Skip to content
September 25, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection CVE-2025-23061
  • Vulnerability

CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection

Do Son January 19, 2025 0
Read More Read more about CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection
Malicious PyPI Package Targets Discord Developers with Token Theft and Backdoor Exploit Malicious Discord PyPI Package
  • Malware

Malicious PyPI Package Targets Discord Developers with Token Theft and Backdoor Exploit

Do Son January 19, 2025 0
Read More Read more about Malicious PyPI Package Targets Discord Developers with Token Theft and Backdoor Exploit
Sneaky 2FA: A New Adversary-in-the-Middle Phishing-as-a-Service Threat micro
  • Cyber Security

Sneaky 2FA: A New Adversary-in-the-Middle Phishing-as-a-Service Threat

Do Son January 19, 2025 0
Read More Read more about Sneaky 2FA: A New Adversary-in-the-Middle Phishing-as-a-Service Threat
Black Basta Exploits Microsoft Teams for Phishing Attacks SloppyLemming
  • Cyber Security
  • Malware

Black Basta Exploits Microsoft Teams for Phishing Attacks

Do Son January 19, 2025 0
Read More Read more about Black Basta Exploits Microsoft Teams for Phishing Attacks
Critical Vulnerabilities in QNX Software Development Platform Image Codecs Expose Systems to Attacks CVE-2024-48856
  • Vulnerability

Critical Vulnerabilities in QNX Software Development Platform Image Codecs Expose Systems to Attacks

Do Son January 19, 2025 0
Read More Read more about Critical Vulnerabilities in QNX Software Development Platform Image Codecs Expose Systems to Attacks
Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns Truth Social Fraud
  • Cyber Security

Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns

Do Son January 19, 2025 0
Read More Read more about Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns
IoT Botnet Fuels Large-Scale DDoS Attacks Targeting Global Organizations IoT Botnet
  • Malware

IoT Botnet Fuels Large-Scale DDoS Attacks Targeting Global Organizations

Do Son January 19, 2025 0
Read More Read more about IoT Botnet Fuels Large-Scale DDoS Attacks Targeting Global Organizations
State Management Architecture. Part 2. From RTK Query to Zustand CVE-2024-31070 & CVE-2024-36491
  • Technique

State Management Architecture. Part 2. From RTK Query to Zustand

Dan Agbo January 19, 2025
Read More Read more about State Management Architecture. Part 2. From RTK Query to Zustand
Cyber Security Services: Protecting Your Business in the Digital Age web-8989999_1280
  • Technique

Cyber Security Services: Protecting Your Business in the Digital Age

Do Son January 19, 2025 0
Read More Read more about Cyber Security Services: Protecting Your Business in the Digital Age
CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability

CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series

Do Son January 18, 2025 0
Read More Read more about CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series
Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Malware

Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique

Do Son January 18, 2025 0
Read More Read more about Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique
CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
  • Cyber Security
  • Vulnerability

CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks

Do Son January 18, 2025 0
Read More Read more about CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks
CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw Undertow Vulnerability CVE-2025-12543 CVE-2025-0107: PoC Exploit Code Undersea Cable Security, China Tech Ban
  • Vulnerability

CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw

Do Son January 17, 2025 0
Read More Read more about CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw
Real Estate Scams on the Rise in the Middle East TASPEN, mobile malware North Korean IT Worker Fraud
  • Cyber Security

Real Estate Scams on the Rise in the Middle East

Do Son January 17, 2025 0
Read More Read more about Real Estate Scams on the Rise in the Middle East
CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw CVE-2024-53691 PoC exploit
  • Vulnerability

CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw

Do Son January 16, 2025 0
Read More Read more about CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw
Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package CVE-2025-23013
  • Vulnerability

Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package

Do Son January 16, 2025 0
Read More Read more about Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package
The Rise of AI Search: Google Search Market Share Dips Below 90% Google Arkansas Investment, AI Data Center Google, privacy fine Ecosia Google Chrome Alphabet Earnings, AI Growth Google Hydropower, AI Data Centers Google Breakup Antitrust Workspace Flows Google Workspace Google remote work, return to office
  • Technology

The Rise of AI Search: Google Search Market Share Dips Below 90%

Do Son January 16, 2025 0
Read More Read more about The Rise of AI Search: Google Search Market Share Dips Below 90%
Microsoft 365 Drops Windows 10: What You Need to Know Before the Deadline Microsoft 365 Windows 10
  • Technology
  • Windows

Microsoft 365 Drops Windows 10: What You Need to Know Before the Deadline

Do Son January 16, 2025 0
Read More Read more about Microsoft 365 Drops Windows 10: What You Need to Know Before the Deadline
HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems CVE-2024-26305 _ CVE-2025-23058 Aruba 5G Core Open Redirect
  • Vulnerability

HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems

Do Son January 16, 2025 0
Read More Read more about HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems
AWS Patches Vulnerabilities in WorkSpaces, AppStream 2.0, and DCV Clients WorkSpaces Token Leak, Local Privilege Escalation CVE-2025-0500 & CVE-2025-0501
  • Vulnerability

AWS Patches Vulnerabilities in WorkSpaces, AppStream 2.0, and DCV Clients

Do Son January 16, 2025 0
Read More Read more about AWS Patches Vulnerabilities in WorkSpaces, AppStream 2.0, and DCV Clients
CVE-2024-52281: Rancher Vulnerability Exposes Users to Stored XSS Attacks CVE-2024-52281 Rancher CLI Vulnerability CVE-2025-67601
  • Vulnerability

CVE-2024-52281: Rancher Vulnerability Exposes Users to Stored XSS Attacks

Do Son January 16, 2025 0
Read More Read more about CVE-2024-52281: Rancher Vulnerability Exposes Users to Stored XSS Attacks
Is Google Too Big? CMA Investigates Search Giant Competition and Markets Authority Google
  • Technology

Is Google Too Big? CMA Investigates Search Giant

Do Son January 16, 2025 0
Read More Read more about Is Google Too Big? CMA Investigates Search Giant
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-85102CVSS 9.8
    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93616CVSS 9.8
    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
  • CVE-2026-93952CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-86860CVSS 9.3
    ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could...
    📅 Updated: Sep 25, 2026
  • CVE-2026-78445CVSS 9.8
    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code...
    📅 Updated: Sep 24, 2026
  • CVE-2026-77493CVSS 9.8
    Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-73025CVSS 9.8
    Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-73009CVSS 9.8
    Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over...
    📅 Updated: Sep 24, 2026
  • CVE-2026-72979CVSS 9.8
    Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-72982CVSS 9.8
    Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
    📅 Updated: Sep 24, 2026
  • CVE-2026-72983CVSS 9.8
    Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a...
    📅 Updated: Sep 24, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.