Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Tomcat Flaw CVE-2025-24813 Exploited in the Wild, PoC Released CVE-2025-24813 PoC
  • Vulnerability

Tomcat Flaw CVE-2025-24813 Exploited in the Wild, PoC Released

Do Son March 16, 2025 0
Read More Read more about Tomcat Flaw CVE-2025-24813 Exploited in the Wild, PoC Released
Laravel Framework Vulnerable to Reflected XSS Attacks (CVE-2024-13918 & CVE-2024-13919) Laravel CRLF injection vulnerability CVE-2026-48019 patch CVE-2024-13918 and CVE-2024-13919
  • Vulnerability

Laravel Framework Vulnerable to Reflected XSS Attacks (CVE-2024-13918 & CVE-2024-13919)

Do Son March 16, 2025 0
Read More Read more about Laravel Framework Vulnerable to Reflected XSS Attacks (CVE-2024-13918 & CVE-2024-13919)
CVE-2024-57040 (CVSS 9.8): TP-Link TL-WR845N Router Vulnerability Grants Hackers Easy Access Archer MR600 command injection WireGuard client configuration Tapo smart device vulnerability unencrypted Bluetooth transmission TP-Link router vulnerability CVE-2026-5509 patch Archer AX53 Vulnerability TP-Link Router Security Tapo C520WS Vulnerability TP-Link Security Patch TP-Link Archer NX Router Vulnerability TP-Link Archer Vulnerability CVE-2025-15568 TP-Link Archer BE230 Vulnerability Command Injection TP-Link Omada Vulnerability CVE-2025-9520 TP-Link Archer MR600 Vulnerability CVE-2025-14756 CVE-2026-0629 TP-Link Omada RCE, CVE-2025-6542 TP-Link, Smart plug vulnerability TP-Link Archer C50, Hardcoded DES Key TP-Link NVR, Command Injection TP-Link Routers cybersecurity
  • Vulnerability

CVE-2024-57040 (CVSS 9.8): TP-Link TL-WR845N Router Vulnerability Grants Hackers Easy Access

Do Son March 16, 2025 0
Read More Read more about CVE-2024-57040 (CVSS 9.8): TP-Link TL-WR845N Router Vulnerability Grants Hackers Easy Access
Cryptominers Exploit Exposed Jupyter Notebooks in Novel Campaign Exploit Jupyter Notebooks
  • Malware

Cryptominers Exploit Exposed Jupyter Notebooks in Novel Campaign

Do Son March 16, 2025 0
Read More Read more about Cryptominers Exploit Exposed Jupyter Notebooks in Novel Campaign
CVE-2025-22954 (CVSS 10): Koha Library Systems at High Risk, Patch Immediately CVE-2025-22954
  • Vulnerability

CVE-2025-22954 (CVSS 10): Koha Library Systems at High Risk, Patch Immediately

Do Son March 16, 2025 0
Read More Read more about CVE-2025-22954 (CVSS 10): Koha Library Systems at High Risk, Patch Immediately
CVE-2025-27407 (CVSS 9.1): Critical GraphQL-Ruby Flaw Exposes Millions to RCE CVE-2025-27407
  • Vulnerability

CVE-2025-27407 (CVSS 9.1): Critical GraphQL-Ruby Flaw Exposes Millions to RCE

Do Son March 16, 2025 0
Read More Read more about CVE-2025-27407 (CVSS 9.1): Critical GraphQL-Ruby Flaw Exposes Millions to RCE
CVE-2025-1960 (CVSS 9.8): Schneider Electric Addresses Critical Flaw in WebHMI Component CVE-2024-10575 CVE-2025-1960 Schneider Electric Vulnerability CVE-2026-0667
  • Vulnerability

CVE-2025-1960 (CVSS 9.8): Schneider Electric Addresses Critical Flaw in WebHMI Component

Do Son March 16, 2025 0
Read More Read more about CVE-2025-1960 (CVSS 9.8): Schneider Electric Addresses Critical Flaw in WebHMI Component
AWS SNS Abused for Data Exfiltration and Phishing, Elastic Report Reveals AWS SNS Abused
  • Cyber Security

AWS SNS Abused for Data Exfiltration and Phishing, Elastic Report Reveals

Do Son March 16, 2025 0
Read More Read more about AWS SNS Abused for Data Exfiltration and Phishing, Elastic Report Reveals
Xbox AI Boost: Copilot for Gaming, Play Anywhere Hits 1,000 Game Copilot for Gaming
  • Technology

Xbox AI Boost: Copilot for Gaming, Play Anywhere Hits 1,000 Game

Do Son March 16, 2025 0
Read More Read more about Xbox AI Boost: Copilot for Gaming, Play Anywhere Hits 1,000 Game
Windows 11: AI Summaries in Notepad, Snipping Tool Enhanced Windows 11 Snipping Tool
  • Windows

Windows 11: AI Summaries in Notepad, Snipping Tool Enhanced

Do Son March 16, 2025 0
Read More Read more about Windows 11: AI Summaries in Notepad, Snipping Tool Enhanced
Microsoft Edge for Android: Extension Support Finally Arrives Edge Extensions for Android
  • Android
  • Technology

Microsoft Edge for Android: Extension Support Finally Arrives

Do Son March 16, 2025 0
Read More Read more about Microsoft Edge for Android: Extension Support Finally Arrives
Google Antitrust: Mozilla Warns of Browser Choice Collapse Anthony Enzor-DeMeo Mozilla CEO, Firefox AI Mode 2026 Ad blockers, Copyright Law Firefox China, Mozilla Restructuring Mozilla Add-ons, Policy Update Mozilla leadership - Mozilla collect data Google Antitrust Antitrust Trial
  • Technology

