Skip to content
September 24, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
10,000 WordPress Websites Compromised to Deliver macOS and Windows Malware SocGholish Windows malware
  • Malware

10,000 WordPress Websites Compromised to Deliver macOS and Windows Malware

Do Son February 3, 2025 0
Read More Read more about 10,000 WordPress Websites Compromised to Deliver macOS and Windows Malware
Lumma Stealer Uses GitHub as a Malware Delivery Platform Artivion cybersecurity - Zero-Day Attacks
  • Malware

Lumma Stealer Uses GitHub as a Malware Delivery Platform

Do Son February 3, 2025 0
Read More Read more about Lumma Stealer Uses GitHub as a Malware Delivery Platform
CVE-2024-53104: Critical Zero-Day Vulnerability Patched in February 2025 Android Security Update Android Zero-Click RCE CVE-2026-0073 Android sideloading CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747 and, CVE-2024-49748
  • Android
  • Vulnerability

CVE-2024-53104: Critical Zero-Day Vulnerability Patched in February 2025 Android Security Update

Do Son February 3, 2025 0
Read More Read more about CVE-2024-53104: Critical Zero-Day Vulnerability Patched in February 2025 Android Security Update
Canadian Hacker Indicted for $65 Million DeFi Exploit Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cyber Security

Canadian Hacker Indicted for $65 Million DeFi Exploit

Do Son February 3, 2025 0
Read More Read more about Canadian Hacker Indicted for $65 Million DeFi Exploit
MediaTek’s February 2025 Security Bulletin: Critical WLAN Vulnerabilities Expose Millions to Remote Attacks MediaTek Modem Vulnerabilities, January 2026 Security Bulletin MediaTek Vulnerabilities, Chipset Security CVE-2024-20103 & CVE-2024-20100 - CVE-2024-20154 - February 2025 Product Security Bulletin
  • Vulnerability

MediaTek’s February 2025 Security Bulletin: Critical WLAN Vulnerabilities Expose Millions to Remote Attacks

Do Son February 3, 2025 0
Read More Read more about MediaTek’s February 2025 Security Bulletin: Critical WLAN Vulnerabilities Expose Millions to Remote Attacks
Cristal Intelligence: SoftBank’s $3B Bet on OpenAI SoftBank OpenAI $41 billion investment, Masayoshi Son AGI wager Cristal Intelligence - SB OpenAI Japan
  • Technology

Cristal Intelligence: SoftBank’s $3B Bet on OpenAI

Do Son February 3, 2025 0
Read More Read more about Cristal Intelligence: SoftBank’s $3B Bet on OpenAI
ChatGPT’s Deep Research: AI-Powered Web Exploration OpenAI Deep Research
  • Technology

ChatGPT’s Deep Research: AI-Powered Web Exploration

Do Son February 3, 2025 0
Read More Read more about ChatGPT’s Deep Research: AI-Powered Web Exploration
CompTIA Linux+: Exploring Its Benefits and Career Paths CompTIA
  • Technique

CompTIA Linux+: Exploring Its Benefits and Career Paths

Do Son February 3, 2025 0
Read More Read more about CompTIA Linux+: Exploring Its Benefits and Career Paths
Sanctions Risk in Open Source: Linux Foundation Offers Guidance Linux Kernel 6.19 AMDGPU update, GCN 1.0 1.1 performance boost Linux Sanctions Risk Linux i486
  • Linux
  • Technology

Sanctions Risk in Open Source: Linux Foundation Offers Guidance

Do Son February 3, 2025 0
Read More Read more about Sanctions Risk in Open Source: Linux Foundation Offers Guidance
Microsoft to Kill its 365 VPN: What You Need to Know student discount Microsoft 365, Intelligent Services Microsoft 365 UWP, App Deprecation Microsoft 365, Startup Boost Windows 10 EOL, Microsoft 365 Support Protocol Deprecation Microsoft 365 Updates, IT Admin Alert Microsoft 365 VPN shut down Microsoft Authenticator, password manager Windows 10 Microsoft 365 Microsoft nonprofit policy, software donations
  • Technology

Microsoft to Kill its 365 VPN: What You Need to Know

Do Son February 3, 2025 0
Read More Read more about Microsoft to Kill its 365 VPN: What You Need to Know
PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8) Apple Background Security CVE-2026-20643 Apple Background Security Improvement Apple Backdoor Apple Lawsuit, Data Exfiltration CVE-2024-44131 - CVE-2025-24118 PoC
  • Vulnerability

PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8)

Do Son February 2, 2025 0
Read More Read more about PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8)
North Korean APT Lazarus Uses Malicious npm Package to Target Developers North Korean APT Lazarus
  • Malware

North Korean APT Lazarus Uses Malicious npm Package to Target Developers

Do Son February 2, 2025 0
Read More Read more about North Korean APT Lazarus Uses Malicious npm Package to Target Developers
CVE-2024-57376: End-of-Life D-Link Routers Vulnerable to Unauthenticated RCE CVE-2024-57376 - DSL-3788 Router Vulnerability
  • Vulnerability

