Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
HijackLoader: The Stealthy Malware Loader Powering Modern Cyberattacks Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Malware

HijackLoader: The Stealthy Malware Loader Powering Modern Cyberattacks

Do Son September 16, 2025 0
Read More Read more about HijackLoader: The Stealthy Malware Loader Powering Modern Cyberattacks
Maranhão Stealer: A New Malware Hijacks Gamers’ PCs Through Pirated Games Cobalt Strike Evade Detection
  • Malware

Maranhão Stealer: A New Malware Hijacks Gamers’ PCs Through Pirated Games

Do Son September 16, 2025 0
Read More Read more about Maranhão Stealer: A New Malware Hijacks Gamers’ PCs Through Pirated Games
Spring Framework and Spring Security Vulnerabilities Expose Authorization Bypass Risks (CVE-2025-41248 & CVE-2025-41249) Spring Data vulnerabilities Spring Cloud Config CVE-2026-22739 Spring Gateway SpEL, STOMP WebSocket CSRF Spring Security, vulnerability CVE-2024-38819 CVE-2025-41243 Spring Cloud Gateway, vulnerability
  • Vulnerability Report

Spring Framework and Spring Security Vulnerabilities Expose Authorization Bypass Risks (CVE-2025-41248 & CVE-2025-41249)

Do Son September 16, 2025 0
Read More Read more about Spring Framework and Spring Security Vulnerabilities Expose Authorization Bypass Risks (CVE-2025-41248 & CVE-2025-41249)
PoC Published: Linux Kernel 0-Click RCE Vulnerability Found in ksmbd Linux kernel, SMB vulnerability
  • Vulnerability Report

PoC Published: Linux Kernel 0-Click RCE Vulnerability Found in ksmbd

Do Son September 16, 2025 0
Read More Read more about PoC Published: Linux Kernel 0-Click RCE Vulnerability Found in ksmbd
Kimsuky Group Weaponizes AI Deepfakes in New Spear-Phishing Campaign North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security

Kimsuky Group Weaponizes AI Deepfakes in New Spear-Phishing Campaign

Do Son September 16, 2025 0
Read More Read more about Kimsuky Group Weaponizes AI Deepfakes in New Spear-Phishing Campaign
Yurei: The New Ransomware Group Using Open-Source Code to Target Businesses Yurei ransomware, open-source malware
  • Malware

Yurei: The New Ransomware Group Using Open-Source Code to Target Businesses

Do Son September 16, 2025 0
Read More Read more about Yurei: The New Ransomware Group Using Open-Source Code to Target Businesses
A Digital Trojan Horse: A New Campaign Is Using SEO to Deliver Malware SEO poisoning, Hiddengh0st
  • Cybercriminals

A Digital Trojan Horse: A New Campaign Is Using SEO to Deliver Malware

Do Son September 16, 2025 0
Read More Read more about A Digital Trojan Horse: A New Campaign Is Using SEO to Deliver Malware
Another Reprieve for TikTok: A Fourth Deadline Extension Is Expected TikTok USDS Joint Venture LLC, TikTok U.S. divestment 2026 TikTok Deal, ByteDance Divestment U.S. ban TikTok TikTok Sale, Trump Announcement TikTok lawsuit Trump Amazon Acquisition
  • Technology

Another Reprieve for TikTok: A Fourth Deadline Extension Is Expected

Do Son September 15, 2025 0
Read More Read more about Another Reprieve for TikTok: A Fourth Deadline Extension Is Expected
OpenAI’s New Grove Incubator Is Building the Next Generation of AI Startups OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

OpenAI’s New Grove Incubator Is Building the Next Generation of AI Startups

Do Son September 15, 2025 0
Read More Read more about OpenAI’s New Grove Incubator Is Building the Next Generation of AI Startups
Qualcomm Unveils the Snapdragon 8 Elite Gen 5, Launching First with Xiaomi Snapdragon 8 Elite Gen 5, Xiaomi
  • Technology

Qualcomm Unveils the Snapdragon 8 Elite Gen 5, Launching First with Xiaomi

Do Son September 15, 2025 0
Read More Read more about Qualcomm Unveils the Snapdragon 8 Elite Gen 5, Launching First with Xiaomi
A New Era for AI: Microsoft Unveils an Optical Computer That’s 100x More Efficient Optical computing, AI hardware
  • Technology

A New Era for AI: Microsoft Unveils an Optical Computer That’s 100x More Efficient

Do Son September 15, 2025 0
Read More Read more about A New Era for AI: Microsoft Unveils an Optical Computer That’s 100x More Efficient
Stack-Based Buffer Overflow in Squid Could Let Hackers Execute Arbitrary Code CVE-2024-25617 CVE-2025-59362 Squid Proxy ICP Vulnerability
  • Vulnerability

Stack-Based Buffer Overflow in Squid Could Let Hackers Execute Arbitrary Code

Do Son September 15, 2025 0
Read More Read more about Stack-Based Buffer Overflow in Squid Could Let Hackers Execute Arbitrary Code
Samsung Zero-Day Exploit CVE-2025-21043 Patched After Active Attacks on Android Devices Samsung zero-day Samsung Galaxy S25 Edge, Sales Performance Samsung Account, Inactive Accounts One UI 7 Samsung Update
  • Vulnerability Report

Samsung Zero-Day Exploit CVE-2025-21043 Patched After Active Attacks on Android Devices

Do Son September 15, 2025 0
Read More Read more about Samsung Zero-Day Exploit CVE-2025-21043 Patched After Active Attacks on Android Devices
Windows 11’s New “Speed Test” Feature: A Gimmick or a Genuine Upgrade? test
  • Windows

Windows 11’s New “Speed Test” Feature: A Gimmick or a Genuine Upgrade?

