Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8) Apple Background Security CVE-2026-20643 Apple Background Security Improvement Apple Backdoor Apple Lawsuit, Data Exfiltration CVE-2024-44131 - CVE-2025-24118 PoC
  • Vulnerability

PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8)

Do Son February 2, 2025 0
Read More Read more about PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8)
North Korean APT Lazarus Uses Malicious npm Package to Target Developers North Korean APT Lazarus
  • Malware

North Korean APT Lazarus Uses Malicious npm Package to Target Developers

Do Son February 2, 2025 0
Read More Read more about North Korean APT Lazarus Uses Malicious npm Package to Target Developers
CVE-2024-57376: End-of-Life D-Link Routers Vulnerable to Unauthenticated RCE CVE-2024-57376 - DSL-3788 Router Vulnerability
  • Vulnerability

CVE-2024-57376: End-of-Life D-Link Routers Vulnerable to Unauthenticated RCE

Do Son February 2, 2025 0
Read More Read more about CVE-2024-57376: End-of-Life D-Link Routers Vulnerable to Unauthenticated RCE
Devil-Traff: The New SMS Phishing Platform Exploited by Cybercriminals Devil-Traff
  • Cyber Security

Devil-Traff: The New SMS Phishing Platform Exploited by Cybercriminals

Do Son February 2, 2025 0
Read More Read more about Devil-Traff: The New SMS Phishing Platform Exploited by Cybercriminals
CVE-2025-0477 (CVSS 9.8): Critical Security Flaw in Rockwell Automation’s FactoryTalk AssetCentre Rockwell Automation Warning OT Security Rockwell SQLi, Industrial Safety DoS Verve Asset Manager API OT Privilege Escalation Rockwell NAT Router, Critical Auth Bypass Rockwell ICS Privilege Escalation, MSI Repair Attack CVE-2025-7353 Critical vulnerability, industrial control systems Rockwell vulnerability, ICS security Rockwell Arena, Memory Abuse Rockwell Automation, RCE Vulnerability CVE-2025-24479 and CVE-2025-24480 - CVE-2025-0477
  • Vulnerability

CVE-2025-0477 (CVSS 9.8): Critical Security Flaw in Rockwell Automation’s FactoryTalk AssetCentre

Do Son February 2, 2025 0
Read More Read more about CVE-2025-0477 (CVSS 9.8): Critical Security Flaw in Rockwell Automation’s FactoryTalk AssetCentre
The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users Malicious AdTech
  • Cyber Security

The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users

Do Son February 2, 2025 0
Read More Read more about The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users
CVE-2025-0851 (CVSS 9.8): Deep Java Library Vulnerability Allows Path Traversal Exploits CVE-2025-0851
  • Vulnerability

CVE-2025-0851 (CVSS 9.8): Deep Java Library Vulnerability Allows Path Traversal Exploits

Do Son February 2, 2025 0
Read More Read more about CVE-2025-0851 (CVSS 9.8): Deep Java Library Vulnerability Allows Path Traversal Exploits
SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security
  • Malware

SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond

Do Son February 2, 2025 0
Read More Read more about SparkRAT: A Persistent Cross-Platform Cyber Threat Targeting macOS and Beyond
.Gov No More: Government Domains Weaponized in Phishing Surge Layoff Phishing Scam Remcos RAT Malware Aruba Phishing, Phishing-as-a-Service PyPI, phishing CVE-2024-25608 PyPI Phishing, Credential Theft
  • Cyber Security
  • Vulnerability

.Gov No More: Government Domains Weaponized in Phishing Surge

Do Son February 2, 2025 0
Read More Read more about .Gov No More: Government Domains Weaponized in Phishing Surge
Unrestricted Access: A Simple Web Misconfiguration Exposes Critical Data Web Misconfiguration
  • Data Leak

Unrestricted Access: A Simple Web Misconfiguration Exposes Critical Data

Do Son February 2, 2025 0
Read More Read more about Unrestricted Access: A Simple Web Misconfiguration Exposes Critical Data
CISA Warns of Hidden Backdoor in Contec CMS8000 Patient Monitors Contec CMS8000 backdoor - CVE-2025-0626 ,CVE-2025-0683
  • Vulnerability

CISA Warns of Hidden Backdoor in Contec CMS8000 Patient Monitors

Do Son February 2, 2025 0
Read More Read more about CISA Warns of Hidden Backdoor in Contec CMS8000 Patient Monitors
Adversarial Misuse of Generative AI: How APTs Are Experimenting with AI for Cyber Operations illegal streaming networks complex criminal enterprises UAT-7290 China-nexus Espionage Adversarial Misuse of Generative AI
  • Cyber Security

Adversarial Misuse of Generative AI: How APTs Are Experimenting with AI for Cyber Operations