Google Antitrust: Mozilla Warns of Browser Choice Collapse

Do Son March 16, 2025 0
Read More Read more about Google Antitrust: Mozilla Warns of Browser Choice Collapse
Android Revolution: Gemini Replaces Assistant on All Devices Gemini Code Assist Android free electrician training, AI energy demand
  • Android
  • Technology

Android Revolution: Gemini Replaces Assistant on All Devices

Do Son March 16, 2025 0
Read More Read more about Android Revolution: Gemini Replaces Assistant on All Devices
OctoV2 Android Banking Trojan Masquerades as Deepseek AI in Phishing Attack Deep
  • Malware

OctoV2 Android Banking Trojan Masquerades as Deepseek AI in Phishing Attack

Do Son March 16, 2025 0
Read More Read more about OctoV2 Android Banking Trojan Masquerades as Deepseek AI in Phishing Attack
Credit Card Skimmer and Backdoor Found Lurking on WordPress E-commerce Site WordPress Backdoor
  • Malware

Credit Card Skimmer and Backdoor Found Lurking on WordPress E-commerce Site

Do Son March 16, 2025 0
Read More Read more about Credit Card Skimmer and Backdoor Found Lurking on WordPress E-commerce Site
SteamOS Arrives: The Handheld Gaming Revolution Steam 64-bit Windows transition, Steam 32-bit end of life January 2026 SteamOS Steam Windows 10 32-bit
  • Linux
  • Technology

SteamOS Arrives: The Handheld Gaming Revolution

Do Son March 15, 2025 0
Read More Read more about SteamOS Arrives: The Handheld Gaming Revolution
Samsung Soundbar Bricked: Disable Updates Now! Samsung MagicInfo9 Vulnerability CVE-2026-25202 Galaxy S26 benchmarks Samsung HBM4 NVIDIA certification Samsung Bixby Perplexity integration, One UI 8.5 AI assistant Samsung Taylor 2nm mass production, TSMC 2nm capacity constraint 2026 Samsung SATA SSD Discontinuation, SSD Market Shift Samsung SATA SSD Discontinuation, M.2 Market Shift Samsung Foundry 4nm Yield Tsavorite OPU Chip Order Samsung Project Moohan, Android XR Samsung OpenAI Partnership, AI Infrastructure Samsung Exynos 2600, 2nm GAA Tesla AI Chips, Samsung Foundry Deal Samsung Foldables, Galaxy Unpacked 2025 Samsung AI, Perplexity AI Samsung data breach Q990D firmware US tariffs
  • Technology

Samsung Soundbar Bricked: Disable Updates Now!

Do Son March 15, 2025 0
Read More Read more about Samsung Soundbar Bricked: Disable Updates Now!
Popular GitHub Action “tj-actions/changed-files” Compromised (CVE-2025-30066) GitHub Copilot Pro trial suspension GitHub Actions Platform Fee, Self-Hosted Runner Tax 2026 GitHub Apple ID, Privacy Login GitHub Microsoft Github disruptions CVE-2025-30066 GitHub Outage, Service Disruption
  • Vulnerability

Popular GitHub Action “tj-actions/changed-files” Compromised (CVE-2025-30066)

Do Son March 15, 2025 0
Read More Read more about Popular GitHub Action “tj-actions/changed-files” Compromised (CVE-2025-30066)
North Korean ScarCruft APT Targets Users with Novel KoSpy Android Spyware KoSpy Android spyware
  • Malware

North Korean ScarCruft APT Targets Users with Novel KoSpy Android Spyware

Do Son March 15, 2025 0
Read More Read more about North Korean ScarCruft APT Targets Users with Novel KoSpy Android Spyware
Booking.com Impersonated in Phishing Campaign Delivering Credential-Stealing Malware Booking Phishing Campaign
  • Malware

Booking.com Impersonated in Phishing Campaign Delivering Credential-Stealing Malware

Do Son March 15, 2025 0
Read More Read more about Booking.com Impersonated in Phishing Campaign Delivering Credential-Stealing Malware
Virginia Man Sentenced to 78 Months for Tax Evasion and $1.3M Trading Bot Scam FIFA website spoofing scams FBI World Cup alert Pig Butchering Scam Jingliang Su Sentencing Meta China Scam Ads, Zuckerberg Revenue Conflict Trading Bot Scam BEC Scam Rental Payment Fraud
  • Cyber Security

Virginia Man Sentenced to 78 Months for Tax Evasion and $1.3M Trading Bot Scam

Do Son March 14, 2025 0
Read More Read more about Virginia Man Sentenced to 78 Months for Tax Evasion and $1.3M Trading Bot Scam
Major LockBit Ransomware Developer Extradited to U.S. Lockbit ransomware disrupted LockBit Ransomware Developer
  • Cyber Security

Major LockBit Ransomware Developer Extradited to U.S.

Do Son March 14, 2025 0
Read More Read more about Major LockBit Ransomware Developer Extradited to U.S.
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105223CVSS 9.1
    maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data,...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105216CVSS 9.1
    go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105222CVSS 9.1
    The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105294CVSS 9.1
    Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105293CVSS 9.2
    Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105221CVSS 9.1
    The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105218CVSS 9.1
    gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105086CVSS 9.3
    WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML...
    📅 Updated: Oct 4, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.