUB Flaw (CVE-2025-13510) Allows Unauthenticated Smart Metering Takeover Iskra iHUB Auth Bypass, Critical Smart Metering Flaw
  • Vulnerability Report

CISA Warns: Critical Iskra iHUB Flaw (CVE-2025-13510) Allows Unauthenticated Smart Metering Takeover

Do Son December 3, 2025 0
Read More Read more about CISA Warns: Critical Iskra iHUB Flaw (CVE-2025-13510) Allows Unauthenticated Smart Metering Takeover
Critical Elementor Plugin Flaw (CVE-2025-8489, CVSS 9.8) Under Active Exploitation Allows Unauthenticated Admin Takeover Elementor Unauthenticated EoP, CVE-2025-8489 Exploitation WordPress Privilege Escalation, WP Freeio WordPress backdoor Jupiter X Core - CVE-2024-7781 & CVE-2024-7782
  • Vulnerability Report

Critical Elementor Plugin Flaw (CVE-2025-8489, CVSS 9.8) Under Active Exploitation Allows Unauthenticated Admin Takeover

Do Son December 3, 2025 0
Read More Read more about Critical Elementor Plugin Flaw (CVE-2025-8489, CVSS 9.8) Under Active Exploitation Allows Unauthenticated Admin Takeover
High-Severity Angular Flaw (CVE-2025-66412) Allows Stored XSS via SVG and MathML Bypass Angular hostname hijacking vulnerability Angular SSRF Origin Hijacking Angular XSS Vulnerability CVE-2026-32635 Angular i18n XSS CVE-2026-27970 Angular SSR SSRF CVE-2026-27739 Angular Vulnerability CVE-2026-22610 CVE-2025-59052 Angular security Angular XSS Bypass, SVG Injection
  • Vulnerability Report

High-Severity Angular Flaw (CVE-2025-66412) Allows Stored XSS via SVG and MathML Bypass

Do Son December 3, 2025 0
Read More Read more about High-Severity Angular Flaw (CVE-2025-66412) Allows Stored XSS via SVG and MathML Bypass
Discontinued Library: High-Severity lz4-java Flaw (CVE‐2025‐12183) Forces Immediate Migration to Community Fork lz4-java Out-of-bounds Read, Library EOL
  • Vulnerability Report

Discontinued Library: High-Severity lz4-java Flaw (CVE‐2025‐12183) Forces Immediate Migration to Community Fork

Do Son December 3, 2025 0
Read More Read more about Discontinued Library: High-Severity lz4-java Flaw (CVE‐2025‐12183) Forces Immediate Migration to Community Fork
Cyber Startup Frenetik Launches with Patented Deception Technology That Bets Against the AI Arms Race frenetik_17640073059qwMUZNORw
  • Press Release

Cyber Startup Frenetik Launches with Patented Deception Technology That Bets Against the AI Arms Race

cybernewswire December 2, 2025 0
Read More Read more about Cyber Startup Frenetik Launches with Patented Deception Technology That Bets Against the AI Arms Race
AI Adoption Surges While Governance Lags — Report Warns of Growing Shadow Identity Risk AI-Data-Security-Report-Image-2_1764604257jUacyOMyCu
  • Press Release

AI Adoption Surges While Governance Lags — Report Warns of Growing Shadow Identity Risk

cybernewswire December 2, 2025 0
Read More Read more about AI Adoption Surges While Governance Lags — Report Warns of Growing Shadow Identity Risk
Apple AI Shakeup: Giannandrea Out, Former Google Gemini Chief Amar Subramanya Hired Apple Spring Event 2026 Apple Intel 14A iPhone 2028, Intel Foundry Apple Silicon iPhone 18 glass cloth shortage, Nittobo T-glass Apple crisis Apple UK App Store lawsuit appeal, Apple tax £1.5bn damages Apple AI Leadership Shakeup Giannandrea Subramanya Touchscreen MacBook Pro Apple 2026 Roadmap Apple Smart Home, Desktop Robot Apple H3 Chip, AirPods Camera Apple chips, on-device AI Apple AI, retail chatbot MacBook, Affordable Foldable iPhone, Apple Strategy Apple COO, Leadership Transition DOJ Lawsuit Apple EU Policy, App Store Fees CVE-2024-23222 Apple French antitrust fine
  • Technology

Apple AI Shakeup: Giannandrea Out, Former Google Gemini Chief Amar Subramanya Hired

Do Son December 2, 2025 0
Read More Read more about Apple AI Shakeup: Giannandrea Out, Former Google Gemini Chief Amar Subramanya Hired
Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration snoesta_17645641359YKXX9ahRy
  • Press Release

Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration

cybernewswire December 2, 2025 0
Read More Read more about Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration
Alarm: Coupang Data Breach Exposes 33.7 Million Users—Over Half of South Korea Fiverr Data Leak Claude Code Leak Anthropic DMCA Takedown Coupang 33.7M Breach South Korea Data Leak Red Hat Breach, Customer Data Theft Farmers Insurance, Salesforce ESLint Plugin -Mamont Android banking Trojan
  • Data Leak

Alarm: Coupang Data Breach Exposes 33.7 Million Users—Over Half of South Korea

Do Son December 2, 2025 0
Read More Read more about Alarm: Coupang Data Breach Exposes 33.7 Million Users—Over Half of South Korea
Europol Shuts Down CryptoMixer, Seizes €25 Million in Bitcoin & 12 TB of Data Europol CryptoMixer Takedown Centralized Mixer Seizure
  • Cybercriminals

Europol Shuts Down CryptoMixer, Seizes €25 Million in Bitcoin & 12 TB of Data

Do Son December 2, 2025 0
Read More Read more about Europol Shuts Down CryptoMixer, Seizes €25 Million in Bitcoin & 12 TB of Data
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-63234CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
  • CVE-2026-63233CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
  • CVE-2026-63232CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
  • CVE-2026-63230CVSS 9.1
    A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated...
  • CVE-2026-63229CVSS 9.1
    A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated...
  • CVE-2026-63227CVSS 9.9
    An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated...
  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …...
  • CVE-2026-64863CVSS 9.1
    goshs is a feature-rich single-binary file server for red teamers and developers....
  • CVE-2026-62325CVSS 9.1
    goshs is a feature-rich single-binary file server for red teamers and developers....
  • CVE-2026-54658CVSS 9.8
    Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue()...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.