Do Son February 1, 2025 0
Read More Read more about Adversarial Misuse of Generative AI: How APTs Are Experimenting with AI for Cyber Operations
CVE-2024-56529: mailcow Patches Session Fixation Vulnerability in Web Panel CVE-2024-56529 - CVE-2025-25198
  • Vulnerability

CVE-2024-56529: mailcow Patches Session Fixation Vulnerability in Web Panel

Do Son February 1, 2025 0
Read More Read more about CVE-2024-56529: mailcow Patches Session Fixation Vulnerability in Web Panel
Fake Game Hacks on YouTube Target Kids with Malware Fake Game Hacks
  • Malware

Fake Game Hacks on YouTube Target Kids with Malware

Do Son February 1, 2025 0
Read More Read more about Fake Game Hacks on YouTube Target Kids with Malware
CVE-2025-24480 (CVSS 9.8): Rockwell Automation Addresses Critical Flaw in FactoryTalk View ME Rockwell Automation Warning OT Security Rockwell SQLi, Industrial Safety DoS Verve Asset Manager API OT Privilege Escalation Rockwell NAT Router, Critical Auth Bypass Rockwell ICS Privilege Escalation, MSI Repair Attack CVE-2025-7353 Critical vulnerability, industrial control systems Rockwell vulnerability, ICS security Rockwell Arena, Memory Abuse Rockwell Automation, RCE Vulnerability CVE-2025-24479 and CVE-2025-24480 - CVE-2025-0477
  • Vulnerability

CVE-2025-24480 (CVSS 9.8): Rockwell Automation Addresses Critical Flaw in FactoryTalk View ME

Do Son February 1, 2025 0
Read More Read more about CVE-2025-24480 (CVSS 9.8): Rockwell Automation Addresses Critical Flaw in FactoryTalk View ME
Best Cloud Mining Platform in 2025, Easily Earn $30,000 Daily CVE-2024-55563 - transaction-relay jamming attack
  • Technique

Best Cloud Mining Platform in 2025, Easily Earn $30,000 Daily

Do Son February 1, 2025 0
Read More Read more about Best Cloud Mining Platform in 2025, Easily Earn $30,000 Daily
CVE-2024-55417: One-Click RCE Vulnerability in Voyager Admin Panel, No Patch CVE-2024-55417
  • Vulnerability

CVE-2024-55417: One-Click RCE Vulnerability in Voyager Admin Panel, No Patch

Do Son January 31, 2025 0
Read More Read more about CVE-2024-55417: One-Click RCE Vulnerability in Voyager Admin Panel, No Patch
Cyber Espionage and Influence: Unmasking APT28’s Tactics Sources and related content APT28 report
  • Cyber Security

Cyber Espionage and Influence: Unmasking APT28’s Tactics Sources and related content

Do Son January 31, 2025 0
Read More Read more about Cyber Espionage and Influence: Unmasking APT28’s Tactics Sources and related content
CVE-2024-7695: Moxa Patches Critical Denial-of-Service Vulnerability in PT Switches Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability

CVE-2024-7695: Moxa Patches Critical Denial-of-Service Vulnerability in PT Switches

Do Son January 31, 2025 0
Read More Read more about CVE-2024-7695: Moxa Patches Critical Denial-of-Service Vulnerability in PT Switches
CVE-2024-53704 – Authentication Bypass in SonicOS: PoC Published CVE-2024-53704 PoC exploit
  • Vulnerability

CVE-2024-53704 – Authentication Bypass in SonicOS: PoC Published

Do Son January 30, 2025 0
Read More Read more about CVE-2024-53704 – Authentication Bypass in SonicOS: PoC Published
D-Link Patches Critical Remote Code Execution Vulnerability in DSL-3788 Router CVE-2024-57376 - DSL-3788 Router Vulnerability
  • Vulnerability

D-Link Patches Critical Remote Code Execution Vulnerability in DSL-3788 Router

Do Son January 30, 2025 0
Read More Read more about D-Link Patches Critical Remote Code Execution Vulnerability in DSL-3788 Router
Google Play Protect: Safeguarding Billions of Users in 2024 Google Play Protect
  • Android
  • Technology

Google Play Protect: Safeguarding Billions of Users in 2024

Do Son January 30, 2025 0
Read More Read more about Google Play Protect: Safeguarding Billions of Users in 2024
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-59346CVSS 9.3
    VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual...
    📅 Updated: Oct 7, 2026
  • CVE-2026-91140CVSS 9.6
    An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76742CVSS 9.8
    Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote...
    📅 Updated: Oct 7, 2026
  • CVE-2026-55330CVSS 9.8
    In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106417CVSS 9.6
    Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106419CVSS 9.6
    Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106401CVSS 9.6
    Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106414CVSS 9.6
    Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.