Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Deepfakes and Deception: A New AI Scam Network Is Targeting India AI investment scams, deepfakes
  • Cybercriminals

Deepfakes and Deception: A New AI Scam Network Is Targeting India

Do Son September 10, 2025 0
Read More Read more about Deepfakes and Deception: A New AI Scam Network Is Targeting India
Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE Hiawatha vulnerability
  • Vulnerability Report

Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE

Do Son September 10, 2025 0
Read More Read more about Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE
GONEPOSTAL: New Outlook Backdoor by Russia’s APT28 Uses Email for C2 APT28, GONEPOSTAL
  • Cybercriminals
  • Malware

GONEPOSTAL: New Outlook Backdoor by Russia’s APT28 Uses Email for C2

Do Son September 10, 2025 0
Read More Read more about GONEPOSTAL: New Outlook Backdoor by Russia’s APT28 Uses Email for C2
Lazarus Group Is Exploiting CVE-2025-48384 in New Phishing Campaign Lazarus Group, phishing campaign
  • Cyber Security

Lazarus Group Is Exploiting CVE-2025-48384 in New Phishing Campaign

Do Son September 10, 2025 0
Read More Read more about Lazarus Group Is Exploiting CVE-2025-48384 in New Phishing Campaign
Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs Docker malware, exposed APIs
  • Malware

Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs

Do Son September 10, 2025 0
Read More Read more about Beyond Cryptominers: A New Malware Strain Is Hijacking Exposed Docker APIs
APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Malware

APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer

Do Son September 10, 2025 0
Read More Read more about APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer
CVE-2025-40795 (CVSS 9.8): Critical Flaw in Siemens SIVaaS Exposes Network Share Without Authentication Siemens SIMATIC Vulnerability CVE-2025-40943 CVE-2024-47901 - Siemens InterMesh system CVE-2025-40804 Siemens SIVaaS
  • Vulnerability Report

CVE-2025-40795 (CVSS 9.8): Critical Flaw in Siemens SIVaaS Exposes Network Share Without Authentication

Do Son September 9, 2025 0
Read More Read more about CVE-2025-40795 (CVSS 9.8): Critical Flaw in Siemens SIVaaS Exposes Network Share Without Authentication
Ivanti Patches Two High-Severity RCE Flaws in Endpoint Manager Ivanti EPMM security updates Ivanti ITSM vulnerability authenticated privilege escalation Ivanti Xtraction vulnerability CVE-2026-8043 Ivanti EPM RCE, SQL Injection Ivanti EPM, remote code execution CVE-2024-50330 - CVE-2025-0282 and CVE-2025-0283
  • Vulnerability Report

Ivanti Patches Two High-Severity RCE Flaws in Endpoint Manager

Do Son September 9, 2025 0
Read More Read more about Ivanti Patches Two High-Severity RCE Flaws in Endpoint Manager
ClickFix Attacks Are Evolving: Here’s How to Detect Them in Your SOC ClickFix Attacks
  • Technique

ClickFix Attacks Are Evolving: Here’s How to Detect Them in Your SOC

Do Son September 9, 2025 0
Read More Read more about ClickFix Attacks Are Evolving: Here’s How to Detect Them in Your SOC
Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure Header_PM_ENG_175741226833AHmGMyap
  • Press Release

Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure

cybernewswire September 9, 2025 0
Read More Read more about Link11 Reports 225% more DDoS attacks in H1 2025 with new tactics against infrastructure
Signal Solves Its Biggest Flaw with a New Privacy-Focused Cloud Backup Signal cloud backup iOS Notification Database
  • Technology

Signal Solves Its Biggest Flaw with a New Privacy-Focused Cloud Backup

Do Son September 9, 2025 0
Read More Read more about Signal Solves Its Biggest Flaw with a New Privacy-Focused Cloud Backup
Now It Can Listen: Google Gemini Adds Support for Audio File Uploads Google Gemini, audio files Gemini AI, Google AI Google Gemini 2.0 Flash Thinking iOS
  • Technology

Now It Can Listen: Google Gemini Adds Support for Audio File Uploads

Do Son September 9, 2025 0
Read More Read more about Now It Can Listen: Google Gemini Adds Support for Audio File Uploads
RatOn: The New Android Trojan That Steals Crypto and Uses NFC Relay Attacks RatOn, Android trojan
  • Malware

RatOn: The New Android Trojan That Steals Crypto and Uses NFC Relay Attacks

Do Son September 9, 2025 0
Read More Read more about RatOn: The New Android Trojan That Steals Crypto and Uses NFC Relay Attacks
CVE-2025-7350: Critical RCE Flaw in Rockwell Stratix Switches Scores CVSS 9.6 CVE-2024-21915 Rockwell Stratix switch CVE-2025-7350
  • Vulnerability Report

