Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
US Treasury Sanctions Russian Bulletproof Hosting Provider Zservers for Supporting LockBit Ransomware Attacks CVE-2024-3393 - Zservers sanctions
  • Cyber Security

US Treasury Sanctions Russian Bulletproof Hosting Provider Zservers for Supporting LockBit Ransomware Attacks

Do Son February 11, 2025 0
Read More Read more about US Treasury Sanctions Russian Bulletproof Hosting Provider Zservers for Supporting LockBit Ransomware Attacks
Microsoft Patches Actively Exploited Zero-Day Flaws – CVE-2025-21418 & CVE-2025-21391 Microsoft Patch Tuesday fixes disclosed zero day vulnerabilities Windows Wormable Exploit April 2026 Patch Tuesday Microsoft Patch Tuesday Zero-Day Vulnerabilities Microsoft, Patch Tuesday CVE-2025-55234 CVE-2024-43573 and CVE-2024-43572 Microsoft Patch Tuesday Security Vulnerabilities
  • Vulnerability

Microsoft Patches Actively Exploited Zero-Day Flaws – CVE-2025-21418 & CVE-2025-21391

Do Son February 11, 2025 0
Read More Read more about Microsoft Patches Actively Exploited Zero-Day Flaws – CVE-2025-21418 & CVE-2025-21391
CVE-2024-12797 – High-Severity OpenSSL Flaw: Update Now to Prevent MITM Attacks OpenSSL Vulnerability RSA Memory Leak OpenSSL Vulnerability CVE-2025-15467 CVE-2022-2274 OpenSSL Vulnerabilities, Timing Side-Channel
  • Vulnerability

CVE-2024-12797 – High-Severity OpenSSL Flaw: Update Now to Prevent MITM Attacks

Do Son February 11, 2025 0
Read More Read more about CVE-2024-12797 – High-Severity OpenSSL Flaw: Update Now to Prevent MITM Attacks
CVE-2024-47908 (CVSS 9.1): Critical Ivanti CSA Flaw Enables Attackers to Run Arbitrary Code CVE-2023-39335 - CVE-2024-47908 - CVE-2024-11771
  • Vulnerability

CVE-2024-47908 (CVSS 9.1): Critical Ivanti CSA Flaw Enables Attackers to Run Arbitrary Code

Do Son February 11, 2025 0
Read More Read more about CVE-2024-47908 (CVSS 9.1): Critical Ivanti CSA Flaw Enables Attackers to Run Arbitrary Code
SAP Security Patch Day February 2025: Multi Vulnerabilities Addressed CVE-2024-33006 - CVE-2025-0064 SAP Critical Patch, RMI-P4 RCE
  • Vulnerability

SAP Security Patch Day February 2025: Multi Vulnerabilities Addressed

Do Son February 11, 2025 0
Read More Read more about SAP Security Patch Day February 2025: Multi Vulnerabilities Addressed
Robust Open Online Safety Tools (ROOST): Tech Giants Unite to Build AI-Era Security Infrastructure "ROOST" Robust Open Online Safety Tools
  • Technology

Robust Open Online Safety Tools (ROOST): Tech Giants Unite to Build AI-Era Security Infrastructure

Do Son February 11, 2025 0
Read More Read more about Robust Open Online Safety Tools (ROOST): Tech Giants Unite to Build AI-Era Security Infrastructure
$16 Million Ransomware Operation Shut Down: 8Base Masterminds Apprehended 8Base ransomware down
  • Cyber Security

$16 Million Ransomware Operation Shut Down: 8Base Masterminds Apprehended

Do Son February 10, 2025 0
Read More Read more about $16 Million Ransomware Operation Shut Down: 8Base Masterminds Apprehended
Google Chrome Tests AI-Driven Auto Password Change for Breached Accounts Chrome Automated password change
  • Technology

Google Chrome Tests AI-Driven Auto Password Change for Breached Accounts

Do Son February 10, 2025 0
Read More Read more about Google Chrome Tests AI-Driven Auto Password Change for Breached Accounts
Google’s reCAPTCHA Fails to Stop Bots—But It’s Great at Harvesting Your Data reCAPTCHA hand gesture verification scanning process and biometric CAPTCHA security reCAPTCHA Data
  • Data Leak

Google’s reCAPTCHA Fails to Stop Bots—But It’s Great at Harvesting Your Data

Do Son February 10, 2025 0
Read More Read more about Google’s reCAPTCHA Fails to Stop Bots—But It’s Great at Harvesting Your Data
GitHub Enterprise SAML Bypass Flaw (CVE-2025-23369) Exposed – Technical Analysis and Exploit PoC CVE-2024-9487 - CVE-2025-23369 PoC
  • Vulnerability

GitHub Enterprise SAML Bypass Flaw (CVE-2025-23369) Exposed – Technical Analysis and Exploit PoC

