Skip to content
June 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
Popular Selenium Library WebDriverManager Hit by Critical XXE Bug (CVE-2025-4641, CVSS 9.3) WebDriverManager, CVE-2025-4641
  • Vulnerability

Popular Selenium Library WebDriverManager Hit by Critical XXE Bug (CVE-2025-4641, CVSS 9.3)

Do Son May 16, 2025 0
A critical XML External Entity (XXE) injection vulnerability has been identified in WebDriverManager, an essential Java library...
Read More Read more about Popular Selenium Library WebDriverManager Hit by Critical XXE Bug (CVE-2025-4641, CVSS 9.3)
TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision TransferLoader, IPFS
  • Malware

TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision

Do Son May 16, 2025 0
Zscaler ThreatLabz has uncovered a new and dangerous malware loader dubbed TransferLoader, actively used in the wild...
Read More Read more about TransferLoader Malware Unmasked: IPFS-Enabled Loader Deploys Ransomware and Backdoors with Obfuscation Precision
Pgpool-II Hit by Critical CVE-2025-46801: CVSS 9.8 Risk Lets Attackers Bypass Authentication Pgpool-II, authentication bypass
  • Vulnerability

Pgpool-II Hit by Critical CVE-2025-46801: CVSS 9.8 Risk Lets Attackers Bypass Authentication

Do Son May 16, 2025 0
The PgPool Global Development Group has issued a high-severity security advisory for Pgpool-II, a widely used middleware...
Read More Read more about Pgpool-II Hit by Critical CVE-2025-46801: CVSS 9.8 Risk Lets Attackers Bypass Authentication
Jenkins Plugin Flaws Expose Critical Risks: CVE-2025-47889 Hits 9.8 CVSS with Auth Bypass Jenkins Security Update CVE-2026-27099 Jenkins security - CVE-2023-35141 Jenkins plugins, CVE-2025-47884
  • Vulnerability

Jenkins Plugin Flaws Expose Critical Risks: CVE-2025-47889 Hits 9.8 CVSS with Auth Bypass

Do Son May 16, 2025 0
Jenkins, a popular open-source automation server, is a crucial tool for many development and operations teams. A...
Read More Read more about Jenkins Plugin Flaws Expose Critical Risks: CVE-2025-47889 Hits 9.8 CVSS with Auth Bypass
Inside North Korea’s Cyber Mafia: How Hidden IT Workers Fuel Global Espionage and Crypto Theft DPRK cybercrime, IT workers
  • Cyber Security

Inside North Korea’s Cyber Mafia: How Hidden IT Workers Fuel Global Espionage and Crypto Theft

Do Son May 16, 2025 0
A recent report by DTEX sheds light on the sophisticated and complex cyber operations of the Democratic...
Read More Read more about Inside North Korea’s Cyber Mafia: How Hidden IT Workers Fuel Global Espionage and Crypto Theft
Critical NAS Risk: I-O DATA Flaw with 9.8 CVSS Allows Remote Command Execution I-O DATA, NAS, command injection
  • Vulnerability

Critical NAS Risk: I-O DATA Flaw with 9.8 CVSS Allows Remote Command Execution

Do Son May 16, 2025 0
Network Attached Storage (NAS) devices have become essential components of both home and business networks, providing centralized...
Read More Read more about Critical NAS Risk: I-O DATA Flaw with 9.8 CVSS Allows Remote Command Execution
Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers Sednit Cyberespionage, APT28
  • Cyber Security
  • Vulnerability

Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers

Do Son May 16, 2025 0
ESET researchers have exposed a covert cyberespionage campaign, dubbed Operation RoundPress, believed to be orchestrated by the...
Read More Read more about Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers
Patch Now: SonicWall SMA1000 Flaw (CVE-2025-40595) Enables Stealth SSRF Attacks SSRF, SonicWall SMA1000
  • Vulnerability

Patch Now: SonicWall SMA1000 Flaw (CVE-2025-40595) Enables Stealth SSRF Attacks

Do Son May 16, 2025 0
A newly disclosed Server-Side Request Forgery (SSRF) vulnerability in SonicWall’s SMA1000 series appliances could allow remote attackers...
Read More Read more about Patch Now: SonicWall SMA1000 Flaw (CVE-2025-40595) Enables Stealth SSRF Attacks
Why IAM Lifecycle Governance Matters for Securing Your Digital Ecosystem in 2025 Img_2025_05_15_20_40_33
  • Technique

Why IAM Lifecycle Governance Matters for Securing Your Digital Ecosystem in 2025

Do Son May 15, 2025 0
The rapid expansion of cloud computing, remote work, and interconnected applications has made Identity and Access Management...
Read More Read more about Why IAM Lifecycle Governance Matters for Securing Your Digital Ecosystem in 2025
High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale a-blog cms, CVE-2025-36560
  • Vulnerability

High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale

Do Son May 15, 2025 0
JPCERT/CC has issued a vulnerability note disclosing multiple security flaws in a-blog cms, a popular content management...
Read More Read more about High-Risk Flaws in a-blog cms: CVE-2025-36560 Scores Critical 9.2 on CVSS Scale
URGENT Chrome Update: High-Risk CVE-2025-4664 Flaw Actively Exploited In The Wild – Patch Immediately! Screenshot_20250515-082049
  • Vulnerability

URGENT Chrome Update: High-Risk CVE-2025-4664 Flaw Actively Exploited In The Wild – Patch Immediately!

