Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours Exploit Jupyter Notebooks
  • Malware

Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours

Do Son July 4, 2025 0
Read More Read more about Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
Critical Lucee Flaw (CVE-2025-34074, CVSS 9.4): Authenticated RCE Via Scheduled Task Abuse, Metasploit Module Out Lucee, Remote Code Execution
  • Vulnerability Report

Critical Lucee Flaw (CVE-2025-34074, CVSS 9.4): Authenticated RCE Via Scheduled Task Abuse, Metasploit Module Out

Do Son July 4, 2025 0
Read More Read more about Critical Lucee Flaw (CVE-2025-34074, CVSS 9.4): Authenticated RCE Via Scheduled Task Abuse, Metasploit Module Out
iOS 26 FaceTime Will Pause Calls for Sensitive Content Detection AirDrop PIN Pairing 30-Day AirDrop Trust iOS 26 downgrade iOS 26 battery drain 5G MacBook, Cellular Mac iOS 26, Communication Safety iOS 26, Wi-Fi Synchronization iOS 26, Wi-Fi Synchronization Apple Redesign Apple Public Betas, AirPods Firmware
  • Technology

iOS 26 FaceTime Will Pause Calls for Sensitive Content Detection

Do Son July 3, 2025 0
Read More Read more about iOS 26 FaceTime Will Pause Calls for Sensitive Content Detection
Pixel 6a Battery Alert: Mandatory Android 16 Update to Limit Capacity After 400 Cycles Due to Overheating Risk Pixel6A
  • Android

Pixel 6a Battery Alert: Mandatory Android 16 Update to Limit Capacity After 400 Cycles Due to Overheating Risk

Do Son July 3, 2025 0
Read More Read more about Pixel 6a Battery Alert: Mandatory Android 16 Update to Limit Capacity After 400 Cycles Due to Overheating Risk
Google Veo 3 Unleashed: AI-Powered Video Generation Now Available for Cinematic Creations Apple Gemini AI AI Overviews, Google Search Google Gemini, Android Privacy Google Veo 3, AI Video Generation Google AI video, generative AI
  • Technology

Google Veo 3 Unleashed: AI-Powered Video Generation Now Available for Cinematic Creations

Do Son July 3, 2025 0
Read More Read more about Google Veo 3 Unleashed: AI-Powered Video Generation Now Available for Cinematic Creations
Microsoft’s Youngest Security Researcher: Dylan, 13, Uncovers Teams Flaw & Prompts Bug Bounty Rule Change Microsoft Researcher, Bug Bounty Azure DDoS attack
  • Vulnerability Report

Microsoft’s Youngest Security Researcher: Dylan, 13, Uncovers Teams Flaw & Prompts Bug Bounty Rule Change

Do Son July 3, 2025 0
Read More Read more about Microsoft’s Youngest Security Researcher: Dylan, 13, Uncovers Teams Flaw & Prompts Bug Bounty Rule Change
Google & XREAL Unveil “Project Aura”: AI-Powered Smart Glasses Coming in 2026 Google Smart Glasses, Project Aura
  • Technology

Google & XREAL Unveil “Project Aura”: AI-Powered Smart Glasses Coming in 2026

Do Son July 3, 2025 0
Read More Read more about Google & XREAL Unveil “Project Aura”: AI-Powered Smart Glasses Coming in 2026
Microsoft Azure Slashes Startup Credits: Up to $150K Program Replaced by Stricter $5K Offer HTTP.sys RCE vulnerability, Windows HTTP stack exploit, CVE-2026-47291 Netlogon RCE vulnerability Exploited in the wild Secure Boot certificate renewal 2026, Windows 11 UEFI update Community-First AI Infrastructure, Microsoft self-funding energy mandate aka.ms/aoh online portal CVE-2025-55681, Windows DWM Elevation Windows Administrator Protection, CVE-2025-60718 Microsoft AI Compute, IREN Infrastructure Microsoft Japan PPA, Renewable Energy Microsoft AI Investment, Cloud Expansion Microsoft Azure, Startup Credits Infinite Workday, AI in Work Microsoft Russia, Bankruptcy AI code generation, Microsoft AI Microsoft Layoffs, Restructuring
  • Technology