Do Son February 10, 2025 0
Read More Read more about GitHub Enterprise SAML Bypass Flaw (CVE-2025-23369) Exposed – Technical Analysis and Exploit PoC
Multiple Security and Privacy Flaws Found in DeepSeek iOS App DeepSeek V3 App Store
  • Data Leak
  • Vulnerability

Multiple Security and Privacy Flaws Found in DeepSeek iOS App

Do Son February 10, 2025 0
Read More Read more about Multiple Security and Privacy Flaws Found in DeepSeek iOS App
Alabama Man Pleads Guilty in Bitcoin Price Manipulation Scheme Involving Hacked SEC X Account X Account Hack
  • Cyber Security

Alabama Man Pleads Guilty in Bitcoin Price Manipulation Scheme Involving Hacked SEC X Account

Do Son February 10, 2025 0
Read More Read more about Alabama Man Pleads Guilty in Bitcoin Price Manipulation Scheme Involving Hacked SEC X Account
Malicious Models on Hugging Face: A New Threat to AI Development nullifAI
  • Malware

Malicious Models on Hugging Face: A New Threat to AI Development

Do Son February 10, 2025 0
Read More Read more about Malicious Models on Hugging Face: A New Threat to AI Development
The Rise of Phishing-as-a-Service: How Cybercriminals are Outsourcing Attacks DocuSign-Themed Phishing Email
  • Cyber Security

The Rise of Phishing-as-a-Service: How Cybercriminals are Outsourcing Attacks

Do Son February 10, 2025 0
Read More Read more about The Rise of Phishing-as-a-Service: How Cybercriminals are Outsourcing Attacks
LegionLoader Malware Downloader Resurfaces with 2,000+ New Samples maps
  • Malware

LegionLoader Malware Downloader Resurfaces with 2,000+ New Samples

Do Son February 10, 2025 0
Read More Read more about LegionLoader Malware Downloader Resurfaces with 2,000+ New Samples
CVE-2025-1077 (CVSSv4 9.5): Critical RCE Vulnerability Found in Visual Weather Products CVE-2025-1077
  • Vulnerability

CVE-2025-1077 (CVSSv4 9.5): Critical RCE Vulnerability Found in Visual Weather Products

Do Son February 10, 2025 0
Read More Read more about CVE-2025-1077 (CVSSv4 9.5): Critical RCE Vulnerability Found in Visual Weather Products
BadIIS Malware Hijacks Asian Websites for SEO Fraud BadIIS malware
  • Malware

BadIIS Malware Hijacks Asian Websites for SEO Fraud

Do Son February 10, 2025 0
Read More Read more about BadIIS Malware Hijacks Asian Websites for SEO Fraud
Progress LoadMaster Security Update: Multiple Vulnerabilities Addressed CVE-2024-6327 - CVE-2024-56131
  • Vulnerability

Progress LoadMaster Security Update: Multiple Vulnerabilities Addressed

Do Son February 10, 2025 0
Read More Read more about Progress LoadMaster Security Update: Multiple Vulnerabilities Addressed
Misconfigured APIs Expose Sensitive Medical Data in Major Diagnostic Chain Misconfigured API
  • Data Leak
  • Vulnerability

Misconfigured APIs Expose Sensitive Medical Data in Major Diagnostic Chain

Do Son February 10, 2025 0
Read More Read more about Misconfigured APIs Expose Sensitive Medical Data in Major Diagnostic Chain
768 CVEs Exploited in 2024: VulnCheck Warns of Rising Threat WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Vulnerability

768 CVEs Exploited in 2024: VulnCheck Warns of Rising Threat

Do Son February 10, 2025 0
Read More Read more about 768 CVEs Exploited in 2024: VulnCheck Warns of Rising Threat
Apple Issues Emergency Updates to Patch Actively Exploited Zero-Day Vulnerability – CVE-2025-24200 DarkSword exploit kit iOS 18.7.7 security update CVE-2024-44308 & CVE-2024-44309 Apple appeal, Epic Games lawsuit
  • Vulnerability

Apple Issues Emergency Updates to Patch Actively Exploited Zero-Day Vulnerability – CVE-2025-24200

Do Son February 10, 2025 0
Read More Read more about Apple Issues Emergency Updates to Patch Actively Exploited Zero-Day Vulnerability – CVE-2025-24200
Optimizing QA Efforts with Risk-Based Testing Techniques devops-3155972_1280
  • Technique

Optimizing QA Efforts with Risk-Based Testing Techniques

Do Son February 10, 2025 0
Read More Read more about Optimizing QA Efforts with Risk-Based Testing Techniques
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-16516CVSS 9.0
    wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm...
    📅 Updated: Oct 7, 2026
  • CVE-2026-14911CVSS 9.3
    Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker...
    📅 Updated: Oct 7, 2026
  • CVE-2026-19386CVSS 9.3
    A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-104334CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106501CVSS 9.6
    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.