CVE-2024-57376: End-of-Life D-Link Routers Vulnerable to Unauthenticated RCE

Do Son February 2, 2025 0
Read More Read more about CVE-2024-57376: End-of-Life D-Link Routers Vulnerable to Unauthenticated RCE
Devil-Traff: The New SMS Phishing Platform Exploited by Cybercriminals Devil-Traff
  • Cyber Security

Devil-Traff: The New SMS Phishing Platform Exploited by Cybercriminals

Do Son February 2, 2025 0
Read More Read more about Devil-Traff: The New SMS Phishing Platform Exploited by Cybercriminals
CVE-2025-0477 (CVSS 9.8): Critical Security Flaw in Rockwell Automation’s FactoryTalk AssetCentre Rockwell Automation Warning OT Security Rockwell SQLi, Industrial Safety DoS Verve Asset Manager API OT Privilege Escalation Rockwell NAT Router, Critical Auth Bypass Rockwell ICS Privilege Escalation, MSI Repair Attack CVE-2025-7353 Critical vulnerability, industrial control systems Rockwell vulnerability, ICS security Rockwell Arena, Memory Abuse Rockwell Automation, RCE Vulnerability CVE-2025-24479 and CVE-2025-24480 - CVE-2025-0477
  • Vulnerability

CVE-2025-0477 (CVSS 9.8): Critical Security Flaw in Rockwell Automation’s FactoryTalk AssetCentre

Do Son February 2, 2025 0
Read More Read more about CVE-2025-0477 (CVSS 9.8): Critical Security Flaw in Rockwell Automation’s FactoryTalk AssetCentre
The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users Malicious AdTech
  • Cyber Security

The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users

Do Son February 2, 2025 0
Read More Read more about The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users
CVE-2025-0851 (CVSS 9.8): Deep Java Library Vulnerability Allows Path Traversal Exploits CVE-2025-0851
  • Vulnerability

CVE-2025-0851 (CVSS 9.8): Deep Java Library Vulnerability Allows Path Traversal Exploits

Do Son February 2, 2025 0
Read More Read more about CVE-2025-0851 (CVSS 9.8): Deep Java Library Vulnerability Allows Path Traversal Exploits
SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security
  • Malware

SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond

Do Son February 2, 2025 0
Read More Read more about SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond
.Gov No More: Government Domains Weaponized in Phishing Surge Layoff Phishing Scam Remcos RAT Malware Aruba Phishing, Phishing-as-a-Service PyPI, phishing CVE-2024-25608 PyPI Phishing, Credential Theft
  • Cyber Security
  • Vulnerability

.Gov No More: Government Domains Weaponized in Phishing Surge

Do Son February 2, 2025 0
Read More Read more about .Gov No More: Government Domains Weaponized in Phishing Surge
Unrestricted Access: A Simple Web Misconfiguration Exposes Critical Data Web Misconfiguration
  • Data Leak

Unrestricted Access: A Simple Web Misconfiguration Exposes Critical Data

Do Son February 2, 2025 0
Read More Read more about Unrestricted Access: A Simple Web Misconfiguration Exposes Critical Data
CISA Warns of Hidden Backdoor in Contec CMS8000 Patient Monitors Contec CMS8000 backdoor - CVE-2025-0626 ,CVE-2025-0683
  • Vulnerability

CISA Warns of Hidden Backdoor in Contec CMS8000 Patient Monitors

Do Son February 2, 2025 0
Read More Read more about CISA Warns of Hidden Backdoor in Contec CMS8000 Patient Monitors
Adversarial Misuse of Generative AI: How APTs Are Experimenting with AI for Cyber Operations illegal streaming networks complex criminal enterprises UAT-7290 China-nexus Espionage Adversarial Misuse of Generative AI
  • Cyber Security

Adversarial Misuse of Generative AI: How APTs Are Experimenting with AI for Cyber Operations

Do Son February 1, 2025 0
Read More Read more about Adversarial Misuse of Generative AI: How APTs Are Experimenting with AI for Cyber Operations
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-32996CVSS 7.3
    A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
    Admin intel📅 Updated: Sep 22, 2026
  • CVE-2026-7273CVSS 8.8
    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a...
    CISA KEV📅 Added to KEV: Sep 21, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    📅 Updated: Sep 24, 2026
  • CVE-2026-78225CVSS 9.0
    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
    📅 Updated: Sep 24, 2026
  • CVE-2026-81855CVSS 9.1
    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
    📅 Updated: Sep 24, 2026
  • CVE-2026-54617CVSS 9.8
    GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can...
    📅 Updated: Sep 24, 2026
  • CVE-2025-59953CVSS 9.8
    LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior...
    📅 Updated: Sep 24, 2026
  • CVE-2026-54752CVSS 9.6
    NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation...
    📅 Updated: Sep 24, 2026
  • CVE-2026-54626CVSS 9.8
    SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles....
    📅 Updated: Sep 24, 2026
  • CVE-2026-45140CVSS 9.8
    Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.