Microsoft Azure Slashes Startup Credits: Up to $150K Program Replaced by Stricter $5K Offer

Do Son July 3, 2025 0
Read More Read more about Microsoft Azure Slashes Startup Credits: Up to $150K Program Replaced by Stricter $5K Offer
Microsoft Axes 9,000 Jobs, Shuts Down Studios: Perfect Dark & Everwild Canceled Amid Gaming Layoffs AI controversy, Xbox layoffs Xbox ban VPN Microsoft Layoffs, Xbox Gaming Cuts
  • Technology

Microsoft Axes 9,000 Jobs, Shuts Down Studios: Perfect Dark & Everwild Canceled Amid Gaming Layoffs

Do Son July 3, 2025 0
Read More Read more about Microsoft Axes 9,000 Jobs, Shuts Down Studios: Perfect Dark & Everwild Canceled Amid Gaming Layoffs
Perplexity AI Launches “Max” Tier: $200/Month for Unlimited AI Tools & Frontier Model Access AI Copyright, Getty Images, Perplexity AI Perplexity Max, AI Subscription
  • Technology

Perplexity AI Launches “Max” Tier: $200/Month for Unlimited AI Tools & Frontier Model Access

Do Son July 3, 2025 0
Read More Read more about Perplexity AI Launches “Max” Tier: $200/Month for Unlimited AI Tools & Frontier Model Access
Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure? Energy Meter RCE CVE-2025-41709 ICS Exposure, Power Grid Security CVE-2025-1393 & CVE-2024-23943
  • Vulnerability Report

Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure?

Do Son July 3, 2025 0
Read More Read more about Power Grid ICS Are Exposed — What Does This Mean for Critical Infrastructure?
Urgent: Linux Kernel Flaw Allows Remote Crash, PoC Available! Linux Kernel, NFS DoS NFSundown
  • Vulnerability

Urgent: Linux Kernel Flaw Allows Remote Crash, PoC Available!

Do Son July 3, 2025 0
Read More Read more about Urgent: Linux Kernel Flaw Allows Remote Crash, PoC Available!
Actively Exploited Google Chrome Zero-Day (CVE-2025-6554) Added to CISA’s KEV Catalog, PoC Available Chrome security update exploit in the wild Chrome Zero-Day CVE-2026-3909 Chrome Zero-Day PoC CVE-2026-2441 Chrome Zero-Day CVE-2026-2441 Chrome Zero-Day, Active Exploitation CVE-2025-10585 Chrome vulnerability, zero-day exploit CVE-2025-6558 Chrome Zero-Day, V8 Vulnerability Chrome Zero-Day, Security Update
  • Vulnerability

Actively Exploited Google Chrome Zero-Day (CVE-2025-6554) Added to CISA’s KEV Catalog, PoC Available

Do Son July 3, 2025 0
Read More Read more about Actively Exploited Google Chrome Zero-Day (CVE-2025-6554) Added to CISA’s KEV Catalog, PoC Available
Pro-Russian Hacktivists Escalate 2025 Cyber Offensive: Targeting Western Critical Infrastructure & ICS Pro-Russian Hacktivism, Critical Infrastructure Attacks
  • Cyber Security

Pro-Russian Hacktivists Escalate 2025 Cyber Offensive: Targeting Western Critical Infrastructure & ICS

Do Son July 3, 2025 0
Read More Read more about Pro-Russian Hacktivists Escalate 2025 Cyber Offensive: Targeting Western Critical Infrastructure & ICS
Four Critical RCE Flaws Found in Grafana Plugins via Chromium: Patch Now! Grafana Vulnerabilities, Remote Code Execution
  • Vulnerability Report

Four Critical RCE Flaws Found in Grafana Plugins via Chromium: Patch Now!

