Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CISA Flags Four Actively Exploited Security Vulnerabilities in KEV Catalog CISA KEV Update, Cisco Zero-Day KEV Vulnerabilities
  • Vulnerability

CISA Flags Four Actively Exploited Security Vulnerabilities in KEV Catalog

Do Son February 4, 2025 0
Read More Read more about CISA Flags Four Actively Exploited Security Vulnerabilities in KEV Catalog
TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns TAG-124
  • Cyber Security
  • Malware

TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns

Do Son February 4, 2025 0
Read More Read more about TAG-124: A Deep Dive into the Traffic Distribution System Powering Malware Campaigns
Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign Unveiled Iranian Hacktivists Operation Epic Fury Cyber New Generation Warfare Russian Hybrid Escalation Plex data breach Water Systems Cybersecurity - Threat Actor Naming Standard
  • Cyber Security

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign Unveiled

Do Son February 4, 2025 0
Read More Read more about Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign Unveiled
Threat Actors Exploit CVE-2019-18935 to Gain Remote Access and Elevate Privileges CVE-2019-18935
  • Cyber Security
  • Vulnerability

Threat Actors Exploit CVE-2019-18935 to Gain Remote Access and Elevate Privileges

Do Son February 4, 2025 0
Read More Read more about Threat Actors Exploit CVE-2019-18935 to Gain Remote Access and Elevate Privileges
Phishing Campaign Hijacks High-Profile X Accounts to Promote Crypto Scams EU Education Scams, .edu.eu Domain App Store security Refund Schemes - Texas Pharmacist's Fraudulent
  • Cyber Security

Phishing Campaign Hijacks High-Profile X Accounts to Promote Crypto Scams

Do Son February 4, 2025 0
Read More Read more about Phishing Campaign Hijacks High-Profile X Accounts to Promote Crypto Scams
CVE-2025-0411: 7-Zip Vulnerability Exploited in Attacks on Ukraine CVE-2025-0411 PoC exploit - Homoglyph Attacks
  • Cyber Security
  • Vulnerability

CVE-2025-0411: 7-Zip Vulnerability Exploited in Attacks on Ukraine

Do Son February 4, 2025 0
Read More Read more about CVE-2025-0411: 7-Zip Vulnerability Exploited in Attacks on Ukraine
Privilege Escalation in Active Directory Domain Services: CVE-2025-21293 Exploit Revealed with PoC Code CVE-2025-21293 PoC
  • Vulnerability

Privilege Escalation in Active Directory Domain Services: CVE-2025-21293 Exploit Revealed with PoC Code

Do Son February 3, 2025 0
Read More Read more about Privilege Escalation in Active Directory Domain Services: CVE-2025-21293 Exploit Revealed with PoC Code
Tria Stealer: Android Malware Hijacks WhatsApp and Telegram Accounts Delivery
  • Malware

Tria Stealer: Android Malware Hijacks WhatsApp and Telegram Accounts

Do Son February 3, 2025 0
Read More Read more about Tria Stealer: Android Malware Hijacks WhatsApp and Telegram Accounts
CL-STA-0048: Chinese-Linked APT Targets Telecoms in South Asia DPRK IT Workers, APT38 Crypto Forfeiture
  • Cyber Security
  • Malware

CL-STA-0048: Chinese-Linked APT Targets Telecoms in South Asia

Do Son February 3, 2025 0
Read More Read more about CL-STA-0048: Chinese-Linked APT Targets Telecoms in South Asia
Time Bandit: ChatGPT-4o Jailbreak Vulnerability OpenAI Major Outage - Time Bandit GPT-4.5 Phase-Out
  • Vulnerability

Time Bandit: ChatGPT-4o Jailbreak Vulnerability

Do Son February 3, 2025 0
Read More Read more about Time Bandit: ChatGPT-4o Jailbreak Vulnerability
Tiny FUD: Fully Undetectable macOS Backdoor Discovered Tiny FUD backdoor
  • Malware

Tiny FUD: Fully Undetectable macOS Backdoor Discovered

Do Son February 3, 2025 0
Read More Read more about Tiny FUD: Fully Undetectable macOS Backdoor Discovered
HTTP Client Tools Weaponized in Account Takeover Attacks Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security

HTTP Client Tools Weaponized in Account Takeover Attacks

Do Son February 3, 2025 0
Read More Read more about HTTP Client Tools Weaponized in Account Takeover Attacks
10,000 WordPress Websites Compromised to Deliver macOS and Windows Malware SocGholish Windows malware
  • Malware

