Skip to content
October 4, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Australian Pension Funds Hacked Australian Pension Funds Hacked
  • Cyber Security

Australian Pension Funds Hacked

Do Son April 4, 2025 0
Read More Read more about Australian Pension Funds Hacked
Oracle Discloses Second Hack (Client Login Data) Oracle breach Oracle Fusion Middleware CVE-2026-21962
  • Data Leak

Oracle Discloses Second Hack (Client Login Data)

Do Son April 4, 2025 0
Read More Read more about Oracle Discloses Second Hack (Client Login Data)
CVE-2025-2704: Critical Bug in OpenVPN Can Trigger Server Crashes CVE-2025-2704
  • Vulnerability

CVE-2025-2704: Critical Bug in OpenVPN Can Trigger Server Crashes

Do Son April 4, 2025 0
Read More Read more about CVE-2025-2704: Critical Bug in OpenVPN Can Trigger Server Crashes
Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868) CVE-2024-53868
  • Vulnerability

Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868)

Do Son April 4, 2025 0
Read More Read more about Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868)
RolandSkimmer: New Wave of Credit Card Skimming Attacks RolandSkimmer
  • Malware

RolandSkimmer: New Wave of Credit Card Skimming Attacks

Do Son April 4, 2025 0
Read More Read more about RolandSkimmer: New Wave of Credit Card Skimming Attacks
Operation HollowQuill Unveiled: Weaponized Documents Infiltrate Russia’s Defense Sector Operation HollowQuill
  • Cyber Security

Operation HollowQuill Unveiled: Weaponized Documents Infiltrate Russia’s Defense Sector

Do Son April 4, 2025 0
Read More Read more about Operation HollowQuill Unveiled: Weaponized Documents Infiltrate Russia’s Defense Sector
Carding Automation: Malicious PyPI Package Threatens Stores Carding attacks
  • Malware

Carding Automation: Malicious PyPI Package Threatens Stores

Do Son April 4, 2025 0
Read More Read more about Carding Automation: Malicious PyPI Package Threatens Stores
Beware the Bait: BeaverTail and Tropidoor Malware Lurk in Recruitment Emails WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Malware

Beware the Bait: BeaverTail and Tropidoor Malware Lurk in Recruitment Emails

Do Son April 4, 2025 0
Read More Read more about Beware the Bait: BeaverTail and Tropidoor Malware Lurk in Recruitment Emails
Cisco Addresses High Severity Vulnerabilities in Enterprise Chat and Email, and Meraki MX/Z Series Devices Cisco Secure FMC CVE-2026-20079 Cisco RCE, Firewall Vulnerability Cisco Nexus, vulnerability CVE-2024-20412 - Cisco data breach
  • Vulnerability

Cisco Addresses High Severity Vulnerabilities in Enterprise Chat and Email, and Meraki MX/Z Series Devices

Do Son April 4, 2025 0
Read More Read more about Cisco Addresses High Severity Vulnerabilities in Enterprise Chat and Email, and Meraki MX/Z Series Devices
CVE-2025-22457: UNC5221 Exploits Ivanti Zero-Day Flaw to Deploy TRAILBLAZE and BRUSHFIRE Malware CVE-2025-22457
  • Vulnerability

CVE-2025-22457: UNC5221 Exploits Ivanti Zero-Day Flaw to Deploy TRAILBLAZE and BRUSHFIRE Malware

Do Son April 3, 2025 0
Read More Read more about CVE-2025-22457: UNC5221 Exploits Ivanti Zero-Day Flaw to Deploy TRAILBLAZE and BRUSHFIRE Malware
CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution CVE-2025-31334
  • Vulnerability

CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution

Do Son April 3, 2025 0
Read More Read more about CVE-2025-31334: WinRAR Flaw Enables Mark-of-the-Web Bypass and Arbitrary Code Execution
AI Crawlers Deluge Wikimedia Commons, Consuming Over 65% of High-Cost Bandwidth ChatGPT Lockdown Mode OpenAI OpenClaw acquisition OpenAI Prism GPT-5.2 LaTeX, scientific research AI workspace OpenAI, Mixpanel Breach ChatGPT Data Preservation, NYT Lawsuit ChatGPT Apps SDK, super app OpenAI Jony Ive, AI Hardware Delay Musk Apple lawsuit, App Store antitrust UK AI Partnership, OpenAI Collaboration Jony Ive OpenAI, DoD Contract OpenAI Lawsuit, ChatGPT Privacy North Korea ChatGPT - GPT-4.5 model OpenAI Models, AI Advancements OpenAI pricing, Flex API
  • Technology