CVE-2025-7350: Critical RCE Flaw in Rockwell Stratix Switches Scores CVSS 9.6

Do Son September 9, 2025 0
Read More Read more about CVE-2025-7350: Critical RCE Flaw in Rockwell Stratix Switches Scores CVSS 9.6
SAP Security Patch Day Fixes Four Critical Flaws, Including a CVSS 10.0 RCE (CVE-2025-42944) SAP security patch day critical security vulnerabilities SAP SQL Injection April 2026 Patch Day SAP Security, Critical Vulnerabilities Security Patch Day CVE-2025-42944
  • Vulnerability Report

SAP Security Patch Day Fixes Four Critical Flaws, Including a CVSS 10.0 RCE (CVE-2025-42944)

Do Son September 9, 2025 0
Read More Read more about SAP Security Patch Day Fixes Four Critical Flaws, Including a CVSS 10.0 RCE (CVE-2025-42944)
Salesforce Breach Through Salesloft Drift Hits Google, Cloudflare, and 750 Firms Knowledge Deliver RCE vulnerability FortiClient EMS Vulnerability CVE-2026-35616 Cisco SD-WAN Vulnerability CVE-2026-20122 PCPcat, Next.js RCE Salesloft breach, Salesforce CRM WIREFIRE web shell
  • Data Leak

Salesforce Breach Through Salesloft Drift Hits Google, Cloudflare, and 750 Firms

Do Son September 9, 2025 0
Read More Read more about Salesforce Breach Through Salesloft Drift Hits Google, Cloudflare, and 750 Firms
Intel’s 14A Process Will Be Its Most Expensive and Advanced Yet Intel graphics drivers Intel 14A, EUV lithography Intel CHIPS Act Intel Government Investment Intel Layoffs, Wafer Foundry CVE-2022-21198
  • Technology

Intel’s 14A Process Will Be Its Most Expensive and Advanced Yet

Do Son September 9, 2025 0
Read More Read more about Intel’s 14A Process Will Be Its Most Expensive and Advanced Yet
Google’s AI Search Goes Global: New AI Mode Supports Five Languages Google Gemini Ads AI Search Monetization Google AI Mode, multilingual search
  • Technology

Google’s AI Search Goes Global: New AI Mode Supports Five Languages

Do Son September 9, 2025 0
Read More Read more about Google’s AI Search Goes Global: New AI Mode Supports Five Languages
Plex Urges Password Reset After Data Breach Iranian Hacktivists Operation Epic Fury Cyber New Generation Warfare Russian Hybrid Escalation Plex data breach Water Systems Cybersecurity - Threat Actor Naming Standard
  • Data Leak

Plex Urges Password Reset After Data Breach

Do Son September 9, 2025 0
Read More Read more about Plex Urges Password Reset After Data Breach
Intel’s Major Leadership Reshuffle: What Does It Mean for the Future? Intel EU Antitrust Fine, Naked Restrictions Intel Layoff Data Theft Jinfeng Luo Intel leadership change Intel SoftBank Intel Foundry, Semiconductor Market Intel Arrow Lake Refresh, Copilot+ PC Intel GPU Performance, Security Mitigations Mitigation Downfall Vulnerability
  • Technology

Intel’s Major Leadership Reshuffle: What Does It Mean for the Future?

Do Son September 9, 2025 0
Read More Read more about Intel’s Major Leadership Reshuffle: What Does It Mean for the Future?
SanDisk Hikes Prices as Storage Costs Continue to Climb SanDisk, price increase SanDisk SSD, AI Storage
  • Technology

SanDisk Hikes Prices as Storage Costs Continue to Climb

Do Son September 9, 2025 0
Read More Read more about SanDisk Hikes Prices as Storage Costs Continue to Climb
Qualcomm and Google Partner to Bring AI to the Car Qualcomm Google Cloud
  • Technology

Qualcomm and Google Partner to Bring AI to the Car

Do Son September 9, 2025 0
Read More Read more about Qualcomm and Google Partner to Bring AI to the Car
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 7 days →

🚨 Active Exploits in the Wild

  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-76708CVSS 9.8
    A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use...
    📅 Updated: Sep 25, 2026
  • CVE-2026-97230CVSS 9.8
    IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93641CVSS 9.3
    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93642CVSS 9.3
    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient...
    📅 Updated: Sep 25, 2026
  • CVE-2026-93643CVSS 9.8
    When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document...
    📅 Updated: Sep 25, 2026
  • CVE-2026-39353CVSS 9.1
    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds...
    📅 Updated: Sep 25, 2026
  • CVE-2026-20147CVSS 9.9
    A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands...
    📅 Updated: Sep 25, 2026
  • CVE-2026-20181CVSS 9.1
    A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on...
    📅 Updated: Sep 25, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.