Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Google Chrome Demands Massive Storage for On-Device AI Google Chrome browser settings interface showing the on-device AI toggle and disk space management
  • Technology

Google Chrome Demands Massive Storage for On-Device AI

Do Son August 7, 2026 0
Read More Read more about Google Chrome Demands Massive Storage for On-Device AI
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access SMOKE#SCREEN campaign infection chain abusing ScreenConnect RMM through fake Zoom update phishing lures
  • Cybercriminals

SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access

Do Son August 7, 2026 0
Read More Read more about SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
OpenAI Files Motion to Dismiss Apple Lawsuit OpenAI motion to dismiss Apple trade secret lawsuit overview
  • Technology

OpenAI Files Motion to Dismiss Apple Lawsuit

Do Son August 7, 2026 0
Read More Read more about OpenAI Files Motion to Dismiss Apple Lawsuit
Impending End of Support for Windows 10 LTSC 2021 Windows 10 LTSC ESU pricing and migration timeline
  • Windows

Impending End of Support for Windows 10 LTSC 2021

Do Son August 7, 2026 0
Read More Read more about Impending End of Support for Windows 10 LTSC 2021
QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users C2Looper Rust backdoor diagram showing GitHub command-and-control and ClickFix ransomware infection chain
  • Malware

QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users

Do Son August 7, 2026 0
Read More Read more about QuickFox Supply Chain Attack Delivers FDMTP Implant to Windows Users
Rogue AI Models Hack Systems to Cheat Evaluations Rogue AI models sandbox escape and external system breach
  • Technology

Rogue AI Models Hack Systems to Cheat Evaluations

Do Son August 7, 2026 0
Read More Read more about Rogue AI Models Hack Systems to Cheat Evaluations
Astaroth WhatsApp Spambot Turns Brazil Victims Into Unwitting Malware Distributors Astaroth WhatsApp spambot targeting Brazil via headless browser automation
  • Cybercriminals

Astaroth WhatsApp Spambot Turns Brazil Victims Into Unwitting Malware Distributors

Do Son August 7, 2026 0
Read More Read more about Astaroth WhatsApp Spambot Turns Brazil Victims Into Unwitting Malware Distributors
Kimi K3 Sandbox Escape: Open AI Model Breaks Out of Isolated Test Environment Kimi K3 open AI model sandbox escape exploiting misconfigured isolated test environment to access public internet during cybersecurity evaluation by Frontier Security
  • Technology

Kimi K3 Sandbox Escape: Open AI Model Breaks Out of Isolated Test Environment

Do Son August 7, 2026 0
Read More Read more about Kimi K3 Sandbox Escape: Open AI Model Breaks Out of Isolated Test Environment
CVE-2026-66747: Zbtlink Router Backdoor ENDLESSDOORS Enables Unauthenticated Remote Code Execution as Root Zbtlink router backdoor ENDLESSDOORS CVE-2026-66747 enabling unauthenticated remote code execution as root
  • Vulnerability Report

CVE-2026-66747: Zbtlink Router Backdoor ENDLESSDOORS Enables Unauthenticated Remote Code Execution as Root

Do Son August 7, 2026 0
Read More Read more about CVE-2026-66747: Zbtlink Router Backdoor ENDLESSDOORS Enables Unauthenticated Remote Code Execution as Root
CVE-2026-64561: Zapscape KVM Escape Runs Commands With Kernel Root Privilege, PoC Exploit Code Publicly Disclosed KVM escape vulnerability Zapscape CVE-2026-64561 running commands with kernel root privilege, with public PoC exploit code
  • Vulnerability Report

CVE-2026-64561: Zapscape KVM Escape Runs Commands With Kernel Root Privilege, PoC Exploit Code Publicly Disclosed

Do Son August 7, 2026 0
Read More Read more about CVE-2026-64561: Zapscape KVM Escape Runs Commands With Kernel Root Privilege, PoC Exploit Code Publicly Disclosed
CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution WordPress security update 7.0.3 fixing CVE-2026-64638 pre-auth XSS that can lead to remote code execution
  • Vulnerability Report

CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution

Do Son August 7, 2026 0
Read More Read more about CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution
Chrome Security Update Patches 41 Vulnerabilities, Including 6 Critical Flaws Chrome security update patching 41 vulnerabilities including critical CVE-2026-19137 and CVE-2026-19170
  • Vulnerability Report

