Skip to content
September 21, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk Apache NiFi RCE CVE-2026-39816 Apache NiFi Vulnerability CVE-2026-25903 Apache NiFi Deserialization, GetAsanaObject Vulnerability CVE-2024-52067 - CVE-2024-56512 CVE-2025-27017
  • Vulnerability Report

Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk

Do Son December 22, 2025 0
Read More Read more about Apache NiFi’s Data Leak: How a High-Severity Deserialization Flaw Puts Your Asana Workflows at Risk
North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes Chinese espionage groups APT35 Phishing, Stormshield CTI
  • Malware

North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes

Do Son December 22, 2025 0
Read More Read more about North Korea’s Kimsuky Upgrades DOCSWAP Malware to Hijack Smartphones via QR Codes
“Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia Iranian Cyber Reconnaissance IP Camera Security NCSC Warning Russian Hacktivists Taiwan Cyberattacks China State-Sponsored Hacking state-sponsored threat actor Ransomware RAT Abuse, AnyDesk
  • Malware

“Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia

Do Son December 22, 2025 0
Read More Read more about “Caminho” to Compromise: BlindEagle Hackers Hijack Government Emails in Colombia
The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky BlueDelta Espionage, UKR.NET Phishing
  • Cyber Security

The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky

Do Son December 22, 2025 0
Read More Read more about The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users Dify API Key Exposure, LLM Security Dify Information Disclosure, LLM Security
  • Vulnerability Report

AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users

Do Son December 22, 2025 0
Read More Read more about AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
PoC Available: Unauthenticated HPE OneView RCE (CVSS 10.0) Exploits Hidden ID Pools API CVE-2025-37164, HPE OneView RCE
  • Vulnerability Report

PoC Available: Unauthenticated HPE OneView RCE (CVSS 10.0) Exploits Hidden ID Pools API

Do Son December 20, 2025 0
Read More Read more about PoC Available: Unauthenticated HPE OneView RCE (CVSS 10.0) Exploits Hidden ID Pools API
VR Vision Shift: Meta Pauses Third-Party Partnerships to Pivot Toward AI Smart Glasses Meta Horizon OS partnership pause, ASUS Lenovo VR headset cancellation
  • Technology

VR Vision Shift: Meta Pauses Third-Party Partnerships to Pivot Toward AI Smart Glasses

Do Son December 20, 2025 0
Read More Read more about VR Vision Shift: Meta Pauses Third-Party Partnerships to Pivot Toward AI Smart Glasses
The Wolf Among TVs: 1.8 Million-Strong Kimwolf Botnet Surpasses Google Traffic to Rule the IoT Kimwolf botnet Android TV, ENS EtherHiding C2
  • Malware

The Wolf Among TVs: 1.8 Million-Strong Kimwolf Botnet Surpasses Google Traffic to Rule the IoT

Do Son December 20, 2025 0
Read More Read more about The Wolf Among TVs: 1.8 Million-Strong Kimwolf Botnet Surpasses Google Traffic to Rule the IoT
The End of SCSI: Windows Server 2025 Unlocks 70% Faster Storage with Native NVMe I/O Windows Server 2025 Native NVMe I/O, SCSI translation layer bypass
  • Windows

The End of SCSI: Windows Server 2025 Unlocks 70% Faster Storage with Native NVMe I/O

Do Son December 20, 2025 0
Read More Read more about The End of SCSI: Windows Server 2025 Unlocks 70% Faster Storage with Native NVMe I/O
110 Milliseconds of Truth: How Amazon Used “Lag” to Catch a North Korean Spy Amazon Redshift JDBC Driver RCE CVE-2026-8178 AWS Bahrain fire 2026 AWS UAE data center fire Amazon North Korean hacker keystroke latency, Arizona laptop farm infiltration
  • Cybercriminals

110 Milliseconds of Truth: How Amazon Used “Lag” to Catch a North Korean Spy

Do Son December 20, 2025 0
Read More Read more about 110 Milliseconds of Truth: How Amazon Used “Lag” to Catch a North Korean Spy
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response Unofficial_Website_1_1765876312JkHKOgrPlO
  • Press Release

Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response

cybernewswire December 19, 2025 0
Read More Read more about Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
Pay to Post: Meta Tests 2-Link Monthly Limit for Unverified Facebook Creators Meta Paid Link Sharing, Facebook Two-Link Limit
  • Technology

Pay to Post: Meta Tests 2-Link Monthly Limit for Unverified Facebook Creators

Do Son December 19, 2025 0
Read More Read more about Pay to Post: Meta Tests 2-Link Monthly Limit for Unverified Facebook Creators
The AI Super App Arrives: OpenAI Launches ChatGPT App Directory to Rule Your Digital Life ChatGPT App Directory Launch, OpenAI AI Super App
  • Technology

The AI Super App Arrives: OpenAI Launches ChatGPT App Directory to Rule Your Digital Life

Do Son December 19, 2025 0
Read More Read more about The AI Super App Arrives: OpenAI Launches ChatGPT App Directory to Rule Your Digital Life
Fusion of Power: Trump Media Inks $6 Billion Merger to Build World’s First Fusion Power Plant Fractile AI inference chip AI Market Trends 2025, Similarweb AI Report
  • Technology

Fusion of Power: Trump Media Inks $6 Billion Merger to Build World’s First Fusion Power Plant

Do Son December 19, 2025 0
Read More Read more about Fusion of Power: Trump Media Inks $6 Billion Merger to Build World’s First Fusion Power Plant
FIFA’s Post-EA Comeback: Netflix to Launch a Reimagined Football Game for the 2026 World Cup FIFA Netflix game FIFA post-EA era
  • Technology

