Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
EggStreme: New Fileless Malware from a Chinese APT Targets Philippine Military Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cyber Security
  • Malware

EggStreme: New Fileless Malware from a Chinese APT Targets Philippine Military

Do Son September 12, 2025 0
Read More Read more about EggStreme: New Fileless Malware from a Chinese APT Targets Philippine Military
BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads INC Ransom Pacific Cyber Threats OysterLoader Malware Rhysida Ransomware Black Basta Ransomware BYOVD Technique Velociraptor Abuse, Storm-2603 Ransomware Crypto24, Ransomware Ransomware Payments, UK Legislation ZACROS data breach
  • Malware

BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads

Do Son September 12, 2025 0
Read More Read more about BlackNevas Ransomware: A Persistent Global Threat With Impossible-to-Decrypt Payloads
ToneShell Backdoor Evolves With Anti-Analysis Tricks, Continues Targeting Myanmar ToneShell, Mustang Panda
  • Cyber Security
  • Malware

ToneShell Backdoor Evolves With Anti-Analysis Tricks, Continues Targeting Myanmar

Do Son September 12, 2025 0
Read More Read more about ToneShell Backdoor Evolves With Anti-Analysis Tricks, Continues Targeting Myanmar
kkRAT: A New Malware Blends Crypto Hijacking with Legitimate RMM Tools kkRAT
  • Malware

kkRAT: A New Malware Blends Crypto Hijacking with Legitimate RMM Tools

Do Son September 12, 2025 0
Read More Read more about kkRAT: A New Malware Blends Crypto Hijacking with Legitimate RMM Tools
Angular SSR Flaw (CVE-2025-59052) Exposes User Data: What Developers Need to Know Angular hostname hijacking vulnerability Angular SSRF Origin Hijacking Angular XSS Vulnerability CVE-2026-32635 Angular i18n XSS CVE-2026-27970 Angular SSR SSRF CVE-2026-27739 Angular Vulnerability CVE-2026-22610 CVE-2025-59052 Angular security Angular XSS Bypass, SVG Injection
  • Vulnerability Report

Angular SSR Flaw (CVE-2025-59052) Exposes User Data: What Developers Need to Know

Do Son September 11, 2025 0
Read More Read more about Angular SSR Flaw (CVE-2025-59052) Exposes User Data: What Developers Need to Know
Community Notes: Meta Invites All Users to Test New Fact-Checking System Meta Community Notes
  • Technology

Community Notes: Meta Invites All Users to Test New Fact-Checking System

Do Son September 11, 2025 0
Read More Read more about Community Notes: Meta Invites All Users to Test New Fact-Checking System
PlayStation Launches Family App for Mobile Parental Controls PlayStation Parental Controls
  • Technology

PlayStation Launches Family App for Mobile Parental Controls

Do Son September 11, 2025 0
Read More Read more about PlayStation Launches Family App for Mobile Parental Controls
1.5 billion packets per second DDoS attack detected with FastNetMon FastNetMon_detects_a_record-scale_DDoS_attack_15B__17574197861FjWINd5Zk
  • Press Release

1.5 billion packets per second DDoS attack detected with FastNetMon

cybernewswire September 11, 2025 0
Read More Read more about 1.5 billion packets per second DDoS attack detected with FastNetMon
A New Era for Developers: Microsoft Waives App Publishing Fees Microsoft Store, app publishing
  • Technology

A New Era for Developers: Microsoft Waives App Publishing Fees

Do Son September 11, 2025 0
Read More Read more about A New Era for Developers: Microsoft Waives App Publishing Fees
Microsoft Copilot to Be Powered by Two AIs: OpenAI and Now Anthropic Microsoft Copilot, Anthropic CVE-2024-38063 on-premises server products
  • Technology

Microsoft Copilot to Be Powered by Two AIs: OpenAI and Now Anthropic

Do Son September 11, 2025 0
Read More Read more about Microsoft Copilot to Be Powered by Two AIs: OpenAI and Now Anthropic
CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible The created ransom note
  • Malware

CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible

Do Son September 11, 2025 0
Read More Read more about CyberVolk Ransomware’s Decryption Flaw Makes Data Recovery Impossible
High-Severity Flaws in Sunshine for Windows Allow Privilege Escalation Sunshine for Windows, vulnerability
  • Vulnerability Report

High-Severity Flaws in Sunshine for Windows Allow Privilege Escalation

Do Son September 11, 2025 0
Read More Read more about High-Severity Flaws in Sunshine for Windows Allow Privilege Escalation
Beyond Cobalt Strike: A New Open-Source Hacking Tool Is on the Rise Winos 4.0 Malware Silver Fox APT RapperBot BVIEC cyberattack - CNC group DAMASCENED PEACOCK, malware analysis
  • Cybercriminals

Beyond Cobalt Strike: A New Open-Source Hacking Tool Is on the Rise

Do Son September 11, 2025 0
Read More Read more about Beyond Cobalt Strike: A New Open-Source Hacking Tool Is on the Rise
CVE-2025-8696: DoS Flaw in Stork UI Allows Unauthenticated Attackers to Crash Servers CVE-2025-8696 Stork UI
  • Vulnerability Report

CVE-2025-8696: DoS Flaw in Stork UI Allows Unauthenticated Attackers to Crash Servers

Do Son September 11, 2025 0
Read More Read more about CVE-2025-8696: DoS Flaw in Stork UI Allows Unauthenticated Attackers to Crash Servers
ChillyHell: A New macOS Backdoor Bypassed Apple Notarization for Years OSX/Amos Stealer Electron ASAR Trojan MioLab Malware macOS Security MacSync Stealer macOS Malware ambar-src npm Malware Supply Chain Typosquatting Matryoshka Mac Malware ClickFix Crypto Scam Infostealer Evolution macOS Malware Predator Spyware Intellexa Anti-Analysis XCSSET macOS Malware, Xcode Supply Chain
  • Malware

