Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
GhostSocks Malware: A New Cyber Threat Leveraging SOCKS5 Backconnect for Evasion GhostSocks malware
  • Malware

GhostSocks Malware: A New Cyber Threat Leveraging SOCKS5 Backconnect for Evasion

Do Son February 23, 2025 0
Read More Read more about GhostSocks Malware: A New Cyber Threat Leveraging SOCKS5 Backconnect for Evasion
Apple Halts iCloud Advanced Data Protection in the UK After Government Demands Backdoor Access macOS Monterey vulnerability Apple Advanced Data Protection
  • Technology

Apple Halts iCloud Advanced Data Protection in the UK After Government Demands Backdoor Access

Do Son February 23, 2025 0
Read More Read more about Apple Halts iCloud Advanced Data Protection in the UK After Government Demands Backdoor Access
ChromeUpdate & DriverEasy: North Korea’s New macOS Cyber Espionage Tools North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Malware

ChromeUpdate & DriverEasy: North Korea’s New macOS Cyber Espionage Tools

Do Son February 23, 2025 0
Read More Read more about ChromeUpdate & DriverEasy: North Korea’s New macOS Cyber Espionage Tools
Moxa PT Switches Vulnerable to CVE-2024-9404 Denial-of-Service Attack Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability

Moxa PT Switches Vulnerable to CVE-2024-9404 Denial-of-Service Attack

Do Son February 23, 2025 0
Read More Read more about Moxa PT Switches Vulnerable to CVE-2024-9404 Denial-of-Service Attack
Russia-Linked Threat Actors Exploiting Signal Messenger to Eavesdrop on Sensitive Communications Signal Messenger threat
  • Cyber Security
  • Malware

Russia-Linked Threat Actors Exploiting Signal Messenger to Eavesdrop on Sensitive Communications

Do Son February 23, 2025 0
Read More Read more about Russia-Linked Threat Actors Exploiting Signal Messenger to Eavesdrop on Sensitive Communications
Exim Mail Transfer Agent Vulnerable to Remote SQL Injection (CVE-2025-26794), PoC Published CVE-2025-26794 Exim SQL Injection, Heap Buffer Overflow
  • Vulnerability

Exim Mail Transfer Agent Vulnerable to Remote SQL Injection (CVE-2025-26794), PoC Published

Do Son February 23, 2025 0
Read More Read more about Exim Mail Transfer Agent Vulnerable to Remote SQL Injection (CVE-2025-26794), PoC Published
CVE-2024-37361 (CVSS 9.9): Critical Vulnerability in Pentaho Business Analytics Server NTLM Vulnerabilities, CVE-2024-43451 CVE-2024-37361 - RESURGE Malware
  • Vulnerability

CVE-2024-37361 (CVSS 9.9): Critical Vulnerability in Pentaho Business Analytics Server

Do Son February 22, 2025 0
Read More Read more about CVE-2024-37361 (CVSS 9.9): Critical Vulnerability in Pentaho Business Analytics Server
LummaC2 Malware Masquerading as Total Commander Crack to Infect Windows Users LummaC2 Malware
  • Malware

LummaC2 Malware Masquerading as Total Commander Crack to Infect Windows Users

Do Son February 22, 2025 0
Read More Read more about LummaC2 Malware Masquerading as Total Commander Crack to Infect Windows Users
DDoS Attacks Surge During World Economic Forum (WEF) World Economic Forum DDoS attacks
  • Cyber Security

DDoS Attacks Surge During World Economic Forum (WEF)

Do Son February 22, 2025 0
Read More Read more about DDoS Attacks Surge During World Economic Forum (WEF)
CVE-2024-56000 (CVSS 9.8): Account Takeover Flaw in KLEO WordPress Theme CVE-2024-56000
  • Vulnerability

CVE-2024-56000 (CVSS 9.8): Account Takeover Flaw in KLEO WordPress Theme

Do Son February 21, 2025 0
Read More Read more about CVE-2024-56000 (CVSS 9.8): Account Takeover Flaw in KLEO WordPress Theme
Bloody Wolf Cybercrime Group Evolves Tactics, Expands Targets Phishing letter
  • Cyber Security

Bloody Wolf Cybercrime Group Evolves Tactics, Expands Targets

Do Son February 21, 2025 0
Read More Read more about Bloody Wolf Cybercrime Group Evolves Tactics, Expands Targets
Publicly Disclosed Exploits Put D-Link DIR-823 Users in Danger – No Security Fixes D-Link DIR-823 vulnerabiity
  • Vulnerability

Publicly Disclosed Exploits Put D-Link DIR-823 Users in Danger – No Security Fixes

Do Son February 21, 2025 0
Read More Read more about Publicly Disclosed Exploits Put D-Link DIR-823 Users in Danger – No Security Fixes
Europol Cracks Down on European Document Forgery and Smuggling Ring Criminal group
  • Cyber Security

Europol Cracks Down on European Document Forgery and Smuggling Ring

Do Son February 21, 2025 0
Read More Read more about Europol Cracks Down on European Document Forgery and Smuggling Ring
Apple’s Spyware Detection: Only 50% Effective? Pegasus spyware sample
  • Malware

Apple’s Spyware Detection: Only 50% Effective?

