Skip to content
October 4, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
DPRK IT Workers: A Global Threat Expanding in Scope and Scale DPRK IT worker
  • Cyber Security

DPRK IT Workers: A Global Threat Expanding in Scope and Scale

Do Son April 3, 2025 0
Read More Read more about DPRK IT Workers: A Global Threat Expanding in Scope and Scale
High-Severity Vulnerabilities in Bruno API Client Expose Users to Potential RCE CVE-2025-30354 & CVE-2025-30210
  • Vulnerability

High-Severity Vulnerabilities in Bruno API Client Expose Users to Potential RCE

Do Son April 3, 2025 0
Read More Read more about High-Severity Vulnerabilities in Bruno API Client Expose Users to Potential RCE
The Rise of Quishing: QR Codes as a Gateway to Phishing Attacks QR-Code-Phishing
  • Cyber Security

The Rise of Quishing: QR Codes as a Gateway to Phishing Attacks

Do Son April 3, 2025 0
Read More Read more about The Rise of Quishing: QR Codes as a Gateway to Phishing Attacks
Qilin Ransomware Attack Exploits MSP Vulnerability to Target Downstream Customers sopho
  • Malware

Qilin Ransomware Attack Exploits MSP Vulnerability to Target Downstream Customers

Do Son April 3, 2025 0
Read More Read more about Qilin Ransomware Attack Exploits MSP Vulnerability to Target Downstream Customers
CVE-2025-0676: High-Severity Vulnerability Threatens Moxa Network Devices CVE-2025-0676
  • Vulnerability

CVE-2025-0676: High-Severity Vulnerability Threatens Moxa Network Devices

Do Son April 2, 2025 0
Read More Read more about CVE-2025-0676: High-Severity Vulnerability Threatens Moxa Network Devices
Mozilla Monetizes Thunderbird: Thundermail and Pro Features Launch Thundermail Thunderbird Pro
  • Technology

Mozilla Monetizes Thunderbird: Thundermail and Pro Features Launch

Do Son April 2, 2025 0
Read More Read more about Mozilla Monetizes Thunderbird: Thundermail and Pro Features Launch
No Consent, No Choice: Microsoft Copilot’s Surprise Windows 11 LTSC Arrival Windows 11 26H1, Copilot+ PC AI content, monetization AI Code Review, Microsoft Engineering Microsoft Copilot Studio Uninstall Copilot AI Windows 11 LTSC
  • Windows

No Consent, No Choice: Microsoft Copilot’s Surprise Windows 11 LTSC Arrival

Do Son April 2, 2025 0
Read More Read more about No Consent, No Choice: Microsoft Copilot’s Surprise Windows 11 LTSC Arrival
Nova Act Unveiled: Amazon’s AI Web Assistant Arrives Amazon Nova Act
  • Technology

Nova Act Unveiled: Amazon’s AI Web Assistant Arrives

Do Son April 2, 2025 0
Read More Read more about Nova Act Unveiled: Amazon’s AI Web Assistant Arrives
€150M Fine: Apple’s Ad Dominance Under French Scrutiny Apple Spring Event 2026 Apple Intel 14A iPhone 2028, Intel Foundry Apple Silicon iPhone 18 glass cloth shortage, Nittobo T-glass Apple crisis Apple UK App Store lawsuit appeal, Apple tax £1.5bn damages Apple AI Leadership Shakeup Giannandrea Subramanya Touchscreen MacBook Pro Apple 2026 Roadmap Apple Smart Home, Desktop Robot Apple H3 Chip, AirPods Camera Apple chips, on-device AI Apple AI, retail chatbot MacBook, Affordable Foldable iPhone, Apple Strategy Apple COO, Leadership Transition DOJ Lawsuit Apple EU Policy, App Store Fees CVE-2024-23222 Apple French antitrust fine
  • Technology

€150M Fine: Apple’s Ad Dominance Under French Scrutiny

Do Son April 2, 2025 0
Read More Read more about €150M Fine: Apple’s Ad Dominance Under French Scrutiny
CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS CVE-2025-24813 exploit
  • Vulnerability

CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS

Do Son April 2, 2025 0
Read More Read more about CISA Flags Apache Tomcat CVE-2025-24813 as Actively Exploited with 9.8 CVSS
Chrome 135: 14 Security Fixes, High-Severity CVE-2025-3066 Flaw Patched Chrome 135 CVE-2025-3066
  • Vulnerability

Chrome 135: 14 Security Fixes, High-Severity CVE-2025-3066 Flaw Patched

Do Son April 2, 2025 0
Read More Read more about Chrome 135: 14 Security Fixes, High-Severity CVE-2025-3066 Flaw Patched
VyOS and Debian Systems Vulnerable to Man-in-the-Middle Attacks (CVE-2025-30095) CVE-2025-30095
  • Vulnerability

VyOS and Debian Systems Vulnerable to Man-in-the-Middle Attacks (CVE-2025-30095)

Do Son April 2, 2025 0
Read More Read more about VyOS and Debian Systems Vulnerable to Man-in-the-Middle Attacks (CVE-2025-30095)
MongoDB Patches: DoS & Bypass Risks Addressed MongoDB Server vulnerability use-after-free vulnerability, CVE-2026-11933, CVE-2026-9740, CVE-2026-9750 MongoDB DoS, Pre-Authentication Vulnerability CVE-2024-7553 - MongoDB Server CVE-2025-3083, CVE-2025-3084, and CVE-2025-3085
  • Vulnerability

