Skip to content
July 29, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Windows 11 Bug Makes Lock Screen Password Icon Vanish After Update Windows Secure Lock Screen Clock Lag Windows 11 KB5079391 error Windows 11 Kernel Driver Trust Microslop Windows 11 Windows 11 modem driver removal 2026, CVE-2025-24052 Agere driver exploit Windows 11 Password Icon Bug Lock Screen Glitch Windows 11 26H1 ARM Snapdragon X2 Windows 11 Reboot-Free, Insider Build Windows Update Error, 0x80070103 File Explorer, NTLM leak Windows bug, WinRE Windows Update, UAC prompts Secure Boot Certificate, Windows Security Windows 11 22H2 Installation security updates Windows UEFI CA 2023 Windows 11 25H2
  • Windows

Windows 11 Bug Makes Lock Screen Password Icon Vanish After Update

Do Son December 1, 2025 0
Read More Read more about Windows 11 Bug Makes Lock Screen Password Icon Vanish After Update
Google’s Pixel AI Strategy: Focusing on ‘Tangible Benefits,’ Not Just Hype Google Pixel 10, Tensor G5Pixel AI Strategy Auto Best Take
  • Android

Google’s Pixel AI Strategy: Focusing on ‘Tangible Benefits,’ Not Just Hype

Do Son December 1, 2025 0
Read More Read more about Google’s Pixel AI Strategy: Focusing on ‘Tangible Benefits,’ Not Just Hype
OpenAI Under Siege: Google’s Gemini 3 Surge Threatens to End ChatGPT’s Early Lead OpenAI confidential IPO filing OpenAI code signing certificate rotation AI private equity joint ventures OpenAI Axios Supply Chain Attack OpenAI Promptfoo acquisition OpenAI military resignation ChatGPT Plus military fraud OpenAI smart speaker Jony Ive OpenAI Frontier platform ChatGPT AI age prediction 2026, OpenAI Persona age verification Sarah Friar OpenAI infrastructure, AI Scaling Law revenue OpenAI Gumdrop AI pen, Jony Ive OpenAI hardware 2027 OpenAI New CRO, Denise Dresser Monetization Strategy OpenAI Competitive Pressure Gemini 3 Overtake OpenAI Infrastructure, AI Closed Loop Economy
  • Technology

OpenAI Under Siege: Google’s Gemini 3 Surge Threatens to End ChatGPT’s Early Lead

Do Son December 1, 2025 0
Read More Read more about OpenAI Under Siege: Google’s Gemini 3 Surge Threatens to End ChatGPT’s Early Lead
Android Hotspot Upgrade: New Feature Allows Simultaneous 2.4 GHz + 6 GHz Dual-Band Sharing Android Dual-Band Hotspot 2.4 GHz + 6 GHz Wi-Fi
  • Android

Android Hotspot Upgrade: New Feature Allows Simultaneous 2.4 GHz + 6 GHz Dual-Band Sharing

Do Son December 1, 2025 0
Read More Read more about Android Hotspot Upgrade: New Feature Allows Simultaneous 2.4 GHz + 6 GHz Dual-Band Sharing
Operation Hanoi Thief: Hackers Use ‘Pseudo-Polyglot’ LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading LOTUSHARVEST Stealer, Pseudo-Polyglot LNK
  • Cybercriminals

Operation Hanoi Thief: Hackers Use ‘Pseudo-Polyglot’ LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading

Do Son December 1, 2025 0
Read More Read more about Operation Hanoi Thief: Hackers Use ‘Pseudo-Polyglot’ LNK/Image to Deploy LOTUSHARVEST Stealer via DLL Sideloading
Critical Devolutions Server Flaw (CVE-2025-13757) Allows Authenticated SQL Injection to Steal All Passwords shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

Critical Devolutions Server Flaw (CVE-2025-13757) Allows Authenticated SQL Injection to Steal All Passwords

Do Son December 1, 2025 0
Read More Read more about Critical Devolutions Server Flaw (CVE-2025-13757) Allows Authenticated SQL Injection to Steal All Passwords
New TangleCrypt Packer Hides EDR Killer, But Coding Flaws Cause Ransomware to Crash Unexpectedly RedLineCyber Clipboard Hijacker TangleCrypt Packer, STONESTOP EDR Killer Gamaredon APT - BoneSpy and PlainGnome
  • Malware

New TangleCrypt Packer Hides EDR Killer, But Coding Flaws Cause Ransomware to Crash Unexpectedly

