Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars HOLLOWGRAPH malware using Microsoft Graph API abuse to hide command-and-control inside a Microsoft 365 calendar event dated 2050
  • Malware

HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars

Do Son July 20, 2026 0
Read More Read more about HOLLOWGRAPH Malware Hides Command-and-Control in Microsoft 365 Calendars
CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords CrashStealer macOS infostealer posing as Apple crash reporter to steal browser and crypto wallet data
  • Malware

CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords

Do Son July 20, 2026 0
Read More Read more about CrashStealer: New macOS Infostealer Poses as Apple Crash Reporter to Steal Wallets and Passwords
Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems Salt Typhoon Teleco Hack, Cisco Academy Link CVE-2025-0282 PoC exploit
  • Cybercriminals

Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems

Do Son July 20, 2026 0
Read More Read more about Operation ShadowRecruit Uses Fake Government Job Ads to Plant SheetAgent RAT on Indian Systems
LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts Exploited VMware
  • Malware

LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts

Do Son July 20, 2026 0
Read More Read more about LabubaRAT Poses as NVIDIA Software to Hand Operators Full Control of Windows Hosts
Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions Codex context window change: OpenAI lowers the limit to 272K and forbids rm -rf $HOME in the system prompt after deletions
  • Technology

Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions

Do Son July 20, 2026 0
Read More Read more about Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions
Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault KB5121767 out-of-band update: Microsoft fix for the Dell USB-C driver compatibility fault on affected Precision and XPS laptops
  • Windows

Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault

Do Son July 20, 2026 0
Read More Read more about Microsoft Ships KB5121767 Out-of-Band Update to Fix a Dell USB-C Compatibility Fault
The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips Mac Pro discontinuation: Apple's cheese-grater tower retired as the Mac Studio and Apple Silicon take over professional workflows
  • Technology

The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips

Do Son July 20, 2026 0
Read More Read more about The Mac Pro That Never Shipped: Apple Secretly Built a New Intel Model and Killed Its “Extreme” Chips
Mid-July 2026: Weekly Threat Intelligence Report actively exploited vulnerabilities
  • Weekly Recap

Mid-July 2026: Weekly Threat Intelligence Report

Do Son July 20, 2026 0
Read More Read more about Mid-July 2026: Weekly Threat Intelligence Report
CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts Kimai vulnerability CVE-2026-52824 account takeover via default Docker APP_SECRET
  • Vulnerability Report

CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts

Do Son July 20, 2026 0
Read More Read more about CVE-2026-52824: Default Docker Secret in Kimai Enables Account Takeover of Super Admin Accounts
Why Network Teams Are Pulling Routing Intelligence Back In-House why
  • Technique

Why Network Teams Are Pulling Routing Intelligence Back In-House

Do Son July 20, 2026 0
Read More Read more about Why Network Teams Are Pulling Routing Intelligence Back In-House
OpenSSL HollowByte Vulnerability Causes Memory Exhaustion Diagram explaining the OpenSSL HollowByte vulnerability and OpenSSL DoS attack mechanism
  • Vulnerability Report

OpenSSL HollowByte Vulnerability Causes Memory Exhaustion

Do Son July 20, 2026 0
Read More Read more about OpenSSL HollowByte Vulnerability Causes Memory Exhaustion
SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware SonicWall SMA zero-day exploit chain compromising SMA VPN appliances to deploy malware
  • Cybercriminals

SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware

Do Son July 19, 2026 0
Read More Read more about SonicWall SMA Zero-Day Chain Roots VPN Appliances and Plants Hidden Malware
US Justice Department Approves TikTok for Government Devices DOJ lifts TikTok ban for federal workers and allows government downloads
  • Technology

US Justice Department Approves TikTok for Government Devices

Do Son July 18, 2026 0
Read More Read more about US Justice Department Approves TikTok for Government Devices
Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent Hugging Face breach driven by an autonomous AI agent attack exposing internal datasets and credentials
  • Data Leak

Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent

Do Son July 18, 2026 0
Read More Read more about Hugging Face Discloses Production Breach Driven by an Autonomous AI Agent
Meta and Anthropic Negotiate Computing Power Lease Meta AI computing power lease and Anthropic data center negotiations
  • Technology

Meta and Anthropic Negotiate Computing Power Lease

Do Son July 18, 2026 0
Read More Read more about Meta and Anthropic Negotiate Computing Power Lease
Claude Fable 5 Subscription Changes Announced Claude Fable 5 subscription updates and AI computational limitations
  • Technology

Claude Fable 5 Subscription Changes Announced

Do Son July 18, 2026 0
Read More Read more about Claude Fable 5 Subscription Changes Announced
Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution Diagram of CVE-2026-6875 ServiceNow sandbox escape RCE and pre-auth code execution
  • Vulnerability Report

Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution

Do Son July 18, 2026 0
Read More Read more about Active Exploitation and Public PoC Disclosed for CVE-2026-6875 ServiceNow Sandbox Escape Remote Code Execution
Cloudflare Blocks Critical WordPress wp2shell Vulnerability Cloudflare firewall blocking the critical WordPress wp2shell vulnerability and RCE attacks
  • Vulnerability Report

Cloudflare Blocks Critical WordPress wp2shell Vulnerability

Do Son July 18, 2026 0
Read More Read more about Cloudflare Blocks Critical WordPress wp2shell Vulnerability
Microsoft Ends OneDrive Support for Windows 10 Microsoft ending OneDrive updates and support for Windows 10 lifecycle
  • Technology

Microsoft Ends OneDrive Support for Windows 10

Do Son July 18, 2026 0
Read More Read more about Microsoft Ends OneDrive Support for Windows 10
Ubuntu Pro Client Flaw CVE-2026-11386 Allows Arbitrary Code Execution With Root Privileges Ubuntu Pro Client vulnerability CVE-2026-11386 APT source injection arbitrary code execution root privileges
  • Vulnerability Report

Ubuntu Pro Client Flaw CVE-2026-11386 Allows Arbitrary Code Execution With Root Privileges

Do Son July 18, 2026 0
Read More Read more about Ubuntu Pro Client Flaw CVE-2026-11386 Allows Arbitrary Code Execution With Root Privileges
WordPress Pre-Auth RCE CVE-2026-63030: Vulnerability Details and PoC Exploit Code Now Public WordPress pre-auth RCE CVE-2026-63030 REST batch route confusion SQL injection public PoC
  • Vulnerability Report

WordPress Pre-Auth RCE CVE-2026-63030: Vulnerability Details and PoC Exploit Code Now Public

Do Son July 18, 2026 0
Read More Read more about WordPress Pre-Auth RCE CVE-2026-63030: Vulnerability Details and PoC Exploit Code Now Public
APT-C-60 Attacks Target Japan With SpyGlace Malware APT-C-60 attacks on Japan using LNK files and legitimate services to deploy SpyGlace malware
  • Cybercriminals

APT-C-60 Attacks Target Japan With SpyGlace Malware

Do Son July 18, 2026 0
Read More Read more about APT-C-60 Attacks Target Japan With SpyGlace Malware
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-59178CVSS 9.8
    ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management...
  • CVE-2026-90945CVSS 9.8
    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing...
  • CVE-2026-90942CVSS 9.6
    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private...
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco...
  • CVE-2026-76443CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-76441CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-76440CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-20353CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-57131CVSS 9.8
    PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router...
  • CVE-2026-57124CVSS 9.8
    PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.