Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations Linux Proxy Malware, Legitimate Tool Abuse
  • Cybercriminals
  • Linux

Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations

Do Son July 3, 2025 0
Read More Read more about Linux Servers Hijacked: Attackers Install Legitimate Proxy Software for Covert Operations
DCRat: Sophisticated RAT Delivered via Phishing Campaign Impersonating Government Entity axios Supply Chain Attack WAVESHAPER.V2 SnappyBee Malware Salt Typhoon Stately Taurus ScoringMathTea RAT, Lazarus Reflective DLL
  • Malware

DCRat: Sophisticated RAT Delivered via Phishing Campaign Impersonating Government Entity

Do Son July 3, 2025 0
Read More Read more about DCRat: Sophisticated RAT Delivered via Phishing Campaign Impersonating Government Entity
New macOS Crypto Stealer Targets Ledger Live Users, Mimics AMOS with Stealthy Tactics macOS Stealer, Crypto Malware
  • Malware

New macOS Crypto Stealer Targets Ledger Live Users, Mimics AMOS with Stealthy Tactics

Do Son July 3, 2025 0
Read More Read more about New macOS Crypto Stealer Targets Ledger Live Users, Mimics AMOS with Stealthy Tactics
Qantas Data Breach: Millions Affected by Third-Party Contact Centre Cyber Incident Qantas Data Breach, Cyberattack
  • Data Leak

Qantas Data Breach: Millions Affected by Third-Party Contact Centre Cyber Incident

Do Son July 2, 2025 0
Read More Read more about Qantas Data Breach: Millions Affected by Third-Party Contact Centre Cyber Incident
Microsoft Hikes On-Premises Server & CAL Prices by Up to 20% Starting July Microsoft, pricing change Microsoft Server Pricing, On-Premises Price Hike Security Core Priority - Microsoft data centers
  • Technology

Microsoft Hikes On-Premises Server & CAL Prices by Up to 20% Starting July

Do Son July 2, 2025 0
Read More Read more about Microsoft Hikes On-Premises Server & CAL Prices by Up to 20% Starting July
Cloudflare Launches “Pay Per Crawl”: Websites Can Now Charge AI Crawlers for Content Cloudflare layoffs 2026 AI bot traffic surge Content Signals Policy, AI Content Usage Cloudflare, Certificate Misissuance Salesforce, supply chain attack DDoS attack, Cloudflare Perplexity AI, Web Scraping Pay Per Crawl Cloudflare abuse R2 outage HTTP Cloudflare Blocking
  • Technology

Cloudflare Launches “Pay Per Crawl”: Websites Can Now Charge AI Crawlers for Content

Do Son July 2, 2025 0
Read More Read more about Cloudflare Launches “Pay Per Crawl”: Websites Can Now Charge AI Crawlers for Content
Apple Sues Ex-Vision Pro Engineer Di Liu: Accused of Stealing Secrets & Joining Competitor Snap Apple Background Security CVE-2026-20643 Apple Background Security Improvement Apple Backdoor Apple Lawsuit, Data Exfiltration CVE-2024-44131 - CVE-2025-24118 PoC
  • Technology

Apple Sues Ex-Vision Pro Engineer Di Liu: Accused of Stealing Secrets & Joining Competitor Snap

Do Son July 2, 2025 0
Read More Read more about Apple Sues Ex-Vision Pro Engineer Di Liu: Accused of Stealing Secrets & Joining Competitor Snap
Windows User Count Controversy: Microsoft Silently “Corrects” User Base to 1.4 Billion After Implied 400M Drop C Windows SecureBoot folder KB5089549 Windows 11 BSOD Microsoft Windows, Rust programming WINS Service Deprecation Windows Server DNS Migration Windows Driver Standard OEM Kernel Privileges Windows Agentic OS Task Manager Bug, Windows 11 Performance Windows 11, Microsoft, WinRE, Update Bug, Tech Support Windows 11 OOBE, Microsoft Account Mandatory Windows 11, SSD failures Windows 11 Recovery, Black Screen of Death Windows 11 Update Issue, KB5062324 Windows 11, Indicator Bar
  • Windows

Windows User Count Controversy: Microsoft Silently “Corrects” User Base to 1.4 Billion After Implied 400M Drop

Do Son July 2, 2025 0
Read More Read more about Windows User Count Controversy: Microsoft Silently “Corrects” User Base to 1.4 Billion After Implied 400M Drop
Google Hit with $314M Verdict: Jury Rules Android Secretly Used Cellular Data for Tracking Google Lawsuit, Android Data Privacy Android September Security
  • Android

Google Hit with $314M Verdict: Jury Rules Android Secretly Used Cellular Data for Tracking

Do Son July 2, 2025 0
Read More Read more about Google Hit with $314M Verdict: Jury Rules Android Secretly Used Cellular Data for Tracking
Google’s New “Offerwall” Tool Helps Publishers Monetize Content Amidst AI Search Impact Google Offerwall, Publisher Monetization
  • Technology

