Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
F5 Warns of TLS Session Resumption Vulnerability in NGINX (CVE-2025-23419) NGINX JavaScript Module Vulnerability CVE-2026-8711 NGINX 1.30.1 Security Update CVE-2026-42945 RCE NGINX Vulnerability CVE-2026-1642 NGINX Github - CVE-2025-23419
  • Vulnerability

F5 Warns of TLS Session Resumption Vulnerability in NGINX (CVE-2025-23419)

Do Son February 5, 2025 0
Read More Read more about F5 Warns of TLS Session Resumption Vulnerability in NGINX (CVE-2025-23419)
XE Group Exploits Zero-Day Vulnerabilities in VeraCore – CVE-2024-57968 & CVE-2025-25181 Winos 4.0 Malware Silver Fox APT RapperBot BVIEC cyberattack - CNC group DAMASCENED PEACOCK, malware analysis
  • Cyber Security
  • Vulnerability

XE Group Exploits Zero-Day Vulnerabilities in VeraCore – CVE-2024-57968 & CVE-2025-25181

Do Son February 5, 2025 0
Read More Read more about XE Group Exploits Zero-Day Vulnerabilities in VeraCore – CVE-2024-57968 & CVE-2025-25181
Malicious Go Package Exploits Caching for Stealthy Persistence Malicious Go Package Exploits Caching for Stealthy Persistence
  • Malware

Malicious Go Package Exploits Caching for Stealthy Persistence

Do Son February 5, 2025 0
Read More Read more about Malicious Go Package Exploits Caching for Stealthy Persistence
Zyxel Routers Under Attack: Default Credentials (CVE-2025-0890) and Code Injection (CVE-2024-40891), No Patch! CVE-2025-0890
  • Vulnerability

Zyxel Routers Under Attack: Default Credentials (CVE-2025-0890) and Code Injection (CVE-2024-40891), No Patch!

Do Son February 5, 2025 0
Read More Read more about Zyxel Routers Under Attack: Default Credentials (CVE-2025-0890) and Code Injection (CVE-2024-40891), No Patch!
Kubernetes Policy Enforcement at Risk: OPA Gatekeeper Bypass Exposes Security Flaws Ingress-Nginx Vulnerability Kubernetes RCE Vulnerability CVE-2025-9708 Kubernetes Security, Image Builder Vulnerability CVE-2024-10220 - OPA Gatekeeper Bypass
  • Vulnerability

Kubernetes Policy Enforcement at Risk: OPA Gatekeeper Bypass Exposes Security Flaws

Do Son February 5, 2025 0
Read More Read more about Kubernetes Policy Enforcement at Risk: OPA Gatekeeper Bypass Exposes Security Flaws
Google Security Team Uncovers AMD Microcode Vulnerability (CVE-2024-56161) AMD Microcode Vulnerability - CVE-2024-56161
  • Vulnerability

Google Security Team Uncovers AMD Microcode Vulnerability (CVE-2024-56161)

Do Son February 5, 2025 0
Read More Read more about Google Security Team Uncovers AMD Microcode Vulnerability (CVE-2024-56161)
$50 for Your Data: NOVA Stealer Sold as Malware-as-a-Service Oracle EBS Zero-Day, GRACEFUL SPIDER Cracked Software, Supply Chain Attack Black Basta - NOVA stealer
  • Malware

$50 for Your Data: NOVA Stealer Sold as Malware-as-a-Service

Do Son February 5, 2025 0
Read More Read more about $50 for Your Data: NOVA Stealer Sold as Malware-as-a-Service
Security Flaws Discovered in Apache Cassandra: Unauthorized Access, Privilege Escalation, and JMX Credential Theft CVE-2025-24860
  • Vulnerability

Security Flaws Discovered in Apache Cassandra: Unauthorized Access, Privilege Escalation, and JMX Credential Theft

Do Son February 5, 2025 0
Read More Read more about Security Flaws Discovered in Apache Cassandra: Unauthorized Access, Privilege Escalation, and JMX Credential Theft
SmartApeSG Campaign Uncovered: A Deep Dive into NetSupport RAT Distribution and Suspected Threat Actor Connections CRussian Market, "Fly" (Flyded) hange Healthcare Cyberattack - CVE-2024-50603 Exploit
  • Cyber Security
  • Malware

SmartApeSG Campaign Uncovered: A Deep Dive into NetSupport RAT Distribution and Suspected Threat Actor Connections

Do Son February 5, 2025 0
Read More Read more about SmartApeSG Campaign Uncovered: A Deep Dive into NetSupport RAT Distribution and Suspected Threat Actor Connections
North Korean-Linked Malware ‘FlexibleFerret’ Expands macOS Attack Surface North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Malware

North Korean-Linked Malware ‘FlexibleFerret’ Expands macOS Attack Surface

Do Son February 5, 2025 0
Read More Read more about North Korean-Linked Malware ‘FlexibleFerret’ Expands macOS Attack Surface
Symantec PAM Patches Critical Security Flaw – CVE-2025-24503 (CVSSv4 9.3) CVE-2025-24503
  • Vulnerability

Symantec PAM Patches Critical Security Flaw – CVE-2025-24503 (CVSSv4 9.3)

Do Son February 5, 2025 0
Read More Read more about Symantec PAM Patches Critical Security Flaw – CVE-2025-24503 (CVSSv4 9.3)
SparkCat Malware: Sneaky Crypto Stealer Found in Google Play and App Store Apps SparkCat malware
  • Malware

