Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Optimizing QA Efforts with Risk-Based Testing Techniques devops-3155972_1280
  • Technique

Optimizing QA Efforts with Risk-Based Testing Techniques

Do Son February 10, 2025 0
Read More Read more about Optimizing QA Efforts with Risk-Based Testing Techniques
Microsoft Integrates AI Agents into GitHub Copilot Copilot Edits - Project Padawan
  • Technology

Microsoft Integrates AI Agents into GitHub Copilot

Do Son February 10, 2025 0
Read More Read more about Microsoft Integrates AI Agents into GitHub Copilot
Cloudflare R2 Outage Explained: Accidental Shutdown Cloudflare layoffs 2026 AI bot traffic surge Content Signals Policy, AI Content Usage Cloudflare, Certificate Misissuance Salesforce, supply chain attack DDoS attack, Cloudflare Perplexity AI, Web Scraping Pay Per Crawl Cloudflare abuse R2 outage HTTP Cloudflare Blocking
  • Technology

Cloudflare R2 Outage Explained: Accidental Shutdown

Do Son February 10, 2025 0
Read More Read more about Cloudflare R2 Outage Explained: Accidental Shutdown
PlayStation Network Down: Players Get 5-Day Extension PlayStation Network outage Sony Russia, business exit
  • Technology

PlayStation Network Down: Players Get 5-Day Extension

Do Son February 10, 2025 0
Read More Read more about PlayStation Network Down: Players Get 5-Day Extension
Meta Sued for Training AI with 81.7TB of Copyrighted Data Meta Horizon Worlds Quest shutdown Meta AI, Child Safety Meta Robotics, Android of Robotics Meta AI, Llama 4.X Meta, AI regulation Meta AI, Data Center Impact Meta AI, Superintelligence Meta Copyrighted Data AI chatbot
  • Technology

Meta Sued for Training AI with 81.7TB of Copyrighted Data

Do Son February 9, 2025 0
Read More Read more about Meta Sued for Training AI with 81.7TB of Copyrighted Data
Meta’s Brain2Qwerty: Turning Brainwaves into Text with 80% Accuracy Brain2Qwerty
  • Technology

Meta’s Brain2Qwerty: Turning Brainwaves into Text with 80% Accuracy

Do Son February 9, 2025 0
Read More Read more about Meta’s Brain2Qwerty: Turning Brainwaves into Text with 80% Accuracy
AnyDesk Exploit Alert: CVE-2024-12754 Enables Privilege Escalation—PoC Available CVE-2024-12754 PoC
  • Vulnerability

AnyDesk Exploit Alert: CVE-2024-12754 Enables Privilege Escalation—PoC Available

Do Son February 9, 2025 0
Read More Read more about AnyDesk Exploit Alert: CVE-2024-12754 Enables Privilege Escalation—PoC Available
CVE-2025-25064 (CVSS 9.8): Critical SQL Injection Bug in Zimbra Collaboration Zimbra 10.1.16 Zimbra Security Update Zimbra LFI, CVE-2025-68645 CVE-2025-25065 & CVE-2025-25064
  • Vulnerability

CVE-2025-25064 (CVSS 9.8): Critical SQL Injection Bug in Zimbra Collaboration

Do Son February 9, 2025 0
Read More Read more about CVE-2025-25064 (CVSS 9.8): Critical SQL Injection Bug in Zimbra Collaboration
Hackers Exploit Google Tag Manager to Steal Credit Card Data from Magento Sites Google Tag Manager Skimmer
  • Malware

Hackers Exploit Google Tag Manager to Steal Credit Card Data from Magento Sites

Do Son February 9, 2025 0
Read More Read more about Hackers Exploit Google Tag Manager to Steal Credit Card Data from Magento Sites
CVE-2025-0674 (CVSS 9.8) & CVE-2025-0675: CISA Warns of Critical Elber Flaws – PoC Available, No Patch CVE-2025-0674 (CVSS 9.8) & CVE-2025-0675
  • Vulnerability

CVE-2025-0674 (CVSS 9.8) & CVE-2025-0675: CISA Warns of Critical Elber Flaws – PoC Available, No Patch

Do Son February 9, 2025 0
Read More Read more about CVE-2025-0674 (CVSS 9.8) & CVE-2025-0675: CISA Warns of Critical Elber Flaws – PoC Available, No Patch
Threat Actors Exploit SimpleHelp Vulnerabilities to Deploy Sliver Backdoor Quest KACE Vulnerability CVE-2025-32975 FortiGate SSO Bypass, Active Exploitation GoAnywhere RCE, Storm-1175 Cisco VPN RCE, ASA Zero-Day TinyColor Supply Chain Attack SK Telecom, data breach Erlang/OTP RCE, OT Network Security Ivanti CSA Attacks WordPress RCE, Theme Vulnerability
  • Cyber Security
  • Vulnerability