Do Son May 15, 2025 0
Google has released a critical Stable Channel Update for Chrome Desktop, bumping the version to 136.0.7103.113/.114 for...
Read More Read more about URGENT Chrome Update: High-Risk CVE-2025-4664 Flaw Actively Exploited In The Wild – Patch Immediately!
Node.js Alerts: High-Severity Flaw (CVE-2025-23166) Risks Remote System Crashes! Update Immediately! CVE-2025-23083 - Node.js EOL
  • Vulnerability

Node.js Alerts: High-Severity Flaw (CVE-2025-23166) Risks Remote System Crashes! Update Immediately!

Do Son May 15, 2025 0
In an important security announcement released recently, the Node.js team has rolled out vital updates for its...
Read More Read more about Node.js Alerts: High-Severity Flaw (CVE-2025-23166) Risks Remote System Crashes! Update Immediately!
BitLocker Encryption Bypassed in Minutes via Bitpixie (CVE-2023-21563) – PoC Reveals High-Risk Attack Path BitLocker bypass, Bitpixie PoC
  • Vulnerability

BitLocker Encryption Bypassed in Minutes via Bitpixie (CVE-2023-21563) – PoC Reveals High-Risk Attack Path

Do Son May 15, 2025 0
Security researchers have demonstrated a powerful software-only technique to bypass Microsoft BitLocker encryption—without needing a screwdriver, soldering...
Read More Read more about BitLocker Encryption Bypassed in Minutes via Bitpixie (CVE-2023-21563) – PoC Reveals High-Risk Attack Path
DarkCloud Stealer Returns: AutoIt-Powered Malware Strikes with New Stealth Tactics DarkCloud Stealer, AutoIt
  • Malware

DarkCloud Stealer Returns: AutoIt-Powered Malware Strikes with New Stealth Tactics

Do Son May 15, 2025 0
First spotted in 2022 and actively developed ever since, DarkCloud Stealer has reemerged with a sophisticated new...
Read More Read more about DarkCloud Stealer Returns: AutoIt-Powered Malware Strikes with New Stealth Tactics
Three Vulnerabilities Expose Apache IoTDB to Attacks Apache IoTDB JEXL injection Apache IoTDB, Security Vulnerabilities
  • Vulnerability

Three Vulnerabilities Expose Apache IoTDB to Attacks

Do Son May 15, 2025 0
Apache IoTDB, a system designed for managing industrial IoT time-series data, faces a series of security vulnerabilities...
Read More Read more about Three Vulnerabilities Expose Apache IoTDB to Attacks
Fortinet Patches Critical TACACS+ Authentication Bypass (CVE-2025-22252) in FortiOS and FortiProxy Fortinet Authentication Bypass CVE-2025-22252
  • Vulnerability

Fortinet Patches Critical TACACS+ Authentication Bypass (CVE-2025-22252) in FortiOS and FortiProxy

Do Son May 15, 2025 0
Fortinet has released patches for a critical vulnerability (CVE-2025-22252, CVSS 9.0) affecting multiple products, including FortiOS, FortiProxy,...
Read More Read more about Fortinet Patches Critical TACACS+ Authentication Bypass (CVE-2025-22252) in FortiOS and FortiProxy
Interlock Ransomware Hits U.S. Defense Contractor AMTEC in Espionage-Driven Data Breach Interlock Ransomware, defense contractor breach
  • Cyber Security
  • Data Leak

Interlock Ransomware Hits U.S. Defense Contractor AMTEC in Espionage-Driven Data Breach

Do Son May 15, 2025 0
A sophisticated ransomware campaign targeting National Defense Corporation (NDC) and its subsidiaries affected the defense supply chain,...
Read More Read more about Interlock Ransomware Hits U.S. Defense Contractor AMTEC in Espionage-Driven Data Breach
Branch Privilege Injection (CVE-2024-45332): New Spectre-Class Attack Bypasses Intel Mitigations with Live PoC Branch Privilege Injection, speculative execution
  • Vulnerability

Branch Privilege Injection (CVE-2024-45332): New Spectre-Class Attack Bypasses Intel Mitigations with Live PoC

Do Son May 15, 2025 0
Security researchers at ETH Zürich have unveiled a novel speculative execution attack—Branch Privilege Injection (CVE-2024-45332)—that subverts Intel’s...
Read More Read more about Branch Privilege Injection (CVE-2024-45332): New Spectre-Class Attack Bypasses Intel Mitigations with Live PoC
Obfuscated Malware Delivered via Google Calendar Invites and Unicode PUAs Google Calendar malware, Unicode PUAs
  • Malware

Obfuscated Malware Delivered via Google Calendar Invites and Unicode PUAs

Do Son May 15, 2025 0
Malware authors have begun exploiting Google Calendar invites and Unicode Private Use Area (PUA) characters to deliver...
Read More Read more about Obfuscated Malware Delivered via Google Calendar Invites and Unicode PUAs
Critical Authentication Bypass in OpenPubkey and OPKSSH Exposes Systems to Remote Access Risks OpenPubkey, authentication bypass
  • Vulnerability

Critical Authentication Bypass in OpenPubkey and OPKSSH Exposes Systems to Remote Access Risks

Do Son May 15, 2025 0
A pair of critical-severity vulnerabilities in the OpenPubkey authentication protocol and its companion tool, OPKSSH, could allow...
Read More Read more about Critical Authentication Bypass in OpenPubkey and OPKSSH Exposes Systems to Remote Access Risks
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.