Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling Squid proxy vulnerabilities, buffer overflow attack Squid Credentials Leak, HTTP Authentication Redaction CVE-2024-25111
  • Vulnerability Report

Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling

Do Son October 20, 2025 0
Read More Read more about Critical Squid Proxy Flaw (CVE-2025-62168, CVSS 10.0) Leaks HTTP Credentials and Security Tokens via Error Handling
GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2 shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2

Do Son October 20, 2025 0
Read More Read more about GlassWorm Supply Chain Worm Uses Invisible Unicode and Solana Blockchain for Stealth C2
SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors CAPI Banking Trojan, LNK Persistence
  • Malware

SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors

Do Son October 20, 2025 0
Read More Read more about SEQRITE Labs Uncovers “CAPI Backdoor” Campaign Targeting Russia’s Automobile and E-Commerce Sectors
UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts UNC5142 EtherHiding, Resilient C2
  • Cybercriminals
  • Malware

UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts

Do Son October 20, 2025 0
Read More Read more about UNC5142 Uses EtherHiding to Deploy Malware via BNB Smart Chain Smart Contracts
131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme WhatsApp Spamware, Chrome Web Store Abuse
  • Cybercriminals

131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme

Do Son October 20, 2025 0
Read More Read more about 131 Chrome Extensions Found Abusing WhatsApp Web for Spam Automation in Massive Reseller Scheme
FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection HoldingHands Rootkit, Cross-Regional APT
  • Malware

FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection

Do Son October 20, 2025 0
Read More Read more about FortiGuard Tracks HoldingHands Malware Shift: Cross-Regional APT Uses Task Scheduler Hijack to Evade Detection
North Korea’s WaterPlum APT Deploys Node.js OtterCandy RAT for Crypto Theft with Anti-Forensic Module North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security
  • Malware

North Korea’s WaterPlum APT Deploys Node.js OtterCandy RAT for Crypto Theft with Anti-Forensic Module

Do Son October 20, 2025 0
Read More Read more about North Korea’s WaterPlum APT Deploys Node.js OtterCandy RAT for Crypto Theft with Anti-Forensic Module
Critical Moxa Flaw (CVE-2025-6950, CVSS 9.9) Allows Unauthenticated Admin Takeover via Hard-Coded JWT Secret Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability Report

Critical Moxa Flaw (CVE-2025-6950, CVSS 9.9) Allows Unauthenticated Admin Takeover via Hard-Coded JWT Secret

Do Son October 20, 2025 0
Read More Read more about Critical Moxa Flaw (CVE-2025-6950, CVSS 9.9) Allows Unauthenticated Admin Takeover via Hard-Coded JWT Secret
Researcher Details Zero-Click RCE in Dolby Audio Decoder Affecting Android, iOS, and macOS Dolby Zero-Click RCE, Audio Decoder Overflow
  • Vulnerability

Researcher Details Zero-Click RCE in Dolby Audio Decoder Affecting Android, iOS, and macOS

Do Son October 20, 2025 0
Read More Read more about Researcher Details Zero-Click RCE in Dolby Audio Decoder Affecting Android, iOS, and macOS
North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2 North Korea EtherHiding, Blockchain C2
  • Cyber Security
  • Malware

North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2

Do Son October 20, 2025 0
Read More Read more about North Korea’s UNC5342 APT Uses EtherHiding to Store Malware in Blockchain Smart Contracts for Stealthy C2
Google Abandons Privacy Sandbox Initiative After 6 Years, Citing Low Adoption of New Ad Tech Low carbon cloud computing Smartphone clusters, Green technology, Data centers, Google research Google Agentic AI search G Suite legacy free commercial reclassification 2026 Agent Payments Protocol AP2 Back-Button Hijacking Google Search AI headlines Google Play Store fee reduction Google Antigravity account recovery Google Advanced Air-Cooling Alphabet $185 billion CapEx 2026 Google Aluminum OS 2026 ai-disclosure HTML attribute, Chrome AI content transparency 2026 Google monopoly appeal 2026, Search data sharing stay Change @gmail.com address, Gmail email alias feature 2025 Google Play Store external download fees, Epic vs Google 2026 billing Google Dark Web Report Retirement, Data Breach Monitoring Google Antitrust One-Year Limit Default Search Contract Term Google AI Headlines Discover Headline Distortion Aluminium OS Android ChromeOS Merge Google Accelerator Impact $31.2 Billion Funding Google Texas Investment AI Data Center Expansion Google Play payments, external billing Gmail HIBP leak Privacy Sandbox Termination, Third-Party Cookies Google Strategic Market Status, CMA Antitrust ICEBlock Removal, DOJ Pressure Google Logo, AI Branding
  • Technology

Google Abandons Privacy Sandbox Initiative After 6 Years, Citing Low Adoption of New Ad Tech

Do Son October 20, 2025 0
Read More Read more about Google Abandons Privacy Sandbox Initiative After 6 Years, Citing Low Adoption of New Ad Tech
NVIDIA Unveils First Blackwell Wafer Made in US at TSMC Arizona Fab, Marking Production Milestone Apple NVIDIA TSMC Semiconductor Supply War NVIDIA Blackwell Wafer, TSMC Arizona Fab
  • Technology

NVIDIA Unveils First Blackwell Wafer Made in US at TSMC Arizona Fab, Marking Production Milestone

