Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Steganographic Campaign Distributes Multiple Malware Variants, Including Remcos and AsyncRAT Steganographic Campaign
  • Malware

Steganographic Campaign Distributes Multiple Malware Variants, Including Remcos and AsyncRAT

Do Son March 19, 2025 0
Read More Read more about Steganographic Campaign Distributes Multiple Malware Variants, Including Remcos and AsyncRAT
Web3 Laundering Fears: OKX Suspends Platform Amidst Scrutiny OKX Suspends Fined US market
  • Cyber Security

Web3 Laundering Fears: OKX Suspends Platform Amidst Scrutiny

Do Son March 19, 2025 0
Read More Read more about Web3 Laundering Fears: OKX Suspends Platform Amidst Scrutiny
Google Chrome Patches Critical ‘Use-After-Free’ Vulnerability in Lens (CVE-2025-2476) Amazon Ads Blocker Affiliate Link Hijacking Malicious browser extensions
  • Vulnerability

Google Chrome Patches Critical ‘Use-After-Free’ Vulnerability in Lens (CVE-2025-2476)

Do Son March 19, 2025 0
Read More Read more about Google Chrome Patches Critical ‘Use-After-Free’ Vulnerability in Lens (CVE-2025-2476)
SecPod launches Saner Cloud: A Revolutionary CNAPP For Preventive Cybersecurity DSC07167_1_17423842189imlMarwRN
  • Press Release

SecPod launches Saner Cloud: A Revolutionary CNAPP For Preventive Cybersecurity

cybernewswire March 19, 2025 0
Read More Read more about SecPod launches Saner Cloud: A Revolutionary CNAPP For Preventive Cybersecurity
SpyCloud’s 2025 Identity Exposure Report Reveals the Scale and Hidden Risks of Digital Identity Threats SpyCloud_wordmark_square_1741882258myhoT5FO0l
  • Press Release

SpyCloud’s 2025 Identity Exposure Report Reveals the Scale and Hidden Risks of Digital Identity Threats

cybernewswire March 19, 2025 0
Read More Read more about SpyCloud’s 2025 Identity Exposure Report Reveals the Scale and Hidden Risks of Digital Identity Threats
CVE-2024-11131 (CVSS 9.8): Critical Vulnerability Found in Synology Camera Firmware Synology Chat Server vulnerabilities Synology security update Synology DSM Update NAS Security Vulnerability Synology VPN Update SSL VPN Vulnerability Synology Telnet Flaw DSM Security Update Synology DSM Telnet vulnerability BeeStation Zero-Day, Pwn2Own RCE CVE-2024-11131 & CVE-2024-10442 CVE-2025-2848 Synology, NAS
  • Vulnerability

CVE-2024-11131 (CVSS 9.8): Critical Vulnerability Found in Synology Camera Firmware

Do Son March 19, 2025 0
Read More Read more about CVE-2024-11131 (CVSS 9.8): Critical Vulnerability Found in Synology Camera Firmware
CVE-2025-0755: MongoDB C Driver Vulnerability Could Lead to Buffer Overflow MongoDB Vulnerability CVE-2026-25611 MongoDB zlib vulnerability, CVE-2025-14847 MongoDB Vulnerabilities, Data Access CVE-2024-6376 CVE-2025-0755
  • Vulnerability

CVE-2025-0755: MongoDB C Driver Vulnerability Could Lead to Buffer Overflow

Do Son March 19, 2025 0
Read More Read more about CVE-2025-0755: MongoDB C Driver Vulnerability Could Lead to Buffer Overflow
CERT-UA Alert: DarkCrystal RAT Deployed via Signal in Ukraine DarkCrystal RAT
  • Malware

CERT-UA Alert: DarkCrystal RAT Deployed via Signal in Ukraine

Do Son March 19, 2025 0
Read More Read more about CERT-UA Alert: DarkCrystal RAT Deployed via Signal in Ukraine
CVE-2024-10441 (CVSS 9.8): Synology Patches Critical Code Execution Flaw in Multiple Products shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability

CVE-2024-10441 (CVSS 9.8): Synology Patches Critical Code Execution Flaw in Multiple Products

Do Son March 18, 2025 0
Read More Read more about CVE-2024-10441 (CVSS 9.8): Synology Patches Critical Code Execution Flaw in Multiple Products
End of Windows 10: Microsoft Warns Users, Update or Pay KB5083769 Update Windows 11 24H2 end of support File Explorer White Flash Windows 11 Dark Mode Bug Windows 11 SE, End of Support Windows Update, Automatic Upgrade CVE-2023-38146 Windows 10
  • Technology
  • Windows

End of Windows 10: Microsoft Warns Users, Update or Pay

Do Son March 18, 2025 0
Read More Read more about End of Windows 10: Microsoft Warns Users, Update or Pay
Hidden Threat: Zero-Day Windows Shortcut Exploited by Global APT Networks Cisco SD-WAN Vulnerability CVE-2026-20133 FortiGate Compromise Ivanti EPMM Zero-Day CVE-2026-1281 SmarterMail Vulnerability Storm-2603 WatchGuard Zero-Day, IKEv2 Out-of-Bounds Write Cisco Zero-Day, UAT-9686 Chinese APT FortiWeb RCE Exploitation CVE-2025-58034 VMware Zero-Day, Privilege Escalation Sitecore, remote code execution CVE-2025-53690 Windows CLFS, Privilege Escalation CVE-2024-47575 & CVE-2024-11120 CVE-2025-24983 vulnerability
  • Vulnerability