Threat Actors Exploit SimpleHelp Vulnerabilities to Deploy Sliver Backdoor

Do Son February 9, 2025 0
Read More Read more about Threat Actors Exploit SimpleHelp Vulnerabilities to Deploy Sliver Backdoor
CVE-2024-48510 (CVSS 9.8): Critical Flaw in ABB Drive Composer Enables File System Access ABB T-MAC Plus vulnerabilities terminal system flaws ABB OPTIMAX Vulnerability CVE-2025-14510 ABB Edgenius Auth Bypass, Critical RCE ABB, ASPECT BMS CVE-2024-48841, CVE-2024-48849, and CVE-2024-48852 CVE-2024-48510
  • Vulnerability

CVE-2024-48510 (CVSS 9.8): Critical Flaw in ABB Drive Composer Enables File System Access

Do Son February 9, 2025 0
Read More Read more about CVE-2024-48510 (CVSS 9.8): Critical Flaw in ABB Drive Composer Enables File System Access
Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks ViewState code injection attacks
  • Cyber Security

Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks

Do Son February 9, 2025 0
Read More Read more about Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks
CVE-2025-0896 (CVSS 9.8): Orthanc DICOM Server Flaw Exposes Medical Images to Unauthorized Access CVE-2025-0896
  • Vulnerability

CVE-2025-0896 (CVSS 9.8): Orthanc DICOM Server Flaw Exposes Medical Images to Unauthorized Access

Do Son February 9, 2025 0
Read More Read more about CVE-2025-0896 (CVSS 9.8): Orthanc DICOM Server Flaw Exposes Medical Images to Unauthorized Access
Abyss Locker Ransomware: Inside the Stealthy Network Intrusions and Destructive Attacks INC Ransom Pacific Cyber Threats OysterLoader Malware Rhysida Ransomware Black Basta Ransomware BYOVD Technique Velociraptor Abuse, Storm-2603 Ransomware Crypto24, Ransomware Ransomware Payments, UK Legislation ZACROS data breach
  • Malware
  • Vulnerability

Abyss Locker Ransomware: Inside the Stealthy Network Intrusions and Destructive Attacks

Do Son February 9, 2025 0
Read More Read more about Abyss Locker Ransomware: Inside the Stealthy Network Intrusions and Destructive Attacks
Massive Indian Mobile Banking Heist Uncovered: FatBoyPanel’s Trojan Network Exposes 50,000 Users’ Data FatBoyPanel
  • Data Leak
  • Malware

Massive Indian Mobile Banking Heist Uncovered: FatBoyPanel’s Trojan Network Exposes 50,000 Users’ Data

Do Son February 9, 2025 0
Read More Read more about Massive Indian Mobile Banking Heist Uncovered: FatBoyPanel’s Trojan Network Exposes 50,000 Users’ Data
CVE-2025-24786 (CVSS 10) & CVE-2025-24787: Critical WhoDB Vulnerabilities CVE-2025-24786 & CVE-2025-24787
  • Vulnerability

CVE-2025-24786 (CVSS 10) & CVE-2025-24787: Critical WhoDB Vulnerabilities

Do Son February 9, 2025 0
Read More Read more about CVE-2025-24786 (CVSS 10) & CVE-2025-24787: Critical WhoDB Vulnerabilities
Flesh Stealer Malware Targets Browsers and Cryptocurrency Wallets Flesh Stealer
  • Malware

Flesh Stealer Malware Targets Browsers and Cryptocurrency Wallets

Do Son February 9, 2025 0
Read More Read more about Flesh Stealer Malware Targets Browsers and Cryptocurrency Wallets
Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks SVG Phishing Attacks
  • Cyber Security

Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks

Do Son February 8, 2025 0
Read More Read more about Sophos Uncovers Rising Threat of SVG-Based Phishing Attacks
CVE-2024-51547 (CVSS 9.8): Hard-Coded Credentials in ABB ASPECT CVE-2024-51547
  • Vulnerability

CVE-2024-51547 (CVSS 9.8): Hard-Coded Credentials in ABB ASPECT

Do Son February 8, 2025 0
Read More Read more about CVE-2024-51547 (CVSS 9.8): Hard-Coded Credentials in ABB ASPECT
Malicious Cisco AnyConnect Ads Target Users with NetSupport RAT shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Malicious Cisco AnyConnect Ads Target Users with NetSupport RAT

Do Son February 8, 2025 0
Read More Read more about Malicious Cisco AnyConnect Ads Target Users with NetSupport RAT
Lazarus Group Lures Victims with Fake LinkedIn Job Offers, Warns Bitdefender North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security

Lazarus Group Lures Victims with Fake LinkedIn Job Offers, Warns Bitdefender

Do Son February 7, 2025 0
Read More Read more about Lazarus Group Lures Victims with Fake LinkedIn Job Offers, Warns Bitdefender
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-15340CVSS 9.8
    lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-16516CVSS 9.0
    wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm...
    📅 Updated: Oct 7, 2026
  • CVE-2026-14911CVSS 9.3
    Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker...
    📅 Updated: Oct 7, 2026
  • CVE-2026-19386CVSS 9.3
    A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-104334CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.