Do Son July 3, 2025 0
Read More Read more about Four Critical RCE Flaws Found in Grafana Plugins via Chromium: Patch Now!
Global E-commerce Fraud Ring Uncovered: Fake Apple, Nordstrom, Brooks Brothers Sites Steal Credit Cards E-commerce Fraud, Phishing Campaign
  • Cybercriminals

Global E-commerce Fraud Ring Uncovered: Fake Apple, Nordstrom, Brooks Brothers Sites Steal Credit Cards

Do Son July 3, 2025 0
Read More Read more about Global E-commerce Fraud Ring Uncovered: Fake Apple, Nordstrom, Brooks Brothers Sites Steal Credit Cards
CVE-2025-20309 (CVSS 10): Cisco Patches Critical Static SSH Root Credential Flaw in Unified CM Cisco UC, Critical RCE
  • Vulnerability Report

CVE-2025-20309 (CVSS 10): Cisco Patches Critical Static SSH Root Credential Flaw in Unified CM

Do Son July 3, 2025 0
Read More Read more about CVE-2025-20309 (CVSS 10): Cisco Patches Critical Static SSH Root Credential Flaw in Unified CM
NimDoor: North Korean APT Uses Nim-Based Malware for Stealthy Web3 & Crypto Attacks on macOS! NimDoor, macOS Malware
  • Malware

NimDoor: North Korean APT Uses Nim-Based Malware for Stealthy Web3 & Crypto Attacks on macOS!

Do Son July 3, 2025 0
Read More Read more about NimDoor: North Korean APT Uses Nim-Based Malware for Stealthy Web3 & Crypto Attacks on macOS!
dpkg-deb Flaw Opens Path to Disk Exhaustion Denial-of-Service on Debian Systems dpkg-deb, DoS Vulnerability
  • Vulnerability Report

dpkg-deb Flaw Opens Path to Disk Exhaustion Denial-of-Service on Debian Systems

Do Son July 3, 2025 0
Read More Read more about dpkg-deb Flaw Opens Path to Disk Exhaustion Denial-of-Service on Debian Systems
Qwizzserial: Telegram-Driven Android SMS Stealer Infects 100,000 Devices Android Malware, Qwizzserial
  • Malware

Qwizzserial: Telegram-Driven Android SMS Stealer Infects 100,000 Devices

Do Son July 3, 2025 0
Read More Read more about Qwizzserial: Telegram-Driven Android SMS Stealer Infects 100,000 Devices
Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations Linux Proxy Malware, Legitimate Tool Abuse
  • Cybercriminals
  • Linux

Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations

Do Son July 3, 2025 0
Read More Read more about Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations
DCRat: Sophisticated RAT Delivered via Phishing Campaign Impersonating Government Entity axios Supply Chain Attack WAVESHAPER.V2 SnappyBee Malware Salt Typhoon Stately Taurus ScoringMathTea RAT, Lazarus Reflective DLL
  • Malware

DCRat: Sophisticated RAT Delivered via Phishing Campaign Impersonating Government Entity

Do Son July 3, 2025 0
Read More Read more about DCRat: Sophisticated RAT Delivered via Phishing Campaign Impersonating Government Entity
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-97359CVSS 10.0
    HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated...
    📅 Updated: Sep 29, 2026
  • CVE-2026-67231CVSS 9.1
    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store...
    📅 Updated: Sep 29, 2026
  • CVE-2026-67404CVSS 9.2
    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no...
    📅 Updated: Sep 29, 2026
  • CVE-2026-96759CVSS 9.3
    orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options...
    📅 Updated: Sep 29, 2026
  • CVE-2026-96754CVSS 9.3
    orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102240CVSS 10.0
    A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of...
    📅 Updated: Sep 29, 2026
  • CVE-2026-101354CVSS 9.4
    A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102361CVSS 9.3
    mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.