Do Son December 1, 2025 0
Read More Read more about New TangleCrypt Packer Hides EDR Killer, But Coding Flaws Cause Ransomware to Crash Unexpectedly
Russian Tomiris APT Adopts “Polyglot” Strategy, Hijacking Telegram/Discord as Covert C2 for Diplomatic Spies Tomiris APT, Polyglot C2
  • Cyber Security
  • Malware

Russian Tomiris APT Adopts “Polyglot” Strategy, Hijacking Telegram/Discord as Covert C2 for Diplomatic Spies

Do Son December 1, 2025 0
Read More Read more about Russian Tomiris APT Adopts “Polyglot” Strategy, Hijacking Telegram/Discord as Covert C2 for Diplomatic Spies
High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF CVE-2023-25157 GeoServer XXE, Unauthenticated File Exfiltration
  • Vulnerability Report

High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF

Do Son December 1, 2025 0
Read More Read more about High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices TAG-150 CastleLoader, ClickFix MaaS NetSupport RAT ClickFix, Multi-Cluster RMM
  • Cybercriminals

New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices

Do Son December 1, 2025 0
Read More Read more about New MaaS Operator TAG-150 Uses ClickFix Lure and Custom CastleLoader to Compromise 469 US Devices
North Korea’s “Contagious Interview” Floods npm with 200 New Packages, Using Fake Crypto Jobs to Deploy OtterCookie Spyware BlueNoroff macOS Attack GhostCall Campaign Carding Underground Bulletproof Hosting DPRK Contagious Interview, npm Flood Stonefly group -HiatusRAT Actors
  • Cyber Security

North Korea’s “Contagious Interview” Floods npm with 200 New Packages, Using Fake Crypto Jobs to Deploy OtterCookie Spyware

Do Son December 1, 2025 0
Read More Read more about North Korea’s “Contagious Interview” Floods npm with 200 New Packages, Using Fake Crypto Jobs to Deploy OtterCookie Spyware
ShadowV2 Mirai Botnet Launched Coordinated IoT Test Attack During Global AWS Outage ShadowV2 Mirai, AWS Outage Attack
  • Malware

ShadowV2 Mirai Botnet Launched Coordinated IoT Test Attack During Global AWS Outage

Do Son December 1, 2025 0
Read More Read more about ShadowV2 Mirai Botnet Launched Coordinated IoT Test Attack During Global AWS Outage
Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing Harvester APT Linux Backdoor OT Cyberattack Iranian APT Operation Olalampo MuddyWater APT Prince of Persia APT, Tonnerre v50 Patchwork APT, DLL Sideloading Subtle Snail, cyber espionage ShadowSilk, cyber espionage Volt Typhoon APT Group - Chinese Cybersecurity Firm
  • Cyber Security
  • Malware

Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing

Do Son December 1, 2025 0
Read More Read more about Bloody Wolf APT Expands to Central Asia, Deploys NetSupport RAT via Custom Java Droppers and Geo-Fencing
Google Assembles Foxconn/Samsung Supply Chain for Q4 2026 AI Glasses Launch Google AI Glasses Foxconn Samsung Supply Chain
  • Android

Google Assembles Foxconn/Samsung Supply Chain for Q4 2026 AI Glasses Launch

Do Son November 29, 2025 0
Read More Read more about Google Assembles Foxconn/Samsung Supply Chain for Q4 2026 AI Glasses Launch
EU Launches Probe: Are Apple Maps & Apple Ads Next for DMA Gatekeeper Status? Apple Maps Apple Ads DMA EU Gatekeeper Probe
  • Technology

EU Launches Probe: Are Apple Maps & Apple Ads Next for DMA Gatekeeper Status?

Do Son November 29, 2025 0
Read More Read more about EU Launches Probe: Are Apple Maps & Apple Ads Next for DMA Gatekeeper Status?
Critical Alert: Apache Kvrocks ‘RESET’ Command Flaw Grants Admin Privileges Apache Kvrocks, Privilege Escalation
  • Vulnerability Report

Critical Alert: Apache Kvrocks ‘RESET’ Command Flaw Grants Admin Privileges

Do Son November 29, 2025 0
Read More Read more about Critical Alert: Apache Kvrocks ‘RESET’ Command Flaw Grants Admin Privileges
CISA Flags Actively Exploited OpenPLC Flaw (CVE-2021-26829) n8n RCE Vulnerability CVE-2025-68613 CISA KEV WinRAR Zero-Day, Cloud Files UAF OpenPLC ScadaBR, CVE-2021-26829 CISA KEV, Gladinet LFI RCE XWiki RCE, VMware EoP CISA KEV CISA, Known Exploited Vulnerabilities CVE-2020-2883 CISA, Trend Micro
  • Vulnerability Report

