Skip to content
October 4, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical Vulnerability (CVE-2025-31498) Patched in c-ares DNS Library c-ares Vulnerability CVE-2025-31498
  • Vulnerability

Critical Vulnerability (CVE-2025-31498) Patched in c-ares DNS Library

Do Son April 11, 2025 0
Read More Read more about Critical Vulnerability (CVE-2025-31498) Patched in c-ares DNS Library
Shuckworm’s Sophisticated Cyber Campaign Targets Ukraine Military Mission Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security
  • Malware

Shuckworm’s Sophisticated Cyber Campaign Targets Ukraine Military Mission

Do Son April 10, 2025 0
Read More Read more about Shuckworm’s Sophisticated Cyber Campaign Targets Ukraine Military Mission
European Commission Launches “AI Continent Action Plan” to Compete with US and China AI Continent Action Plan European Commission EU repairability label, smartphone labeling
  • Technology

European Commission Launches “AI Continent Action Plan” to Compete with US and China

Do Son April 10, 2025 0
Read More Read more about European Commission Launches “AI Continent Action Plan” to Compete with US and China
WordPress.com Launches AI Website Builder for Easy Site Creation AI Website Builder WordPress.com
  • Technology

WordPress.com Launches AI Website Builder for Easy Site Creation

Do Son April 10, 2025 0
Read More Read more about WordPress.com Launches AI Website Builder for Easy Site Creation
Anthropic Launches Claude Max Subscription with Higher Usage Tiers Claude Max Anthropic
  • Technology

Anthropic Launches Claude Max Subscription with Higher Usage Tiers

Do Son April 10, 2025 0
Read More Read more about Anthropic Launches Claude Max Subscription with Higher Usage Tiers
KB5055523 Update Creates Unnecessary inetpub Folder in Windows 11 24H2 inetpub Folder KB5055523
  • Windows

KB5055523 Update Creates Unnecessary inetpub Folder in Windows 11 24H2

Do Son April 10, 2025 0
Read More Read more about KB5055523 Update Creates Unnecessary inetpub Folder in Windows 11 24H2
Google Gemini to Support Anthropic’s Model Context Protocol (MCP) Agentic AI Foundation, MCP Protocol Open-Source Chrome DevTools AI, MCP Protocol Model Context Protocol (MCP) Gemini AI Windows AI future, AI interoperability
  • Technology

Google Gemini to Support Anthropic’s Model Context Protocol (MCP)

Do Son April 10, 2025 0
Read More Read more about Google Gemini to Support Anthropic’s Model Context Protocol (MCP)
Google Firebase Studio Launches as AI-Powered IDE Rival to Cursor AI Cursor AI Google Firebase Studio
  • Technology

Google Firebase Studio Launches as AI-Powered IDE Rival to Cursor AI

Do Son April 10, 2025 0
Read More Read more about Google Firebase Studio Launches as AI-Powered IDE Rival to Cursor AI
KB5002700 Update Causing Office 2016 Crashes on Windows 10/11 Office 2021 End of Life CVE-2024-21413 KB5002700 Office 2016 Update
  • Windows

KB5002700 Update Causing Office 2016 Crashes on Windows 10/11

Do Son April 10, 2025 0
Read More Read more about KB5002700 Update Causing Office 2016 Crashes on Windows 10/11
SonicWall Patches Multi Vulnerabilities in NetExtender VPN Client SonicWall Zero-Day, SMA1000 Exploit Chain SonicWall, firewall configuration CVE-2024-29010 & CVE-2024-29011 SonicWall NetExtender VPN Vulnerability
  • Vulnerability

SonicWall Patches Multi Vulnerabilities in NetExtender VPN Client

Do Son April 10, 2025 0
Read More Read more about SonicWall Patches Multi Vulnerabilities in NetExtender VPN Client
CISA Warns of Actively Exploited Linux Kernel Vulnerabilities (CVE-2024-53197, CVE-2024-53150) CVE-2024-28986 exploitation SolarWinds Web Help Desk Linux Vulnerability CVE-2024-53197
  • Vulnerability

CISA Warns of Actively Exploited Linux Kernel Vulnerabilities (CVE-2024-53197, CVE-2024-53150)

Do Son April 10, 2025 0
Read More Read more about CISA Warns of Actively Exploited Linux Kernel Vulnerabilities (CVE-2024-53197, CVE-2024-53150)
Seven Years Later: Cisco CVE-2018-0171 Still Exposes Thousands to RCE Cisco ISE Root Escalation * Read-Only Admin Exploit Cisco Secure FMC Vulnerability CVE-2026-20131 Cisco Meeting Management Vulnerability CVE-2026-20098 Cisco vulnerability, RCE flaw CVE-2025-20265 Cisco Meraki, VPN Vulnerability Cisco Nexus Dashboard - CVE-2024-20424 CVE-2025-20115 Cisco Vulnerability CVE-2018-0171 Privilege Escalation Cisco Unified Intelligence Center
  • Vulnerability