10,000 WordPress Websites Compromised to Deliver macOS and Windows Malware

Do Son February 3, 2025 0
Read More Read more about 10,000 WordPress Websites Compromised to Deliver macOS and Windows Malware
Lumma Stealer Uses GitHub as a Malware Delivery Platform Artivion cybersecurity - Zero-Day Attacks
  • Malware

Lumma Stealer Uses GitHub as a Malware Delivery Platform

Do Son February 3, 2025 0
Read More Read more about Lumma Stealer Uses GitHub as a Malware Delivery Platform
CVE-2024-53104: Critical Zero-Day Vulnerability Patched in February 2025 Android Security Update Android Zero-Click RCE CVE-2026-0073 Android sideloading CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747 and, CVE-2024-49748
  • Android
  • Vulnerability

CVE-2024-53104: Critical Zero-Day Vulnerability Patched in February 2025 Android Security Update

Do Son February 3, 2025 0
Read More Read more about CVE-2024-53104: Critical Zero-Day Vulnerability Patched in February 2025 Android Security Update
Canadian Hacker Indicted for $65 Million DeFi Exploit Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cyber Security

Canadian Hacker Indicted for $65 Million DeFi Exploit

Do Son February 3, 2025 0
Read More Read more about Canadian Hacker Indicted for $65 Million DeFi Exploit
MediaTek’s February 2025 Security Bulletin: Critical WLAN Vulnerabilities Expose Millions to Remote Attacks MediaTek Modem Vulnerabilities, January 2026 Security Bulletin MediaTek Vulnerabilities, Chipset Security CVE-2024-20103 & CVE-2024-20100 - CVE-2024-20154 - February 2025 Product Security Bulletin
  • Vulnerability

MediaTek’s February 2025 Security Bulletin: Critical WLAN Vulnerabilities Expose Millions to Remote Attacks

Do Son February 3, 2025 0
Read More Read more about MediaTek’s February 2025 Security Bulletin: Critical WLAN Vulnerabilities Expose Millions to Remote Attacks
Cristal Intelligence: SoftBank’s $3B Bet on OpenAI SoftBank OpenAI $41 billion investment, Masayoshi Son AGI wager Cristal Intelligence - SB OpenAI Japan
  • Technology

Cristal Intelligence: SoftBank’s $3B Bet on OpenAI

Do Son February 3, 2025 0
Read More Read more about Cristal Intelligence: SoftBank’s $3B Bet on OpenAI
ChatGPT’s Deep Research: AI-Powered Web Exploration OpenAI Deep Research
  • Technology

ChatGPT’s Deep Research: AI-Powered Web Exploration

Do Son February 3, 2025 0
Read More Read more about ChatGPT’s Deep Research: AI-Powered Web Exploration
CompTIA Linux+: Exploring Its Benefits and Career Paths CompTIA
  • Technique

CompTIA Linux+: Exploring Its Benefits and Career Paths

Do Son February 3, 2025 0
Read More Read more about CompTIA Linux+: Exploring Its Benefits and Career Paths
Sanctions Risk in Open Source: Linux Foundation Offers Guidance Linux Kernel 6.19 AMDGPU update, GCN 1.0 1.1 performance boost Linux Sanctions Risk Linux i486
  • Linux
  • Technology

Sanctions Risk in Open Source: Linux Foundation Offers Guidance

Do Son February 3, 2025 0
Read More Read more about Sanctions Risk in Open Source: Linux Foundation Offers Guidance
Microsoft to Kill its 365 VPN: What You Need to Know student discount Microsoft 365, Intelligent Services Microsoft 365 UWP, App Deprecation Microsoft 365, Startup Boost Windows 10 EOL, Microsoft 365 Support Protocol Deprecation Microsoft 365 Updates, IT Admin Alert Microsoft 365 VPN shut down Microsoft Authenticator, password manager Windows 10 Microsoft 365 Microsoft nonprofit policy, software donations
  • Technology

Microsoft to Kill its 365 VPN: What You Need to Know

Do Son February 3, 2025 0
Read More Read more about Microsoft to Kill its 365 VPN: What You Need to Know
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-59346CVSS 9.3
    VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual...
    📅 Updated: Oct 7, 2026
  • CVE-2026-91140CVSS 9.6
    An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76742CVSS 9.8
    Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote...
    📅 Updated: Oct 7, 2026
  • CVE-2026-55330CVSS 9.8
    In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106417CVSS 9.6
    Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106419CVSS 9.6
    Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106401CVSS 9.6
    Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106414CVSS 9.6
    Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.