FIFA’s Post-EA Comeback: Netflix to Launch a Reimagined Football Game for the 2026 World Cup

Do Son December 19, 2025 0
Read More Read more about FIFA’s Post-EA Comeback: Netflix to Launch a Reimagined Football Game for the 2026 World Cup
The Grand Divorce: TikTok Signs Landmark Deal to Hand U.S. Control to Oracle-Led Group TikTok USDS Joint Venture LLC, TikTok U.S. divestment 2026 TikTok Deal, ByteDance Divestment U.S. ban TikTok TikTok Sale, Trump Announcement TikTok lawsuit Trump Amazon Acquisition
  • Technology

The Grand Divorce: TikTok Signs Landmark Deal to Hand U.S. Control to Oracle-Led Group

Do Son December 19, 2025 0
Read More Read more about The Grand Divorce: TikTok Signs Landmark Deal to Hand U.S. Control to Oracle-Led Group
Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel Linux Kernel 7.1 release Linux Kernel update, AMD ZEN 6 support, Linux driver fixes Linux Kernel 7.1 i486 support Linux 7.0 HIPPI support removal, legacy networking protocol retirement Linus Torvalds AI slop Linux kernel, Lorenzo Stoakes AI tool debate Linux Kernel Rust CVE-2025-68260, Android Binder Rust Race Condition TSEM Security Module Controversy, Linus Torvalds LSM Dispute Kernel Panic, PoC released Linux Kernel 6.16, File System Fixes CVE-2023-42753 - Linux Kernel Developers
  • Linux
  • Vulnerability Report

Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel

Do Son December 19, 2025 0
Read More Read more about Rust’s First Breach: CVE-2025-68260 Marks the First Rust Vulnerability in the Linux Kernel
Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts Kibana Vega XSS, Elastic Stack Security CVE-2024-37287 - Kibana security update
  • Vulnerability Report

Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts

Do Son December 19, 2025 0
Read More Read more about Visualizations Weaponized: New Kibana Flaw Allows XSS Attacks via Vega Charts
Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption CVE-2022-23307 Log4j TLS Bypass, Socket Appender Vulnerability
  • Vulnerability Report

Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption

Do Son December 19, 2025 0
Read More Read more about Log4j’s Security Blind Spot: New TLS Flaw Lets Attackers Intercept Sensitive Logs Despite Encryption
WatchGuard Under Siege: Critical CVSS 9.3 Zero-Day Exploited in the Wild to Hijack Corporate Firewalls Cisco SD-WAN Vulnerability CVE-2026-20133 FortiGate Compromise Ivanti EPMM Zero-Day CVE-2026-1281 SmarterMail Vulnerability Storm-2603 WatchGuard Zero-Day, IKEv2 Out-of-Bounds Write Cisco Zero-Day, UAT-9686 Chinese APT FortiWeb RCE Exploitation CVE-2025-58034 VMware Zero-Day, Privilege Escalation Sitecore, remote code execution CVE-2025-53690 Windows CLFS, Privilege Escalation CVE-2024-47575 & CVE-2024-11120 CVE-2025-24983 vulnerability
  • Vulnerability Report

WatchGuard Under Siege: Critical CVSS 9.3 Zero-Day Exploited in the Wild to Hijack Corporate Firewalls

Do Son December 19, 2025 0
Read More Read more about WatchGuard Under Siege: Critical CVSS 9.3 Zero-Day Exploited in the Wild to Hijack Corporate Firewalls
Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters Headlamp Kubernetes, Helm Credential Hijack
  • Vulnerability Report

Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters

Do Son December 19, 2025 0
Read More Read more about Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters
FreeBSD Network Alert: Malicious IPv6 Packets Can Trigger Remote Code Execution via resolvconf (CVE-2025-14558) CVE-2024-41721 - FreeBSD FreeBSD RCE, IPv6 Router Advertisement
  • Linux
  • Vulnerability Report

FreeBSD Network Alert: Malicious IPv6 Packets Can Trigger Remote Code Execution via resolvconf (CVE-2025-14558)

Do Son December 19, 2025 0
Read More Read more about FreeBSD Network Alert: Malicious IPv6 Packets Can Trigger Remote Code Execution via resolvconf (CVE-2025-14558)
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-58138CVSS 9.8
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute...
    Admin intel📅 Updated: Sep 20, 2026
  • CVE-2026-86124CVSS 9.8
    AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and...
    Admin intel📅 Updated: Sep 19, 2026
  • CVE-2025-39682CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2025-39964CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2026-53266CVSS 8.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2026-76460CVSS 10.0
    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-69586CVSS 9.8
    Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 21, 2026
  • CVE-2026-69590CVSS 9.8
    Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access...
    📅 Updated: Sep 21, 2026
  • CVE-2026-69595CVSS 9.8
    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code...
    📅 Updated: Sep 21, 2026
  • CVE-2026-58491CVSS 9.3
    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start...
    📅 Updated: Sep 21, 2026
  • CVE-2026-93765CVSS 9.1
    Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose...
    📅 Updated: Sep 21, 2026
  • CVE-2026-85497CVSS 9.8
    CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient...
    📅 Updated: Sep 21, 2026
  • CVE-2026-93742CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of...
    📅 Updated: Sep 21, 2026
  • CVE-2024-58385CVSS 9.8
    Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter...
    📅 Updated: Sep 21, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.