Do Son February 21, 2025 0
Read More Read more about Apple’s Spyware Detection: Only 50% Effective?
ChatGPT Hits 400 Million Weekly Users ChatGPT active user
  • Technology

ChatGPT Hits 400 Million Weekly Users

Do Son February 21, 2025 0
Read More Read more about ChatGPT Hits 400 Million Weekly Users
Apple C2 Modem: Next-Gen 5G in the Works? Apple C2 modem Apple Product Roadmap, iPhone 17
  • Technology

Apple C2 Modem: Next-Gen 5G in the Works?

Do Son February 21, 2025 0
Read More Read more about Apple C2 Modem: Next-Gen 5G in the Works?
Amazon Appstore on Android to Shut Down in 2025: What It Means for Users and Developers Amazon Appstore Android
  • Technology

Amazon Appstore on Android to Shut Down in 2025: What It Means for Users and Developers

Do Son February 20, 2025 0
Read More Read more about Amazon Appstore on Android to Shut Down in 2025: What It Means for Users and Developers
Google Releases PoC for CVE-2025-0110 Command Injection in PAN-OS Firewalls CVE-2024-5921 - CVE-2025-0103 CVE-2025-0110 PoC
  • Vulnerability

Google Releases PoC for CVE-2025-0110 Command Injection in PAN-OS Firewalls

Do Son February 20, 2025 0
Read More Read more about Google Releases PoC for CVE-2025-0110 Command Injection in PAN-OS Firewalls
CVE-2025-23115 & CVE-2025-23116: Hackers Can Hijack Ubiquiti UniFi Protect Cameras CVE-2025-23115 & CVE-2025-23116
  • Vulnerability

CVE-2025-23115 & CVE-2025-23116: Hackers Can Hijack Ubiquiti UniFi Protect Cameras

Do Son February 20, 2025 0
Read More Read more about CVE-2025-23115 & CVE-2025-23116: Hackers Can Hijack Ubiquiti UniFi Protect Cameras
CVE-2025-0111 & CVE-2025-23209: Palo Alto Firewalls and Craft CMS Under Active Attack Ivanti EPMM Vulnerability CVE-2026-1340 CISA KEV Catalog CVE-2026-21385 CISA KEV Update CVE-2008-0015 CISA KEV, Array Networks Command Injection CVE-2025-0111 & CVE-2025-23209 CISA, Known Exploited Vulnerabilities
  • Vulnerability

CVE-2025-0111 & CVE-2025-23209: Palo Alto Firewalls and Craft CMS Under Active Attack

Do Son February 20, 2025 0
Read More Read more about CVE-2025-0111 & CVE-2025-23209: Palo Alto Firewalls and Craft CMS Under Active Attack
China’s Cybersecurity Firms Reveal Alleged NSA (Equation Group) Tactics in University Hack APT-C-40 - Equation Group
  • Cyber Security

China’s Cybersecurity Firms Reveal Alleged NSA (Equation Group) Tactics in University Hack

Do Son February 20, 2025 0
Read More Read more about China’s Cybersecurity Firms Reveal Alleged NSA (Equation Group) Tactics in University Hack
CVE-2024-39327 (CVSS 9.9): Critical IDPKI Flaw Could Allow Illegitimate Certificate Issuance Ollama Heap Leak CVE-2026-5757 Anritsu Vulnerability Authentication Bypass Gootloader Malware Malformed ZIP Evasion Blender Malware, StealC V2 Lectora, XSS CVE-2025-9125 HFS RCE, Template Injection Arch Linux Malware, CHAOS RAT CVE-2024-56404 - CVE-2024-39327 CVE-2025-2538
  • Vulnerability

CVE-2024-39327 (CVSS 9.9): Critical IDPKI Flaw Could Allow Illegitimate Certificate Issuance

Do Son February 20, 2025 0
Read More Read more about CVE-2024-39327 (CVSS 9.9): Critical IDPKI Flaw Could Allow Illegitimate Certificate Issuance
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-78312CVSS 9.1
    Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-78308CVSS 9.8
    Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
    📅 Updated: Sep 24, 2026
  • CVE-2026-84502CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84719CVSS 9.9
    A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission...
    📅 Updated: Sep 24, 2026
  • CVE-2026-84474CVSS 9.9
    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed...
    📅 Updated: Sep 24, 2026
  • CVE-2026-75884CVSS 9.1
    A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts...
    📅 Updated: Sep 24, 2026
  • CVE-2026-12564CVSS 9.6
    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads...
    📅 Updated: Sep 24, 2026
  • CVE-2026-86708CVSS 10.0
    ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.