Skip to content
June 27, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cyber Security

STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users

Do Son January 23, 2025 0
Read More Read more about STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users
CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users SonicWall Security Advisory SonicOS Patch 2026 CVE-2025-23006 SonicWall, SMA 100 Vulnerabilities
  • Vulnerability

CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users

Do Son January 23, 2025 0
Read More Read more about CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users
CVE-2025-0314: GitLab Releases Patch for XSS Exploit GitLab AI Gateway Vulnerability CVE-2026-1868 CVE-2025-0314 GitLab Security Update CVE-2025-9222
  • Vulnerability

CVE-2025-0314: GitLab Releases Patch for XSS Exploit

Do Son January 23, 2025 0
Read More Read more about CVE-2025-0314: GitLab Releases Patch for XSS Exploit
CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory OCRFix Botnet EtherHiding CrowdStrike supply chain attack Ivanti CSA Vulnerabilities
  • Vulnerability

CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory

Do Son January 22, 2025 0
Read More Read more about CISA and FBI Warn of Exploited Ivanti CSA Vulnerabilities in Joint Security Advisory
CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation CVE-2025-20156
  • Vulnerability

CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation

Do Son January 22, 2025 0
Read More Read more about CVE-2025-20156 (CVSS 9.9): Cisco Meeting Management Flaw Allows for Privilege Escalation
Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS

Do Son January 22, 2025 0
Read More Read more about Purrglar: Emerging Stealer Targets Chrome and Exodus Wallet Data on macOS
Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed deanonymization attack - cache geolocation attack
  • Data Leak
  • Vulnerability

Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed

Do Son January 22, 2025 0
Read More Read more about Signal and Discord Vulnerabilities Exposed: 0-Click Deanonymization Attack Revealed
ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware ApateWeb operation
  • Cyber Security

ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware

Do Son January 22, 2025 0
Read More Read more about ApateWeb Campaign Hijacks Blogspot, Spreads Phishing and Malware
Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk mercedes-benz-2692776_1280
  • Vulnerability

Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk

Do Son January 22, 2025 0
Read More Read more about Mercedes-Benz MBUX Vulnerabilities: User Data and Safety at Risk
New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments Azure Bruteforce Campaign
  • Cyber Security

New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments

Do Son January 22, 2025 0
Read More Read more about New Bruteforce Campaign Exploits fasthttp Library to Target Azure Environments
Proof-of-Concept Found for ClamAV DoS Flaw: CVE-2025-20128 New_ClamAV_Logo.svg
  • Vulnerability

Proof-of-Concept Found for ClamAV DoS Flaw: CVE-2025-20128

Do Son January 22, 2025 0
Read More Read more about Proof-of-Concept Found for ClamAV DoS Flaw: CVE-2025-20128
GamaCopy: A New Cyber Espionage Group Imitating Gamaredon to Target Russia Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security

GamaCopy: A New Cyber Espionage Group Imitating Gamaredon to Target Russia

Do Son January 22, 2025 0
Read More Read more about GamaCopy: A New Cyber Espionage Group Imitating Gamaredon to Target Russia
Security Update for Chrome: Protect Against CVE-2025-0611 and CVE-2025-0612 CVE-2025-0611 and CVE-2025-0612
  • Vulnerability

Security Update for Chrome: Protect Against CVE-2025-0611 and CVE-2025-0612

Do Son January 22, 2025 0
Read More Read more about Security Update for Chrome: Protect Against CVE-2025-0611 and CVE-2025-0612
Operation (Giỗ Tổ Hùng Vương) Hurricane: New OceanLotus Group Revealed in Espionage Campaigns CVE-2024-36072 Water Gamayun, MSC EvilTwin
  • Cyber Security

Operation (Giỗ Tổ Hùng Vương) Hurricane: New OceanLotus Group Revealed in Espionage Campaigns

Do Son January 22, 2025 0
Read More Read more about Operation (Giỗ Tổ Hùng Vương) Hurricane: New OceanLotus Group Revealed in Espionage Campaigns
Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign BlueNoroff macOS Attack GhostCall Campaign Carding Underground Bulletproof Hosting DPRK Contagious Interview, npm Flood Stonefly group -HiatusRAT Actors
  • Cyber Security

Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign

Do Son January 22, 2025 0
Read More Read more about Cybercriminals Exploit AnyDesk to Impersonate CERT-UA in Sophisticated Phishing Campaign
Breaking News: Introducing the Stargate Project – OpenAI’s Transformative AI Infrastructure Yoshua Bengio AI sycophancy, reverse deception AI feedback AI chatbots, FTC investigation AI-generated content Trump AI Policy, AI Deregulation Military AI, DoD Funding Stargate Project AI Art Restoration
  • Technology

Breaking News: Introducing the Stargate Project – OpenAI’s Transformative AI Infrastructure

Do Son January 22, 2025 0
Read More Read more about Breaking News: Introducing the Stargate Project – OpenAI’s Transformative AI Infrastructure
Mirai Botnet Unleashes Record-Breaking DDoS Attack, Cloudflare Thwarts Threat MadeYouReset, HTTP/2 vulnerability FSF, AI Scraping Attacks OracleIV botnet
  • Cyber Security

Mirai Botnet Unleashes Record-Breaking DDoS Attack, Cloudflare Thwarts Threat

Do Son January 22, 2025 0
Read More Read more about Mirai Botnet Unleashes Record-Breaking DDoS Attack, Cloudflare Thwarts Threat
ASUS and AdGuard Team Up to Deliver Ad-Free Wi-Fi 7 Experience AdGuard DNS
  • Technology

ASUS and AdGuard Team Up to Deliver Ad-Free Wi-Fi 7 Experience

Do Son January 22, 2025 0
Read More Read more about ASUS and AdGuard Team Up to Deliver Ad-Free Wi-Fi 7 Experience
CVE-2024-12857: Critical Flaw in AdForest Theme Allows Complete Account Takeover, Thousands of Sites at Risk CVE-2024-12857
  • Vulnerability

CVE-2024-12857: Critical Flaw in AdForest Theme Allows Complete Account Takeover, Thousands of Sites at Risk

Do Son January 21, 2025 0
Read More Read more about CVE-2024-12857: Critical Flaw in AdForest Theme Allows Complete Account Takeover, Thousands of Sites at Risk
CVE-2025-23083: Node.js Vulnerability Exposes Sensitive Data and Resources CVE-2025-23083 - Node.js EOL
  • Vulnerability

CVE-2025-23083: Node.js Vulnerability Exposes Sensitive Data and Resources

Do Son January 21, 2025 0
Read More Read more about CVE-2025-23083: Node.js Vulnerability Exposes Sensitive Data and Resources
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-42208
    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version...
  • CVE-2018-1273CVSS 9.8
    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a...
  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-12569
    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The...
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
  • CVE-2026-21509CVSS 7.8
    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a...
  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-12415CVSS 9.8
    The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due...
  • CVE-2026-28701CVSS 9.8
    Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote...
  • CVE-2026-53576CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-49869CVSS 10.0
    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21,...
  • CVE-2026-54350CVSS 10.0
    Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor...
  • CVE-2026-54352CVSS 9.6
    Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at...
  • CVE-2026-52785CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52782CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-52780CVSS 9.6
    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1,...
  • CVE-2026-46386CVSS 9.9
    OpenProject is open-source, web-based project management software. Prior to , the official...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.