Do Son October 20, 2025 0
Read More Read more about NVIDIA Unveils First Blackwell Wafer Made in US at TSMC Arizona Fab, Marking Production Milestone
Apple Secures Exclusive F1 Broadcasting Rights in the US Starting 2026; F1 TV Pro Included with Apple TV Apple TV F1 Exclusive, F1 TV Pro Included
  • Technology

Apple Secures Exclusive F1 Broadcasting Rights in the US Starting 2026; F1 TV Pro Included with Apple TV

Do Son October 20, 2025 0
Read More Read more about Apple Secures Exclusive F1 Broadcasting Rights in the US Starting 2026; F1 TV Pro Included with Apple TV
Critical Keras 3 RCE Flaw (CVE-2025-49655, CVSS 9.8) Allows Code Execution on Model Load Keras RCE, Insecure Deserialization
  • Vulnerability Report

Critical Keras 3 RCE Flaw (CVE-2025-49655, CVSS 9.8) Allows Code Execution on Model Load

Do Son October 20, 2025 0
Read More Read more about Critical Keras 3 RCE Flaw (CVE-2025-49655, CVSS 9.8) Allows Code Execution on Model Load
Wikipedia Warns of Existential AI Threat as Page Views Fall 8% Due to Chatbot Summaries Yoshua Bengio AI sycophancy, reverse deception AI feedback AI chatbots, FTC investigation AI-generated content Trump AI Policy, AI Deregulation Military AI, DoD Funding Stargate Project AI Art Restoration
  • Technology

Wikipedia Warns of Existential AI Threat as Page Views Fall 8% Due to Chatbot Summaries

Do Son October 20, 2025 0
Read More Read more about Wikipedia Warns of Existential AI Threat as Page Views Fall 8% Due to Chatbot Summaries
Privilege Escalation Flaw Discovered in MinIO Service Accounts — CVE-2025-62506 MinIO Signature Bypass Unauthenticated Object Write MinIO Privilege Escalation, Policy Bypass CVE-2024-55949
  • Vulnerability Report

Privilege Escalation Flaw Discovered in MinIO Service Accounts — CVE-2025-62506

Do Son October 18, 2025 0
Read More Read more about Privilege Escalation Flaw Discovered in MinIO Service Accounts — CVE-2025-62506
CAD Assistant for PC: Professional 3D CAD Visualization on Desktop tech-computer
  • Technique

CAD Assistant for PC: Professional 3D CAD Visualization on Desktop

Do Son October 17, 2025 0
Read More Read more about CAD Assistant for PC: Professional 3D CAD Visualization on Desktop
Google DeepMind Partners with CFS to Use AI for Optimizing SPARC Fusion Reactor Efficiency DeepMind Fusion AI, SPARC Optimization
  • Technology

Google DeepMind Partners with CFS to Use AI for Optimizing SPARC Fusion Reactor Efficiency

Do Son October 17, 2025 0
Read More Read more about Google DeepMind Partners with CFS to Use AI for Optimizing SPARC Fusion Reactor Efficiency
Zimbra Issues Emergency Patch for Critical SSRF Vulnerability in Chat Proxy Configuration Zimbra SSRF, Chat Proxy Flaw
  • Vulnerability Report

Zimbra Issues Emergency Patch for Critical SSRF Vulnerability in Chat Proxy Configuration

Do Son October 17, 2025 0
Read More Read more about Zimbra Issues Emergency Patch for Critical SSRF Vulnerability in Chat Proxy Configuration
Record $40 Billion Deal: NVIDIA, Microsoft, BlackRock Consortium Acquires Aligned Data Centers AI Infrastructure Deal, Aligned Data Centers Abilene data center
  • Technology

Record $40 Billion Deal: NVIDIA, Microsoft, BlackRock Consortium Acquires Aligned Data Centers

Do Son October 17, 2025 0
Read More Read more about Record $40 Billion Deal: NVIDIA, Microsoft, BlackRock Consortium Acquires Aligned Data Centers
Apple Planning Touchscreen OLED MacBook Pro with M6 Chip for Late 2026 Debut MacBook Pro OLED touch screen MacBook Pro Touchscreen, M6 Chip OLED M5 MacBook Pro, 24-Hour Battery
  • Technology

Apple Planning Touchscreen OLED MacBook Pro with M6 Chip for Late 2026 Debut

Do Son October 17, 2025 0
Read More Read more about Apple Planning Touchscreen OLED MacBook Pro with M6 Chip for Late 2026 Debut
Meta Retiring Messenger Desktop App on Dec 15, Redirecting Users to Web Version Messenger Desktop EOL, Web Redirect Meta Political Ads, EU Regulation Meta EU Fine, DMA Compliance Meta AI, PlayAI Acquisition bypass AI security Meta AI EU Data Privacy
  • Technology

Meta Retiring Messenger Desktop App on Dec 15, Redirecting Users to Web Version

Do Son October 17, 2025 0
Read More Read more about Meta Retiring Messenger Desktop App on Dec 15, Redirecting Users to Web Version
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90608CVSS 9.9
    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element...
  • CVE-2026-90607CVSS 9.9
    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function...
  • CVE-2026-90606CVSS 9.9
    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue...
  • CVE-2026-90605CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects...
  • CVE-2026-81648CVSS 10.0
    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply...
  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
  • CVE-2026-84171CVSS 9.8
    The WP images upload on piclect WordPress plugin through 1.0 does not...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.