Skip to content
September 13, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Full Studio AI: Adobe Firefly Expands to Video Editor, Soundtracks, and Voice Adobe Creative Cloud hosts file Adobe Firefly, AI video
  • Technology

Full Studio AI: Adobe Firefly Expands to Video Editor, Soundtracks, and Voice

Do Son October 29, 2025 0
Read More Read more about Full Studio AI: Adobe Firefly Expands to Video Editor, Soundtracks, and Voice
AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption Gunra Linux Weak Key, ChaCha20 rand()
  • Malware

AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption

Do Son October 29, 2025 0
Read More Read more about AhnLab Uncovers Gunra Ransomware: Dual-Platform Threat with Weak Linux Encryption
Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems Herodotus Human Typing, Behavioral Biometrics Bypass
  • Malware

Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems

Do Son October 29, 2025 0
Read More Read more about Next-Gen Android Trojan Herodotus Mimics Human Typing to Bypass Behavioral Biometrics Anti-Fraud Systems
Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts CVE-2024-41110 Docker Compose Path Traversal, OCI Artifacts
  • Vulnerability Report

Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts

Do Son October 29, 2025 0
Read More Read more about Docker Compose Path Traversal (CVE-2025-62725) Allows Arbitrary File Overwrite via OCI Artifacts
BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cyber Security
  • Malware

BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings

Do Son October 29, 2025 0
Read More Read more about BlueNoroff APT Launches AI-Enhanced Espionage on macOS, Using GPT-4o Images in Fake GhostCall Meetings
Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available Wear OS Messages Intent, Confused Deputy SMS
  • Vulnerability Report

Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available

Do Son October 29, 2025 0
Read More Read more about Wear OS Messages Flaw (CVE-2025-12080) Allows Unprivileged Apps to Send SMS/RCS Without Permission, PoC Available
Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE Magento SessionReaper, RCE Exploitation
  • Vulnerability Report

Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE

Do Son October 29, 2025 0
Read More Read more about Critical Magento Flaw (CVE-2025-54236) Actively Exploited for Session Hijacking and Unauthenticated RCE
Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion Beast RaaS, ChaCha20 Stealth
  • Cybercriminals

Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion

Do Son October 29, 2025 0
Read More Read more about Beast Ransomware Emerges as New RaaS Threat, Using ChaCha20 and Stealthy VSS Deletion
Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig MikroTik HTTP Credential Leak, WebFig MitM CVE-2025-61481
  • Vulnerability Report

Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig

Do Son October 29, 2025 0
Read More Read more about Critical MikroTik Flaw (CVE-2025-61481, CVSS 10.0) Exposes Router Admin Credentials Over Unencrypted HTTP WebFig
Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking WhatsApp antitrust API probe India SIM-Binding Mandate Messaging App KYC WhatsApp DMA Interoperability BirdyChat Haiket Denmark Social Media Ban CVE-2025-55177 WhatsApp vulnerability, zero-click flaw npm Malware, System Wipe WhatsApp Windows App, WebView2 Downgrade WhatsApp Ban, US House NSO WhatsApp, Pegasus Spyware WhatsApp iPad iPadOS app
  • Malware

Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking

Do Son October 29, 2025 0
Read More Read more about Water Saci Evolves: Multi-Layered WhatsApp Worm Uses IMAP Email for Covert C2 and Session Hijacking
Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen Rhadamanthys Ren'Py, Fake Game Stealer
  • Malware

Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen

Do Son October 29, 2025 0
Read More Read more about Rhadamanthys Infostealer Hides in Ren’Py Visual Novel Games, Deploys Malware via Fake 1 Million Second Loading Screen
Critical .NET Flaw (CVE-2025-55315) in QNAP: NAS Backup Utility Vulnerable to Credential Theft QNAP Security Patches, NAS Vulnerabilities ASP.NET, QNAP CVE-2023-39296 PoC - CVE-2024-50394
  • Vulnerability Report

Critical .NET Flaw (CVE-2025-55315) in QNAP: NAS Backup Utility Vulnerable to Credential Theft

Do Son October 28, 2025 0
Read More Read more about Critical .NET Flaw (CVE-2025-55315) in QNAP: NAS Backup Utility Vulnerable to Credential Theft
Microsoft Teams Will Auto-Track Office Location via Wi-Fi Teams Workplace Check-in Microsoft 365 privacy, employee tracking tools, Teams location sharing Microsoft Teams EU antitrust, Teams Wi-Fi tracking, employee privacy
  • Technology

Microsoft Teams Will Auto-Track Office Location via Wi-Fi

Do Son October 28, 2025 0
Read More Read more about Microsoft Teams Will Auto-Track Office Location via Wi-Fi
Grokipedia Launches: Elon Musk’s xAI Debuts AI Encyclopedia to Rival Wikipedia Grokipedia, AI encyclopedia
  • Technology

Grokipedia Launches: Elon Musk’s xAI Debuts AI Encyclopedia to Rival Wikipedia

Do Son October 28, 2025 0
Read More Read more about Grokipedia Launches: Elon Musk’s xAI Debuts AI Encyclopedia to Rival Wikipedia
RIP Twitter.com: X Retires Old Domain, Forcing Passkey Reset by Nov 10 Twitter.com retirement, passkey reset Musk Twitter Severance, Lawsuit Settlement
  • Technology