Google’s New “Offerwall” Tool Helps Publishers Monetize Content Amidst AI Search Impact

Do Son July 2, 2025 0
Read More Read more about Google’s New “Offerwall” Tool Helps Publishers Monetize Content Amidst AI Search Impact
Cloudflare Unveils AI Crawler Leaderboard: ByteDance Ranks Last AI Crawlers, Cloudflare Leaderboard
  • Technology

Cloudflare Unveils AI Crawler Leaderboard: ByteDance Ranks Last

Do Son July 2, 2025 0
Read More Read more about Cloudflare Unveils AI Crawler Leaderboard: ByteDance Ranks Last
CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases Wing FTP Server, Remote Code Execution
  • Vulnerability Report

CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases

Do Son July 2, 2025 0
Read More Read more about CVSS 10 RCE in Wing FTP Server (CVE-2025-47812) Allows Full Server Takeover, PoC Releases
CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover WordPress Plugin, Arbitrary File Deletion
  • Vulnerability Report

CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover

Do Son July 2, 2025 0
Read More Read more about CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing Smishing, SMS Blaster
  • Cybercriminals

Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing

Do Son July 2, 2025 0
Read More Read more about Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing
ANSSI Exposes “Houken”: China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits Houken, Ivanti CSA Zero-Day
  • Cyber Security

ANSSI Exposes “Houken”: China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits

Do Son July 2, 2025 0
Read More Read more about ANSSI Exposes “Houken”: China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits
OFAC Sanctions Russian “Bulletproof Host” Aeza Group: Linked to Ransomware, Infostealers & Darknet OFAC Sanctions, Aeza Group
  • Cybercriminals

OFAC Sanctions Russian “Bulletproof Host” Aeza Group: Linked to Ransomware, Infostealers & Darknet

Do Son July 2, 2025 0
Read More Read more about OFAC Sanctions Russian “Bulletproof Host” Aeza Group: Linked to Ransomware, Infostealers & Darknet
DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cybercriminals

DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons

Do Son July 2, 2025 0
Read More Read more about DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
CVSS 9.8 RCE in Netflix Conductor Exposes Servers to Full Remote Shell – PoC Available Remote Code Execution Netflix Conductor
  • Vulnerability

CVSS 9.8 RCE in Netflix Conductor Exposes Servers to Full Remote Shell – PoC Available

Do Son July 2, 2025 0
Read More Read more about CVSS 9.8 RCE in Netflix Conductor Exposes Servers to Full Remote Shell – PoC Available
Multi DataEase Flaws: RCE & Bypass Vulnerabilities Threaten BI Platform via JDBC DataEase Vulnerabilities, Remote Code Execution
  • Vulnerability Report

Multi DataEase Flaws: RCE & Bypass Vulnerabilities Threaten BI Platform via JDBC

Do Son July 2, 2025 0
Read More Read more about Multi DataEase Flaws: RCE & Bypass Vulnerabilities Threaten BI Platform via JDBC
Graylog Flaw (CVE-2025-53106, CVSS 8.8): Privilege Escalation Via API Token Abuse Graylog Vulnerability, Privilege Escalation
  • Vulnerability Report

Graylog Flaw (CVE-2025-53106, CVSS 8.8): Privilege Escalation Via API Token Abuse

Do Son July 2, 2025 0
Read More Read more about Graylog Flaw (CVE-2025-53106, CVSS 8.8): Privilege Escalation Via API Token Abuse
Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection Frappe Framework, Critical Vulnerabilities
  • Vulnerability Report

Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection

Do Son July 2, 2025 0
Read More Read more about Security Flaws in Frappe Framework Expose Self-Hosted ERPNext Users to Takeovers, XSS, and SQL Injection
Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware Oracle EBS Zero-Day, GRACEFUL SPIDER Cracked Software, Supply Chain Attack Black Basta - NOVA stealer
  • Cybercriminals

Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware

Do Son July 2, 2025 0
Read More Read more about Cracked Software Danger: Report Exposes Pakistani Freelancers Building Websites to Deliver Stealer Malware
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-88771CVSS 9.5
    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37,...
    CISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-102422CVSS 9.2
    shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out...
    📅 Updated: Sep 29, 2026
  • CVE-2026-88378CVSS 9.8
    QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().
    📅 Updated: Sep 29, 2026
  • CVE-2026-88365CVSS 9.8
    minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field.
    📅 Updated: Sep 29, 2026
  • CVE-2026-79766CVSS 9.1
    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until...
    📅 Updated: Sep 29, 2026
  • CVE-2026-77602CVSS 9.9
    OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded...
    📅 Updated: Sep 29, 2026
  • CVE-2026-51996CVSS 9.8
    An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the...
    📅 Updated: Sep 29, 2026
  • CVE-2026-97359CVSS 10.0
    HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated...
    📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.