AI Crawlers Deluge Wikimedia Commons, Consuming Over 65% of High-Cost Bandwidth

Do Son April 3, 2025 0
Read More Read more about AI Crawlers Deluge Wikimedia Commons, Consuming Over 65% of High-Cost Bandwidth
Google Password Manager Adds Passkeys, Future Export Teased Google Password Manager passkey export
  • Technology

Google Password Manager Adds Passkeys, Future Export Teased

Do Son April 3, 2025 0
Read More Read more about Google Password Manager Adds Passkeys, Future Export Teased
Amazon Eyes TikTok: Acquisition Race Heats Up TikTok USDS Joint Venture LLC, TikTok U.S. divestment 2026 TikTok Deal, ByteDance Divestment U.S. ban TikTok TikTok Sale, Trump Announcement TikTok lawsuit Trump Amazon Acquisition
  • Technology

Amazon Eyes TikTok: Acquisition Race Heats Up

Do Son April 3, 2025 0
Read More Read more about Amazon Eyes TikTok: Acquisition Race Heats Up
Verizon Call Filter App Vulnerability Exposed Call Records of Millions Verizon
  • Data Leak
  • Vulnerability

Verizon Call Filter App Vulnerability Exposed Call Records of Millions

Do Son April 3, 2025 0
Read More Read more about Verizon Call Filter App Vulnerability Exposed Call Records of Millions
Multiple Jenkins Plugin and Core Vulnerabilities Expose Sensitive Data and Execution Paths CVE-2025-31720
  • Vulnerability

Multiple Jenkins Plugin and Core Vulnerabilities Expose Sensitive Data and Execution Paths

Do Son April 3, 2025 0
Read More Read more about Multiple Jenkins Plugin and Core Vulnerabilities Expose Sensitive Data and Execution Paths
CVE-2025-31137: React Router Vulnerability Exposes Web Apps to Cache Poisoning and WAF Bypass Attacks CVE-2025-31137
  • Vulnerability

CVE-2025-31137: React Router Vulnerability Exposes Web Apps to Cache Poisoning and WAF Bypass Attacks

Do Son April 3, 2025 0
Read More Read more about CVE-2025-31137: React Router Vulnerability Exposes Web Apps to Cache Poisoning and WAF Bypass Attacks
CVE-2025-0415 (CVSSv4 9.2): Critical Vulnerability Discovered in Moxa Network Devices Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability

CVE-2025-0415 (CVSSv4 9.2): Critical Vulnerability Discovered in Moxa Network Devices

Do Son April 3, 2025 0
Read More Read more about CVE-2025-0415 (CVSSv4 9.2): Critical Vulnerability Discovered in Moxa Network Devices
Multiple Vulnerabilities in Zabbix Open the Door to XSS, DoS, and SQL Injection CVE-2024-36465
  • Vulnerability

Multiple Vulnerabilities in Zabbix Open the Door to XSS, DoS, and SQL Injection

Do Son April 3, 2025 0
Read More Read more about Multiple Vulnerabilities in Zabbix Open the Door to XSS, DoS, and SQL Injection
Outlaw Linux Malware: Persistent Threat Leveraging Simplicity Outlaw Linux malware
  • Malware

Outlaw Linux Malware: Persistent Threat Leveraging Simplicity

Do Son April 3, 2025 0
Read More Read more about Outlaw Linux Malware: Persistent Threat Leveraging Simplicity
DLL Sideloading Exposed: TookPS Hides with TeamViewer TookPS downloader
  • Malware

DLL Sideloading Exposed: TookPS Hides with TeamViewer

Do Son April 3, 2025 0
Read More Read more about DLL Sideloading Exposed: TookPS Hides with TeamViewer
Rancher Users: Update Now to Fix Admin Takeover Bug (CVE-2025-23391) CVE-2025-23391
  • Vulnerability

Rancher Users: Update Now to Fix Admin Takeover Bug (CVE-2025-23391)

Do Son April 3, 2025 0
Read More Read more about Rancher Users: Update Now to Fix Admin Takeover Bug (CVE-2025-23391)
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intel📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-103355CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105135CVSS 10.0
    A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105134CVSS 10.0
    A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the...
    📅 Updated: Oct 4, 2026
  • CVE-2026-97637CVSS 9.8
    The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in...
    📅 Updated: Oct 3, 2026
  • CVE-2026-92084CVSS 9.1
    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to...
    📅 Updated: Oct 3, 2026
  • CVE-2026-87115CVSS 9.1
    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...
    📅 Updated: Oct 3, 2026
  • CVE-2026-14378CVSS 9.8
    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all...
    📅 Updated: Oct 3, 2026
  • CVE-2026-19660CVSS 9.8
    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
    📅 Updated: Oct 3, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.