Do Son September 15, 2025 0
Read More Read more about Windows 11’s New “Speed Test” Feature: A Gimmick or a Genuine Upgrade?
PoC Available: FlowiseAI Flaw (CVE-2025-58434) Allows Full Account Takeover (CVSS 9.8) Flowise Sandbox Escape CVE-2026-46442 Flowise RCE Flowise Auth Bypass, Unauthenticated Registration Flowise RCE, WriteFileTool FlowiseAI, account takeover CVE-2025-58434
  • Vulnerability Report

PoC Available: FlowiseAI Flaw (CVE-2025-58434) Allows Full Account Takeover (CVSS 9.8)

Do Son September 15, 2025 0
Read More Read more about PoC Available: FlowiseAI Flaw (CVE-2025-58434) Allows Full Account Takeover (CVSS 9.8)
FBI Alert: Two Cybercriminal Groups Are Actively Compromising Salesforce TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Cyber Security

FBI Alert: Two Cybercriminal Groups Are Actively Compromising Salesforce

Do Son September 15, 2025 0
Read More Read more about FBI Alert: Two Cybercriminal Groups Are Actively Compromising Salesforce
AI Content War: Penske Media Sues Google Over AI Overviews AI Overviews opt out Google Gemini Pentagon contract Penske Media, AI Overviews
  • Technology

AI Content War: Penske Media Sues Google Over AI Overviews

Do Son September 15, 2025 0
Read More Read more about AI Content War: Penske Media Sues Google Over AI Overviews
VaultGemma: Google’s New AI Model Is the First with Differential Privacy VaultGemma, differential privacy
  • Technology

VaultGemma: Google’s New AI Model Is the First with Differential Privacy

Do Son September 15, 2025 0
Read More Read more about VaultGemma: Google’s New AI Model Is the First with Differential Privacy
Digiever NVR Flaws (CVE-2025-10264, CVE-2025-10265) Let Hackers Steal Credentials & Take Control Digiever NVR, critical vulnerabilities
  • Vulnerability Report

Digiever NVR Flaws (CVE-2025-10264, CVE-2025-10265) Let Hackers Steal Credentials & Take Control

Do Son September 15, 2025 0
Read More Read more about Digiever NVR Flaws (CVE-2025-10264, CVE-2025-10265) Let Hackers Steal Credentials & Take Control
Unveiling BaoLoader: How One Malware Family Abuses Trust for 7 Years BaoLoader, code-signing abuse
  • Cybercriminals

Unveiling BaoLoader: How One Malware Family Abuses Trust for 7 Years

Do Son September 15, 2025 0
Read More Read more about Unveiling BaoLoader: How One Malware Family Abuses Trust for 7 Years
CVE-2025-9556 (CVSS 9.8):Critical Vulnerability in LangChainGo Puts LLM Apps at Risk Everon OCPP Vulnerability CVE-2026-26288 ASUSTOR ADM Vulnerability CVE-2026-24936 PrismX MX100 Vulnerability Hard-Coded Credentials Advantech Vulnerability CVE-2025-52694 Eaton UPS Companion, CVE-2025-59887 ASUS Router, Authentication Bypass ASUSTOR DLL Hijacking, Privilege Escalation OpenShift AI, Privilege Escalation GoAnywhere vulnerability CVE-2025-10035 LangChainGo, template injection DeepDiff, class pollution ToolShell Sunshine, CSRF Vulnerability KACE SMA, Critical Vulnerabilities Oracle Zero-Days - PDQ Deploy vulnerability
  • Vulnerability Report

CVE-2025-9556 (CVSS 9.8):Critical Vulnerability in LangChainGo Puts LLM Apps at Risk

Do Son September 15, 2025 0
Read More Read more about CVE-2025-9556 (CVSS 9.8):Critical Vulnerability in LangChainGo Puts LLM Apps at Risk
Phishing Wave Hits U.S. Energy Giants: Chevron, ConocoPhillips Targeted Layoff Phishing Scam Remcos RAT Malware Aruba Phishing, Phishing-as-a-Service PyPI, phishing CVE-2024-25608 PyPI Phishing, Credential Theft
  • Cybercriminals

Phishing Wave Hits U.S. Energy Giants: Chevron, ConocoPhillips Targeted

Do Son September 15, 2025 0
Read More Read more about Phishing Wave Hits U.S. Energy Giants: Chevron, ConocoPhillips Targeted
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-19072CVSS 9.9
    Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for...
    📅 Updated: Sep 24, 2026
  • CVE-2026-94097CVSS 10.0
    A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of...
    📅 Updated: Sep 24, 2026
  • CVE-2026-94003CVSS 10.0
    A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12227CVSS 9.8
    The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up...
    📅 Updated: Sep 24, 2026
  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.