RIP Twitter.com: X Retires Old Domain, Forcing Passkey Reset by Nov 10

Do Son October 28, 2025 0
Read More Read more about RIP Twitter.com: X Retires Old Domain, Forcing Passkey Reset by Nov 10
One in Nine: Amazon Prepares for Massive Layoff of 30,000 Corporate Staff Motorola Smart Feed redirect Anthropic Amazon 5GW partnership Amazon Perplexity lawsuit AWS-LC Vulnerabilities Cryptographic Bypass AWS Middle East drone strikes Amazon layoffs 2026, Amazon AI restructuring Amazon Kindle DRM Policy, Publisher Control EPUB AWS Nova Forge AI Model Customization AWS Trainium3 EC2 Trn3 UltraServer Route 53 Accelerated Recovery AWS DNS Resilience AI Browser War, Amazon Comet Amazon layoffs, cost reduction AWS outage, DynamoDB DNS AWS outage, cloud dependency AWS VPN Client, Root Privilege Escalation WSA shutdown, Amazon Appstore Amazon Wondery, Podcast Restructuring Amazon Q2 2025 Generative AI AWS Client VPN, Privilege Escalation Amazon AI, Wearable AI
  • Technology

One in Nine: Amazon Prepares for Massive Layoff of 30,000 Corporate Staff

Do Son October 28, 2025 0
Read More Read more about One in Nine: Amazon Prepares for Massive Layoff of 30,000 Corporate Staff
Privacy Win: Firefox Mandates Clear Data Collection Disclosure for All Extensions Firefox built-in VPN Firefox VPN data limit, Firefox VPN countries, Mozilla VPN subscription Sanitizer API Firefox 148 Security Firefox WebRTC Vulnerability CVE-2025-14321 PoC Firefox VPN Feature, Browser-Only VPN Firefox Add-ons Rollback Firefox Encryption Firefox MKV support Firefox ESR, Windows 7
  • Data Leak

Privacy Win: Firefox Mandates Clear Data Collection Disclosure for All Extensions

Do Son October 28, 2025 0
Read More Read more about Privacy Win: Firefox Mandates Clear Data Collection Disclosure for All Extensions
Values Over Cash: Python Foundation Rejects $1.5M US Grant Over Anti-DEI Clause Python Security Memory Safety PLY Vulnerability CVE-2025-56005 Python Software Foundation, NSF DEI CVE-2024-12254
  • Technology

Values Over Cash: Python Foundation Rejects $1.5M US Grant Over Anti-DEI Clause

Do Son October 28, 2025 0
Read More Read more about Values Over Cash: Python Foundation Rejects $1.5M US Grant Over Anti-DEI Clause
Google Debunks False Gmail Breach Rumors as Credentials Leak Again Low carbon cloud computing Smartphone clusters, Green technology, Data centers, Google research Google Agentic AI search G Suite legacy free commercial reclassification 2026 Agent Payments Protocol AP2 Back-Button Hijacking Google Search AI headlines Google Play Store fee reduction Google Antigravity account recovery Google Advanced Air-Cooling Alphabet $185 billion CapEx 2026 Google Aluminum OS 2026 ai-disclosure HTML attribute, Chrome AI content transparency 2026 Google monopoly appeal 2026, Search data sharing stay Change @gmail.com address, Gmail email alias feature 2025 Google Play Store external download fees, Epic vs Google 2026 billing Google Dark Web Report Retirement, Data Breach Monitoring Google Antitrust One-Year Limit Default Search Contract Term Google AI Headlines Discover Headline Distortion Aluminium OS Android ChromeOS Merge Google Accelerator Impact $31.2 Billion Funding Google Texas Investment AI Data Center Expansion Google Play payments, external billing Gmail HIBP leak Privacy Sandbox Termination, Third-Party Cookies Google Strategic Market Status, CMA Antitrust ICEBlock Removal, DOJ Pressure Google Logo, AI Branding
  • Data Leak

Google Debunks False Gmail Breach Rumors as Credentials Leak Again

Do Son October 28, 2025 0
Read More Read more about Google Debunks False Gmail Breach Rumors as Credentials Leak Again
Qilin RaaS Expands Global Impact: 40+ Victims/Month, Cyberduck Abuse, and WDigest Credential Theft Qilin RaaS, Cyberduck Credential Theft
  • Cybercriminals

Qilin RaaS Expands Global Impact: 40+ Victims/Month, Cyberduck Abuse, and WDigest Credential Theft

Do Son October 28, 2025 0
Read More Read more about Qilin RaaS Expands Global Impact: 40+ Victims/Month, Cyberduck Abuse, and WDigest Credential Theft
Kaspersky Exposes Chrome Zero-Day RCE (CVE-2025-2783) Delivering Memento Labs Spyware in ForumTroll Campaign spyware
  • Cyber Security
  • Vulnerability Report

Kaspersky Exposes Chrome Zero-Day RCE (CVE-2025-2783) Delivering Memento Labs Spyware in ForumTroll Campaign

Do Son October 28, 2025 0
Read More Read more about Kaspersky Exposes Chrome Zero-Day RCE (CVE-2025-2783) Delivering Memento Labs Spyware in ForumTroll Campaign
High-Severity OpenVPN Flaw (CVE-2025-10680) Allows Script Injection on Linux/macOS via Malicious DNS Server OpenVPN Script Injection CVE-2025-10680
  • Vulnerability Report

High-Severity OpenVPN Flaw (CVE-2025-10680) Allows Script Injection on Linux/macOS via Malicious DNS Server

Do Son October 28, 2025 0
Read More Read more about High-Severity OpenVPN Flaw (CVE-2025-10680) Allows Script Injection on Linux/macOS via Malicious DNS Server
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
  • CVE-2026-84171CVSS 9.8
    The WP images upload on piclect WordPress plugin through 1.0 does not...
  • CVE-2026-82845CVSS 9.9
    The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values...
  • CVE-2026-81402CVSS 9.8
    The DS Ad Rotator WordPress plugin through 0.8 does not perform any...
  • CVE-2026-77006CVSS 9.6
    The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied...
  • CVE-2026-77005CVSS 9.6
    The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a...
  • CVE-2026-75800CVSS 9.8
    The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.