ChillyHell: A New macOS Backdoor Bypassed Apple Notarization for Years

Do Son September 11, 2025 0
Read More Read more about ChillyHell: A New macOS Backdoor Bypassed Apple Notarization for Years
ACSC Warns of Active Exploitation of SonicWall SSL VPN Vulnerability (CVE-2024-40766) Everon OCPP Vulnerability CVE-2026-26288 ASUSTOR ADM Vulnerability CVE-2026-24936 PrismX MX100 Vulnerability Hard-Coded Credentials Advantech Vulnerability CVE-2025-52694 Eaton UPS Companion, CVE-2025-59887 ASUS Router, Authentication Bypass ASUSTOR DLL Hijacking, Privilege Escalation OpenShift AI, Privilege Escalation GoAnywhere vulnerability CVE-2025-10035 LangChainGo, template injection DeepDiff, class pollution ToolShell Sunshine, CSRF Vulnerability KACE SMA, Critical Vulnerabilities Oracle Zero-Days - PDQ Deploy vulnerability
  • Vulnerability Report

ACSC Warns of Active Exploitation of SonicWall SSL VPN Vulnerability (CVE-2024-40766)

Do Son September 11, 2025 0
Read More Read more about ACSC Warns of Active Exploitation of SonicWall SSL VPN Vulnerability (CVE-2024-40766)
KillSec Ransomware Strikes Brazilian Healthcare Provider, Exposing Patient Data KillSec Ransomware
  • Cybercriminals
  • Data Leak

KillSec Ransomware Strikes Brazilian Healthcare Provider, Exposing Patient Data

Do Son September 11, 2025 0
Read More Read more about KillSec Ransomware Strikes Brazilian Healthcare Provider, Exposing Patient Data
Unsealed Indictment Exposes Mastermind Behind Notorious Ransomware Gangs WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Cybercriminals

Unsealed Indictment Exposes Mastermind Behind Notorious Ransomware Gangs

Do Son September 11, 2025 0
Read More Read more about Unsealed Indictment Exposes Mastermind Behind Notorious Ransomware Gangs
CVE-2025-58063: CoreDNS Vulnerability Could Disrupt DNS Updates CoreDNS Security Encrypted DNS Vulnerabilities CoreDNS vulnerability, DNS cache poisoning
  • Vulnerability Report

CVE-2025-58063: CoreDNS Vulnerability Could Disrupt DNS Updates

Do Son September 11, 2025 0
Read More Read more about CVE-2025-58063: CoreDNS Vulnerability Could Disrupt DNS Updates
NVIDIA Patches High-Severity Vulnerabilities in NVDebug Tool NVIDIA acquisition rumors NVIDIA AI Security AI Framework Vulnerabilities Nvidia 595.76 Hotfix NVIDIA Megatron Bridge vulnerability GPU vs ASIC AI battle NVIDIA Driver Vulnerability CVE-2025-33217 NVIDIA biggest TSMC customer 2026, NVIDIA vs Apple TSMC revenue share NVIDIA CUDA Toolkit CVE-2025-33228 Groq NVIDIA licensing deal, Jonathan Ross acquihire 2025 NeMo Code Injection, AI Framework RCE NVIDIA App Privilege Escalation, CVE-2025-23358 NVIDIA Security Update, DLS Vulnerability CVE-2025-23316 NVIDIA NVDebug, vulnerabilities NVIDIA Driver Vulnerabilities, vGPU Security Nvidia Jetson, UEFI Vulnerabilities CVE-2024-0130 - CVE-2024-0136 CVE-2024-0148 NVIDIA Driver Support, Windows 10 EOL
  • Vulnerability Report

NVIDIA Patches High-Severity Vulnerabilities in NVDebug Tool

Do Son September 11, 2025 0
Read More Read more about NVIDIA Patches High-Severity Vulnerabilities in NVDebug Tool
Fake AI Ad Tool “Madgicx Plus” Hijacks Meta Advertiser Accounts LokiBot Steganography, .NET Loader PlugX malware YiBackdoor, ransomware
  • Malware

Fake AI Ad Tool “Madgicx Plus” Hijacks Meta Advertiser Accounts

Do Son September 11, 2025 0
Read More Read more about Fake AI Ad Tool “Madgicx Plus” Hijacks Meta Advertiser Accounts
The Gentlemen: A New Ransomware Group Using Legitimate Tools to Bypass Security Chinese espionage groups APT35 Phishing, Stormshield CTI
  • Cybercriminals

The Gentlemen: A New Ransomware Group Using Legitimate Tools to Bypass Security

Do Son September 11, 2025 0
Read More Read more about The Gentlemen: A New Ransomware Group Using Legitimate Tools to Bypass Security
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 7 days →

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-76708CVSS 9.8
    A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use...
    📅 Updated: Sep 25, 2026
  • CVE-2026-97230CVSS 9.8
    IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93641CVSS 9.3
    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93642CVSS 9.3
    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93643CVSS 9.8
    When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document...
    📅 Updated: Sep 25, 2026
  • CVE-2026-39353CVSS 9.1
    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds...
    📅 Updated: Sep 25, 2026
  • CVE-2026-20147CVSS 9.9
    A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands...
    📅 Updated: Sep 25, 2026
  • CVE-2026-20181CVSS 9.1
    A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on...
    📅 Updated: Sep 25, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.