Seven Years Later: Cisco CVE-2018-0171 Still Exposes Thousands to RCE

Do Son April 10, 2025 0
Read More Read more about Seven Years Later: Cisco CVE-2018-0171 Still Exposes Thousands to RCE
SureTriggers Vulnerability Exposes 100,000+ WordPress Sites to Admin Takeover WordPress Vulnerability SureTriggers
  • Vulnerability

SureTriggers Vulnerability Exposes 100,000+ WordPress Sites to Admin Takeover

Do Son April 10, 2025 0
Read More Read more about SureTriggers Vulnerability Exposes 100,000+ WordPress Sites to Admin Takeover
Dell Addresses Security Vulnerabilities in PowerScale OneFS CVE-2024-37143 & CVE-2024-37144 Dell PowerScale OneFS vulnerability
  • Vulnerability

Dell Addresses Security Vulnerabilities in PowerScale OneFS

Do Son April 10, 2025 0
Read More Read more about Dell Addresses Security Vulnerabilities in PowerScale OneFS
Scattered Spider Evolving: New Tactics and Spectre RAT Scattered Spider Tactics Phishing kits
  • Cybercriminals
  • Malware

Scattered Spider Evolving: New Tactics and Spectre RAT

Do Son April 10, 2025 0
Read More Read more about Scattered Spider Evolving: New Tactics and Spectre RAT
NATS Server Vulnerability: Missing Access Controls in JetStream API NATS security JetStream API vulnerability
  • Vulnerability

NATS Server Vulnerability: Missing Access Controls in JetStream API

Do Son April 10, 2025 0
Read More Read more about NATS Server Vulnerability: Missing Access Controls in JetStream API
Critical SSRF Vulnerability Patched in LNbits Lightning Wallet Server LNbits SSRF LNURL Vulnerability
  • Vulnerability

Critical SSRF Vulnerability Patched in LNbits Lightning Wallet Server

Do Son April 10, 2025 0
Read More Read more about Critical SSRF Vulnerability Patched in LNbits Lightning Wallet Server
Spyware Alert: BADBAZAAR and MOONSHINE Target Civil Society and Ethnic Groups BADBAZAAR, MOONSHINE
  • Malware

Spyware Alert: BADBAZAAR and MOONSHINE Target Civil Society and Ethnic Groups

Do Son April 10, 2025 0
Read More Read more about Spyware Alert: BADBAZAAR and MOONSHINE Target Civil Society and Ethnic Groups
High-Severity XXE Vulnerability Found in NAKIVO Backup & Replication NAKIVO XXE vulnerability CVE-2025-32406
  • Vulnerability

High-Severity XXE Vulnerability Found in NAKIVO Backup & Replication

Do Son April 10, 2025 0
Read More Read more about High-Severity XXE Vulnerability Found in NAKIVO Backup & Replication
“Pick Your Poison” Phishing Attack: Credentials or Malware? Phishing Attack Double-edged phishing
  • Cybercriminals
  • Malware

“Pick Your Poison” Phishing Attack: Credentials or Malware?

Do Son April 10, 2025 0
Read More Read more about “Pick Your Poison” Phishing Attack: Credentials or Malware?
Evolving Cybercrime: Inside the Russian-Speaking Underground Russian cybercriminal underground Cybercrime trends
  • Cybercriminals

Evolving Cybercrime: Inside the Russian-Speaking Underground

Do Son April 10, 2025 0
Read More Read more about Evolving Cybercrime: Inside the Russian-Speaking Underground
Tool Poisoning Attacks: Critical Vulnerability Discovered in Model Context Protocol (MCP) Tool Poisoning Attack MCP Vulnerability
  • Vulnerability

Tool Poisoning Attacks: Critical Vulnerability Discovered in Model Context Protocol (MCP)

Do Son April 10, 2025 0
Read More Read more about Tool Poisoning Attacks: Critical Vulnerability Discovered in Model Context Protocol (MCP)
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intel📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-103355CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105135CVSS 10.0
    A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105134CVSS 10.0
    A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the...
    📅 Updated: Oct 4, 2026
  • CVE-2026-97637CVSS 9.8
    The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in...
    📅 Updated: Oct 3, 2026
  • CVE-2026-92084CVSS 9.1
    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to...
    📅 Updated: Oct 3, 2026
  • CVE-2026-87115CVSS 9.1
    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...
    📅 Updated: Oct 3, 2026
  • CVE-2026-14378CVSS 9.8
    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all...
    📅 Updated: Oct 3, 2026
  • CVE-2026-19660CVSS 9.8
    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
    📅 Updated: Oct 3, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.