SparkCat Malware: Sneaky Crypto Stealer Found in Google Play and App Store Apps

Do Son February 5, 2025 0
Read More Read more about SparkCat Malware: Sneaky Crypto Stealer Found in Google Play and App Store Apps
Microsoft Releases PowerShell Script for UEFI Certificate Update Windows Secure Lock Screen Clock Lag Windows 11 KB5079391 error Windows 11 Kernel Driver Trust Microslop Windows 11 Windows 11 modem driver removal 2026, CVE-2025-24052 Agere driver exploit Windows 11 Password Icon Bug Lock Screen Glitch Windows 11 26H1 ARM Snapdragon X2 Windows 11 Reboot-Free, Insider Build Windows Update Error, 0x80070103 File Explorer, NTLM leak Windows bug, WinRE Windows Update, UAC prompts Secure Boot Certificate, Windows Security Windows 11 22H2 Installation security updates Windows UEFI CA 2023 Windows 11 25H2
  • Technology
  • Windows

Microsoft Releases PowerShell Script for UEFI Certificate Update

Do Son February 5, 2025 0
Read More Read more about Microsoft Releases PowerShell Script for UEFI Certificate Update
Meta Unveils “Frontier AI Framework” to Address High-Risk AI Frontier AI Framework
  • Technology

Meta Unveils “Frontier AI Framework” to Address High-Risk AI

Do Son February 5, 2025 0
Read More Read more about Meta Unveils “Frontier AI Framework” to Address High-Risk AI
New in Windows 11: Lock Screen Widget Customization Windows 11 lock screen widget
  • Windows

New in Windows 11: Lock Screen Widget Customization

Do Son February 5, 2025 0
Read More Read more about New in Windows 11: Lock Screen Widget Customization
Google Under Investigation in China Amidst Trade Tensions Google Self-Preferencing Fine Idealo Antitrust Damages Anthropic, Google TPUs Google DMA Compliance, Search Self-Preferencing Google Play Store Ruling, Epic Games Victory Google fine, ad tech Google lawsuit, privacy violation Gmail security, false alarm Google Play EU regulation Google Security, Phone Number Leak Google 2025 - Google China’s Anti-Monopoly Law Google monopoly, ad tech Pixel 7a battery, battery swelling
  • Technology

Google Under Investigation in China Amidst Trade Tensions

Do Son February 5, 2025 0
Read More Read more about Google Under Investigation in China Amidst Trade Tensions
PoC Releases for Linux Kernel Flaw CVE-2024-36972: Double Free Flaw Enables Privilege Escalation and Container Escape CVE-2024-36972 PoC exploit
  • Linux
  • Vulnerability

PoC Releases for Linux Kernel Flaw CVE-2024-36972: Double Free Flaw Enables Privilege Escalation and Container Escape

Do Son February 4, 2025 0
Read More Read more about PoC Releases for Linux Kernel Flaw CVE-2024-36972: Double Free Flaw Enables Privilege Escalation and Container Escape
CVE-2025-23114 (CVSS 9.0): Critical Veeam Backup Vulnerability Enables Remote Code Execution CVE-2024-29849 - CVE-2025-23114
  • Vulnerability

CVE-2025-23114 (CVSS 9.0): Critical Veeam Backup Vulnerability Enables Remote Code Execution

Do Son February 4, 2025 0
Read More Read more about CVE-2025-23114 (CVSS 9.0): Critical Veeam Backup Vulnerability Enables Remote Code Execution
Google Fixes High-Severity Chrome Vulnerabilities (CVE-2025-0444 & CVE-2025-0445) Chrome 133 - CVE-2025-0444 & CVE-2025-0445
  • Vulnerability

Google Fixes High-Severity Chrome Vulnerabilities (CVE-2025-0444 & CVE-2025-0445)

Do Son February 4, 2025 0
Read More Read more about Google Fixes High-Severity Chrome Vulnerabilities (CVE-2025-0444 & CVE-2025-0445)
Coyote Banking Trojan: A Multi-Stage Financial Cyber Threat Targeting Brazil Coyote Banking Trojan
  • Malware

Coyote Banking Trojan: A Multi-Stage Financial Cyber Threat Targeting Brazil

Do Son February 4, 2025 0
Read More Read more about Coyote Banking Trojan: A Multi-Stage Financial Cyber Threat Targeting Brazil
Cybercriminals Exploit Big Tech Cloud IPs in Infrastructure Laundering Scheme infrastructure laundering
  • Cyber Security

Cybercriminals Exploit Big Tech Cloud IPs in Infrastructure Laundering Scheme

Do Son February 4, 2025 0
Read More Read more about Cybercriminals Exploit Big Tech Cloud IPs in Infrastructure Laundering Scheme
CISA Flags Four Actively Exploited Security Vulnerabilities in KEV Catalog CISA KEV Update, Cisco Zero-Day KEV Vulnerabilities
  • Vulnerability

CISA Flags Four Actively Exploited Security Vulnerabilities in KEV Catalog

Do Son February 4, 2025 0
Read More Read more about CISA Flags Four Actively Exploited Security Vulnerabilities in KEV Catalog
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-15340CVSS 9.8
    lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-16516CVSS 9.0
    wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm...
    📅 Updated: Oct 7, 2026
  • CVE-2026-14911CVSS 9.3
    Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker...
    📅 Updated: Oct 7, 2026
  • CVE-2026-19386CVSS 9.3
    A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
  • CVE-2026-104334CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.