CISA Flags Actively Exploited OpenPLC Flaw (CVE-2021-26829)

Do Son November 29, 2025 0
Read More Read more about CISA Flags Actively Exploited OpenPLC Flaw (CVE-2021-26829)
The Authentication Gap Among Retail Shift Workers: Implications and Risks Undertow Vulnerability CVE-2025-12543 CVE-2025-0107: PoC Exploit Code Undersea Cable Security, China Tech Ban
  • Technique

The Authentication Gap Among Retail Shift Workers: Implications and Risks

Do Son November 28, 2025
Read More Read more about The Authentication Gap Among Retail Shift Workers: Implications and Risks
OpenAI API Users Exposed in Mixpanel Security Breach ChatGPT Lockdown Mode OpenAI OpenClaw acquisition OpenAI Prism GPT-5.2 LaTeX, scientific research AI workspace OpenAI, Mixpanel Breach ChatGPT Data Preservation, NYT Lawsuit ChatGPT Apps SDK, super app OpenAI Jony Ive, AI Hardware Delay Musk Apple lawsuit, App Store antitrust UK AI Partnership, OpenAI Collaboration Jony Ive OpenAI, DoD Contract OpenAI Lawsuit, ChatGPT Privacy North Korea ChatGPT - GPT-4.5 model OpenAI Models, AI Advancements OpenAI pricing, Flex API
  • Data Leak

OpenAI API Users Exposed in Mixpanel Security Breach

Do Son November 28, 2025 0
Read More Read more about OpenAI API Users Exposed in Mixpanel Security Breach
Google Cuts Free Daily Quota for Gemini 3 Pro and Nano Banana Pro AI Models Gemini Free Quota Cut Nano Banana Pro Limit
  • Technology

Google Cuts Free Daily Quota for Gemini 3 Pro and Nano Banana Pro AI Models

Do Son November 28, 2025 0
Read More Read more about Google Cuts Free Daily Quota for Gemini 3 Pro and Nano Banana Pro AI Models
Pixel 10 Exclusive: Google Maps Launches Power-Saving Navigation Mode for 4-Hour Battery Boost Pixel 10 Power-Saving Navigation Google Maps Battery Saver
  • Android

Pixel 10 Exclusive: Google Maps Launches Power-Saving Navigation Mode for 4-Hour Battery Boost

Do Son November 28, 2025 0
Read More Read more about Pixel 10 Exclusive: Google Maps Launches Power-Saving Navigation Mode for 4-Hour Battery Boost
AWS Guarantees 60-Minute Recovery Time with New Route 53 Accelerated Recovery Motorola Smart Feed redirect Anthropic Amazon 5GW partnership Amazon Perplexity lawsuit AWS-LC Vulnerabilities Cryptographic Bypass AWS Middle East drone strikes Amazon layoffs 2026, Amazon AI restructuring Amazon Kindle DRM Policy, Publisher Control EPUB AWS Nova Forge AI Model Customization AWS Trainium3 EC2 Trn3 UltraServer Route 53 Accelerated Recovery AWS DNS Resilience AI Browser War, Amazon Comet Amazon layoffs, cost reduction AWS outage, DynamoDB DNS AWS outage, cloud dependency AWS VPN Client, Root Privilege Escalation WSA shutdown, Amazon Appstore Amazon Wondery, Podcast Restructuring Amazon Q2 2025 Generative AI AWS Client VPN, Privilege Escalation Amazon AI, Wearable AI
  • Technology

AWS Guarantees 60-Minute Recovery Time with New Route 53 Accelerated Recovery

Do Son November 28, 2025 0
Read More Read more about AWS Guarantees 60-Minute Recovery Time with New Route 53 Accelerated Recovery
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-58155CVSS 9.3
    Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,...
  • CVE-2026-58150CVSS 10.0
    Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade...
  • CVE-2026-57834CVSS 10.0
    Apache Traffic Server allows request smuggling if chunked messages are malformed. This...
  • CVE-2026-33267CVSS 10.0
    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache...
  • CVE-2026-41920CVSS 9.3
    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache...
  • CVE-2026-63234CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
  • CVE-2026-63233CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
  • CVE-2026-63232CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
  • CVE-2026-63230CVSS 9.1
    A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated...
  • CVE-2026-63229CVSS 9.1
    A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.