Chrome Security Update Patches 41 Vulnerabilities, Including 6 Critical Flaws

Do Son August 7, 2026 0
Read More Read more about Chrome Security Update Patches 41 Vulnerabilities, Including 6 Critical Flaws
Cisco IMC Argument Injection Flaw CVE-2026-20200 Enables Root RCE, PoC Exploit Code Publicly Available Cisco IMC vulnerabilities CVE-2026-20200 and CVE-2026-20288 enabling remote code execution as root
  • Vulnerability Report

Cisco IMC Argument Injection Flaw CVE-2026-20200 Enables Root RCE, PoC Exploit Code Publicly Available

Do Son August 7, 2026 0
Read More Read more about Cisco IMC Argument Injection Flaw CVE-2026-20200 Enables Root RCE, PoC Exploit Code Publicly Available
Canadian Man Pleads Guilty to Cloud Hacking Extortion Scheme That Hit 165 Companies Cloud hacking extortion guilty plea over the Snowflake data breach affecting 165 companies
  • Cybercriminals

Canadian Man Pleads Guilty to Cloud Hacking Extortion Scheme That Hit 165 Companies

Do Son August 7, 2026 0
Read More Read more about Canadian Man Pleads Guilty to Cloud Hacking Extortion Scheme That Hit 165 Companies
How DDoS Testing Helps Businesses Prepare for Real Cyber Attacks Undertow Vulnerability CVE-2025-12543 CVE-2025-0107: PoC Exploit Code Undersea Cable Security, China Tech Ban
  • Technique

How DDoS Testing Helps Businesses Prepare for Real Cyber Attacks

Do Son August 7, 2026 0
Read More Read more about How DDoS Testing Helps Businesses Prepare for Real Cyber Attacks
Phoenix Contact CHARX Vulnerabilities Expose EV Charging Controllers Phoenix Contact CHARX vulnerabilities affecting EV charging controller firmware
  • Vulnerability Report

Phoenix Contact CHARX Vulnerabilities Expose EV Charging Controllers

Do Son August 6, 2026 0
Read More Read more about Phoenix Contact CHARX Vulnerabilities Expose EV Charging Controllers
DarkSword iOS Exploit Spreads Across 100+ Sites and Drops GHOSTBLADE DarkSword iOS exploit chain operator panel serving GHOSTBLADE implant and fake Apple ID login credential harvesting page
  • Cybercriminals

DarkSword iOS Exploit Spreads Across 100+ Sites and Drops GHOSTBLADE

Do Son August 6, 2026 0
Read More Read more about DarkSword iOS Exploit Spreads Across 100+ Sites and Drops GHOSTBLADE
CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw macOS kernel vulnerability CVE-2026-39868 in DTrace DOF parsing with public proof-of-concept exploit code
  • Vulnerability Report

CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw

Do Son August 6, 2026 0
Read More Read more about CVE-2026-39868: Public PoC Discloses a macOS and iOS Kernel Memory Corruption Flaw
Xeno Roblox Malware Spreads a Java Stealer Through Fake Cheats CVE-2024-3393 - Zservers sanctions
  • Malware

Xeno Roblox Malware Spreads a Java Stealer Through Fake Cheats

Do Son August 6, 2026 0
Read More Read more about Xeno Roblox Malware Spreads a Java Stealer Through Fake Cheats
XCSSET v40 Malware Targets macOS Developers Through Xcode XCSSET v40 malware infection chain showing Xcode project supply chain attack on macOS
  • Malware

XCSSET v40 Malware Targets macOS Developers Through Xcode

Do Son August 6, 2026 0
Read More Read more about XCSSET v40 Malware Targets macOS Developers Through Xcode
CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide CaptiveCrunch malware campaign diagram showing hotel Wi-Fi captive portal hijack by Storm-2945
  • Cybercriminals

CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide

Do Son August 6, 2026 0
Read More Read more about CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide
OpenAI AI Agents Collude to Breach Internal Systems OpenAI AI agents breach diagram showing autonomous agent communication
  • Data Leak

OpenAI AI Agents Collude to Breach Internal Systems

Do Son August 6, 2026 0
Read More Read more about OpenAI AI Agents Collude to Breach Internal Systems
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90608CVSS 9.9
    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element...
  • CVE-2026-90607CVSS 9.9
    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function...
  • CVE-2026-90606CVSS 9.9
    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue...
  • CVE-2026-90605CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects...
  • CVE-2026-81648CVSS 10.0
    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply...
  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
  • CVE-2026-84171CVSS 9.8
    The WP images upload on piclect WordPress plugin through 1.0 does not...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.