MongoDB Patches: DoS & Bypass Risks Addressed

Do Son April 2, 2025 0
Read More Read more about MongoDB Patches: DoS & Bypass Risks Addressed
CVE-2025-30223 (CVSS 9.3): Critical XSS Vulnerability Discovered in Beego Framework CVE-2025-30223
  • Vulnerability

CVE-2025-30223 (CVSS 9.3): Critical XSS Vulnerability Discovered in Beego Framework

Do Son April 2, 2025 0
Read More Read more about CVE-2025-30223 (CVSS 9.3): Critical XSS Vulnerability Discovered in Beego Framework
Gootloader Returns with Fake Legal Document Lure via Google Ads Everon OCPP Vulnerability CVE-2026-26288 ASUSTOR ADM Vulnerability CVE-2026-24936 PrismX MX100 Vulnerability Hard-Coded Credentials Advantech Vulnerability CVE-2025-52694 Eaton UPS Companion, CVE-2025-59887 ASUS Router, Authentication Bypass ASUSTOR DLL Hijacking, Privilege Escalation OpenShift AI, Privilege Escalation GoAnywhere vulnerability CVE-2025-10035 LangChainGo, template injection DeepDiff, class pollution ToolShell Sunshine, CSRF Vulnerability KACE SMA, Critical Vulnerabilities Oracle Zero-Days - PDQ Deploy vulnerability
  • Malware

Gootloader Returns with Fake Legal Document Lure via Google Ads

Do Son April 2, 2025 0
Read More Read more about Gootloader Returns with Fake Legal Document Lure via Google Ads
HijackLoader Evolves: New Modules Bring Stealth, Persistence, and Advanced VM Evasion HijackLoader Evasion Tactics
  • Malware

HijackLoader Evolves: New Modules Bring Stealth, Persistence, and Advanced VM Evasion

Do Son April 2, 2025 0
Read More Read more about HijackLoader Evolves: New Modules Bring Stealth, Persistence, and Advanced VM Evasion
8 Zero-Day Vulnerabilities Uncovered in Netgear WNR854T Router Netgear WNR854T vulnerability Vulnerabilities
  • Vulnerability

8 Zero-Day Vulnerabilities Uncovered in Netgear WNR854T Router

Do Son April 2, 2025 0
Read More Read more about 8 Zero-Day Vulnerabilities Uncovered in Netgear WNR854T Router
PostgreSQL Servers Hacked: 1,500+ Cloud Systems Mining Crypto via CPU_HU Exploit Jupyter Notebooks
  • Malware

PostgreSQL Servers Hacked: 1,500+ Cloud Systems Mining Crypto via CPU_HU

Do Son April 2, 2025 0
Read More Read more about PostgreSQL Servers Hacked: 1,500+ Cloud Systems Mining Crypto via CPU_HU
CVE-2025-30065 (CVSS 10): Critical Vulnerability Discovered in Apache Parquet Java CVE-2025-30065 Apache Parquet, CVE-2025-46762
  • Vulnerability

CVE-2025-30065 (CVSS 10): Critical Vulnerability Discovered in Apache Parquet Java

Do Son April 2, 2025 0
Read More Read more about CVE-2025-30065 (CVSS 10): Critical Vulnerability Discovered in Apache Parquet Java
SmokeLoader Malware Deployed in Stealthy Campaign Targeting Major Banks SmokeLoader campaign
  • Malware

SmokeLoader Malware Deployed in Stealthy Campaign Targeting Major Banks

Do Son April 2, 2025 0
Read More Read more about SmokeLoader Malware Deployed in Stealthy Campaign Targeting Major Banks
Critical Vulnerabilities Threaten IBM App Connect Enterprise IBM API Connect, CVE-2025-13915 IBM Privilege Escalation, CVE-2025-36356 IBM Power Systems - CVE-2024-45656 CVE-2024-49814 and CVE-2024-51450 CVE-2024-56346 and CVE-2024-56347 CVE-2025-1302
  • Vulnerability

Critical Vulnerabilities Threaten IBM App Connect Enterprise

Do Son April 2, 2025 0
Read More Read more about Critical Vulnerabilities Threaten IBM App Connect Enterprise
Google Patches ImageRunner: Fixing Critical Cloud Run Container Access Flaw Railway app Google Cloud suspension Google Cloud CDN Interconnect pricing 2026, GCP data transfer cost increase Google Cloud Disrupted ImageRunner Alphabet earnings, Google AI
  • Vulnerability

Google Patches ImageRunner: Fixing Critical Cloud Run Container Access Flaw

Do Son April 1, 2025 0
Read More Read more about Google Patches ImageRunner: Fixing Critical Cloud Run Container Access Flaw
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intel📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-103355CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105135CVSS 10.0
    A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105134CVSS 10.0
    A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the...
    📅 Updated: Oct 4, 2026
  • CVE-2026-97637CVSS 9.8
    The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in...
    📅 Updated: Oct 3, 2026
  • CVE-2026-92084CVSS 9.1
    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to...
    📅 Updated: Oct 3, 2026
  • CVE-2026-87115CVSS 9.1
    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...
    📅 Updated: Oct 3, 2026
  • CVE-2026-14378CVSS 9.8
    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all...
    📅 Updated: Oct 3, 2026
  • CVE-2026-19660CVSS 9.8
    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
    📅 Updated: Oct 3, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.