Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Subaru’s STARLINK Vulnerability: How Hackers Could Track and Control Vehicles Subaru STARLINK Vulnerability
  • Vulnerability

Subaru’s STARLINK Vulnerability: How Hackers Could Track and Control Vehicles

Do Son January 26, 2025 0
Read More Read more about Subaru’s STARLINK Vulnerability: How Hackers Could Track and Control Vehicles
CVE-2024-50050: Critical Security Flaw in Meta’s Llama-Stack Framework PoC-exploit
  • Vulnerability

CVE-2024-50050: Critical Security Flaw in Meta’s Llama-Stack Framework

Do Son January 25, 2025 0
Read More Read more about CVE-2024-50050: Critical Security Flaw in Meta’s Llama-Stack Framework
HellCat and Morpheus: Ransomware Affiliates Using Identical Payloads to Escalate Attacks HellCat & Morpheus ransomware
  • Malware

HellCat and Morpheus: Ransomware Affiliates Using Identical Payloads to Escalate Attacks

Do Son January 25, 2025 0
Read More Read more about HellCat and Morpheus: Ransomware Affiliates Using Identical Payloads to Escalate Attacks
Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks CVE-2024-53299
  • Vulnerability

Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks

Do Son January 25, 2025 0
Read More Read more about Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks
QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution backConnect malware
  • Malware

QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution

Do Son January 25, 2025 0
Read More Read more about QBot Resurfaces: New BackConnect Malware Signals a Dangerous Evolution
North Korean IT Workers Indicted in Elaborate “Laptop Farm” Scheme to Evade Sanctions North Korean Laptop Farm DPRK Insider Threat North Korea WMD Cyber Funding, Australia Sanctions Insider threat, North Korean hackers Kimsuky, cyber-espionage NPM Malware, North Korea Cyber-espionage North Korea, Remote IT Job Scam Laptop Farm - DriverEasy - Kimsuky Watering Hole Attack
  • Cyber Security

North Korean IT Workers Indicted in Elaborate “Laptop Farm” Scheme to Evade Sanctions

Do Son January 24, 2025 0
Read More Read more about North Korean IT Workers Indicted in Elaborate “Laptop Farm” Scheme to Evade Sanctions
Lumma Stealer Malware Now Using ChaCha20 Cipher for Evasion ChaCha20 Cipher
  • Malware

Lumma Stealer Malware Now Using ChaCha20 Cipher for Evasion

Do Son January 24, 2025 0
Read More Read more about Lumma Stealer Malware Now Using ChaCha20 Cipher for Evasion
Popular WordPress Real Estate Theme Vulnerable to Complete Site Takeover, No Patch CVE-2024-32444 & CVE-2024-32555
  • Vulnerability

Popular WordPress Real Estate Theme Vulnerable to Complete Site Takeover, No Patch

Do Son January 24, 2025 0
Read More Read more about Popular WordPress Real Estate Theme Vulnerable to Complete Site Takeover, No Patch
Android Boosts Anti-Theft Measures with AI and Biometric Security Android security, anti-theft backup Android Identity Check & Theft Detection Lock
  • Android
  • Technology

Android Boosts Anti-Theft Measures with AI and Biometric Security

Do Son January 24, 2025 0
Read More Read more about Android Boosts Anti-Theft Measures with AI and Biometric Security
Social Media Marketing: Definition, Significance, and Strategic Insights email-4284157_1280
  • Technique

Social Media Marketing: Definition, Significance, and Strategic Insights

Do Son January 24, 2025 0
Read More Read more about Social Media Marketing: Definition, Significance, and Strategic Insights
CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code CVE-2024-43468 PoC exploit
  • Vulnerability

CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code

Do Son January 23, 2025 0
Read More Read more about CVE-2024-43468 (CVSS 9.8): Microsoft Configuration Manager Exploit Revealed with PoC Code
CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution CVE-2025-21535 Oracle EBS RCE, CVE-2025-61882
  • Vulnerability

CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution

Do Son January 23, 2025 0
Read More Read more about CVE-2025-21535 (CVSS 9.8): Vulnerability in Oracle WebLogic Server Could Lead to Remote Code Execution
Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies Malicious VS Code Extension
  • Malware

Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies

Do Son January 23, 2025 0
Read More Read more about Malicious VS Code Extension Masquerades as Zoom to Steal Chrome Cookies
CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information CVE-2024-43707 Kibana vulnerability Prototype pollution CVE-2025-25014
  • Vulnerability

CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information

Do Son January 23, 2025 0
Read More Read more about CVE-2024-43707: Kibana Patches High Severity Vulnerability Exposing Sensitive Information
Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps Credential Harvesting
  • Cyber Security

Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps

Do Son January 23, 2025 0
Read More Read more about Beyond DocuSign: Credential Harvesting Now Targets a Wider Range of Cloud Apps
Donot APT Group Targets Android Devices with Malicious Chat Apps Donot APT Group - Android zero-day
  • Malware

Donot APT Group Targets Android Devices with Malicious Chat Apps

Do Son January 23, 2025 0
Read More Read more about Donot APT Group Targets Android Devices with Malicious Chat Apps
2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar Payment Fraud Report
  • Cyber Security

2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar

Do Son January 23, 2025 0
Read More Read more about 2024 Payment Fraud Report: E-Skimming, Check Fraud, and Threat Actor Sophistication Soar
phpMyAdmin Patches XSS Vulnerabilities in Latest Release phpMyAdmin Vulnerabilities
  • Vulnerability

phpMyAdmin Patches XSS Vulnerabilities in Latest Release

Do Son January 23, 2025 0
Read More Read more about phpMyAdmin Patches XSS Vulnerabilities in Latest Release
CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Malware
  • Vulnerability

CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks

Do Son January 23, 2025 0
Read More Read more about CVE-2024-7029 and CVE-2017-17215 Exploited in Latest Murdoc Botnet Attacks
Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Malware

Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi

Do Son January 23, 2025 0
Read More Read more about Stealthy and Persistent: New Ransomware Tactics Target VMware ESXi
STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Cyber Security

STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users

Do Son January 23, 2025 0
Read More Read more about STAC5143 and STAC5777: New Ransomware Campaigns Target Microsoft Office 365 Users
CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users SonicWall Security Advisory SonicOS Patch 2026 CVE-2025-23006 SonicWall, SMA 100 Vulnerabilities
  • Vulnerability

CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users

Do Son January 23, 2025 0
Read More Read more about CVE-2025-23006 (CVSS 9.8): SonicWall Warns of Active Exploits, Issues Urgent Update for SMA1000 Users
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-59346CVSS 9.3
    VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual...
    📅 Updated: Oct 7, 2026
  • CVE-2025-52691CVSS 10.0
    Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on...
    CISA KEV📅 Added to KEV: Jan 26, 2026📅 Updated: Oct 7, 2026
  • CVE-2025-57460CVSS 9.8
    File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
    📅 Updated: Oct 7, 2026
  • CVE-2025-68897CVSS 9.9
    Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows...
    📅 Updated: Oct 7, 2026
  • CVE-2025-68562CVSS 9.9
    Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a...
    📅 Updated: Oct 7, 2026
  • CVE-2025-69234CVSS 9.1
    Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
    📅 Updated: Oct 7, 2026
  • CVE-2025-15102CVSS 9.1
    DVP-12SE11T - Password Protection Bypass
    📅 Updated: Oct 7, 2026
  • CVE-2025-15359CVSS 9.1
    DVP-12SE11T - Out-of-bound memory write Vulnerability
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.