Hidden Threat: Zero-Day Windows Shortcut Exploited by Global APT Networks

Do Son March 18, 2025 0
Read More Read more about Hidden Threat: Zero-Day Windows Shortcut Exploited by Global APT Networks
Million-Download Node.js Library xml-crypto Hit by Critical Security Flaws (CVE-2025-29774, CVE-2025-29775) CVE-2025-29774, CVE-2025-29775
  • Vulnerability

Million-Download Node.js Library xml-crypto Hit by Critical Security Flaws (CVE-2025-29774, CVE-2025-29775)

Do Son March 18, 2025 0
Read More Read more about Million-Download Node.js Library xml-crypto Hit by Critical Security Flaws (CVE-2025-29774, CVE-2025-29775)
Cybersecurity Alert: CISA Adds Fortinet and GitHub Action Vulnerabilities to Exploited List GitHub Action Vulnerabilities
  • Vulnerability

Cybersecurity Alert: CISA Adds Fortinet and GitHub Action Vulnerabilities to Exploited List

Do Son March 18, 2025 0
Read More Read more about Cybersecurity Alert: CISA Adds Fortinet and GitHub Action Vulnerabilities to Exploited List
FIN7’s New Stealth Weapon: AnubisBackdoor Emerges in the Wild DriverFixer0428, Contagious Interview Cache Smuggling, ClickFix Evasion North Korean Cyber Espionage
  • Malware

FIN7’s New Stealth Weapon: AnubisBackdoor Emerges in the Wild

Do Son March 18, 2025 0
Read More Read more about FIN7’s New Stealth Weapon: AnubisBackdoor Emerges in the Wild
CVE-2025-2000 (CVSS 9.8): Qiskit SDK Vulnerability Allows Arbitrary Code Execution CVE-2025-2000
  • Vulnerability

CVE-2025-2000 (CVSS 9.8): Qiskit SDK Vulnerability Allows Arbitrary Code Execution

Do Son March 18, 2025 0
Read More Read more about CVE-2025-2000 (CVSS 9.8): Qiskit SDK Vulnerability Allows Arbitrary Code Execution
Unusual Malware Samples Discovered, Including C++/CLI IIS Backdoor C++/CLI IIS Backdoor
  • Malware

Unusual Malware Samples Discovered, Including C++/CLI IIS Backdoor

Do Son March 18, 2025 0
Read More Read more about Unusual Malware Samples Discovered, Including C++/CLI IIS Backdoor
Critical Vulnerabilities Found in Sungrow iSolarCloud App and WiNet Firmware Critical Vulnerabilities Found in Sungrow iSolarCloud App and WiNet Firmware
  • Vulnerability

Critical Vulnerabilities Found in Sungrow iSolarCloud App and WiNet Firmware

Do Son March 18, 2025 0
Read More Read more about Critical Vulnerabilities Found in Sungrow iSolarCloud App and WiNet Firmware
INDOHAXSEC: Emerging Indonesian Hacktivist Collective Targets Southeast Asia INDOHAXSEC Hacktivist
  • Cyber Security

INDOHAXSEC: Emerging Indonesian Hacktivist Collective Targets Southeast Asia

Do Son March 18, 2025 0
Read More Read more about INDOHAXSEC: Emerging Indonesian Hacktivist Collective Targets Southeast Asia
CVE-2025-2263 (CVSS 9.8): Stack Overflow Flaw Threatens Patient Data in PACS Systems, PoC Published CVE-2025-2263 Orthanc Security DICOM Vulnerabilities
  • Vulnerability

CVE-2025-2263 (CVSS 9.8): Stack Overflow Flaw Threatens Patient Data in PACS Systems, PoC Published

Do Son March 18, 2025 0
Read More Read more about CVE-2025-2263 (CVSS 9.8): Stack Overflow Flaw Threatens Patient Data in PACS Systems, PoC Published
Google’s Android Terminal: More Linux Apps, Not a Linux Desktop Android 16 adoption rate Android 16KB Page, .NET MAUI 9 Android Security, Fast Charging Android Canary, Developer Program Android Updates, EU Regulation Android 16 Google Android Terminal Cloud Compilation Android, Google I/O
  • Android
  • Technology

Google’s Android Terminal: More Linux Apps, Not a Linux Desktop

Do Son March 18, 2025 0
Read More Read more about Google’s Android Terminal: More Linux Apps, Not a Linux Desktop
Critical Flaws Expose SICK DL100 Devices to Code Execution and Password Hacks CVE-2024-10025 CVE-2025-27593 & CVE-2025-27595
  • Vulnerability

Critical Flaws Expose SICK DL100 Devices to Code Execution and Password Hacks

Do Son March 18, 2025 0
Read More Read more about Critical Flaws Expose SICK DL100 Devices to Code Execution and Password Hacks
Fans-CRM: Best Creator Tool for OnlyFans VPN & Content Management 1
  • Technique

Fans-CRM: Best Creator Tool for OnlyFans VPN & Content Management

Do Son March 18, 2025 0
Read More Read more about Fans-CRM: Best Creator Tool for OnlyFans VPN & Content Management
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105221CVSS 9.1
    The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105222CVSS 9.1
    The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105218CVSS 9.1
    gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105216CVSS 9.1
    go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105086CVSS 9.3
    WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105089CVSS 9.3
    WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject...
    📅 Updated: Oct 4, 2026
  • CVE-2026-82042CVSS 9.3
    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105215CVSS 9.3
    ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because...
    📅 Updated: Oct 4, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.