Skip to content
June 28, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
Subaru’s STARLINK Vulnerability: How Hackers Could Track and Control Vehicles Subaru STARLINK Vulnerability
  • Vulnerability

Subaru’s STARLINK Vulnerability: How Hackers Could Track and Control Vehicles

Do Son January 26, 2025 0
Read More Read more about Subaru’s STARLINK Vulnerability: How Hackers Could Track and Control Vehicles
CVE-2024-50050: Critical Security Flaw in Meta’s Llama-Stack Framework PoC-exploit
  • Vulnerability

CVE-2024-50050: Critical Security Flaw in Meta’s Llama-Stack Framework

Do Son January 25, 2025 0
Read More Read more about CVE-2024-50050: Critical Security Flaw in Meta’s Llama-Stack Framework
HellCat and Morpheus: Ransomware Affiliates Using Identical Payloads to Escalate Attacks HellCat & Morpheus ransomware
  • Malware

HellCat and Morpheus: Ransomware Affiliates Using Identical Payloads to Escalate Attacks

Do Son January 25, 2025 0
Read More Read more about HellCat and Morpheus: Ransomware Affiliates Using Identical Payloads to Escalate Attacks
Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks CVE-2024-53299
  • Vulnerability

Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks

Do Son January 25, 2025 0
Read More Read more about Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks
QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution backConnect malware
  • Malware

QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution

Do Son January 25, 2025 0
Read More Read more about QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution
North Korean IT Workers Indicted in Elaborate “Laptop Farm” Scheme to Evade Sanctions North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security

North Korean IT Workers Indicted in Elaborate “Laptop Farm” Scheme to Evade Sanctions

Do Son January 24, 2025 0
Read More Read more about North Korean IT Workers Indicted in Elaborate “Laptop Farm” Scheme to Evade Sanctions
Lumma Stealer Malware Now Using ChaCha20 Cipher for Evasion ChaCha20 Cipher
  • Malware

Lumma Stealer Malware Now Using ChaCha20 Cipher for Evasion

Do Son January 24, 2025 0
Read More Read more about Lumma Stealer Malware Now Using ChaCha20 Cipher for Evasion
Popular WordPress Real Estate Theme Vulnerable to Complete Site Takeover, No Patch CVE-2024-32444 & CVE-2024-32555
  • Vulnerability

Popular WordPress Real Estate Theme Vulnerable to Complete Site Takeover, No Patch

Do Son January 24, 2025 0
Read More Read more about Popular WordPress Real Estate Theme Vulnerable to Complete Site Takeover, No Patch
Android Boosts Anti-Theft Measures with AI and Biometric Security Android security, anti-theft backup Android Identity Check & Theft Detection Lock
  • Android
  • Technology

Android Boosts Anti-Theft Measures with AI and Biometric Security

Do Son January 24, 2025 0
Read More Read more about Android Boosts Anti-Theft Measures with AI and Biometric Security
Social Media Marketing: Definition, Significance, and Strategic Insights email-4284157_1280
  • Technique

Social Media Marketing: Definition, Significance, and Strategic Insights

Do Son January 24, 2025 0
Read More Read more about Social Media Marketing: Definition, Significance, and Strategic Insights
CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code CVE-2024-43468 PoC exploit
  • Vulnerability

CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code

Do Son January 23, 2025 0
Read More Read more about CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution CVE-2025-21535 Oracle EBS RCE, CVE-2025-61882
  • Vulnerability

CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution

Do Son January 23, 2025 0
Read More Read more about CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies Malicious VS Code Extension
  • Malware

Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies

Do Son January 23, 2025 0
Read More Read more about Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies
CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information CVE-2024-43707 Kibana vulnerability Prototype pollution CVE-2025-25014
  • Vulnerability

CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information

Do Son January 23, 2025 0
Read More Read more about CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information
Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps Credential Harvesting
  • Cyber Security

Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps

Do Son January 23, 2025 0
Read More Read more about Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps
Donot APT Group Targets Android Devices with Malicious Chat Apps Donot APT Group - Android zero-day
  • Malware

Donot APT Group Targets Android Devices with Malicious Chat Apps

Do Son January 23, 2025 0
Read More Read more about Donot APT Group Targets Android Devices with Malicious Chat Apps
2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar Payment Fraud Report
  • Cyber Security

2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar

Do Son January 23, 2025 0
Read More Read more about 2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar
phpMyAdmin Patches XSS Vulnerabilities in Latest Release phpMyAdmin Vulnerabilities
  • Vulnerability

phpMyAdmin Patches XSS Vulnerabilities in Latest Release

Do Son January 23, 2025 0
Read More Read more about phpMyAdmin Patches XSS Vulnerabilities in Latest Release
CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Malware
  • Vulnerability

CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks

Do Son January 23, 2025 0
Read More Read more about CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks
Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Malware

Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi

Do Son January 23, 2025 0
Read More Read more about Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-42208
    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version...
  • CVE-2018-1273CVSS 9.8
    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-12569
    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The...
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
  • CVE-2026-21509CVSS 7.8
    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a...
  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12415CVSS 9.8
    The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due...
  • CVE-2026-28701CVSS 9.8
    Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote...
  • CVE-2026-53576CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-49869CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-54350CVSS 10.0
    Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor...
  • CVE-2026-54352CVSS 9.6
    Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at...
  • CVE-2026-52785CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52782CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52780CVSS 9.6
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-46386CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to , the official...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.