Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2024-52320 and More: Planet Switches Expose Networks to Attack Screenshot 2025-01-20 161709
  • Vulnerability

CVE-2024-52320 and More: Planet Switches Expose Networks to Attack

Do Son January 21, 2025 0
Read More Read more about CVE-2024-52320 and More: Planet Switches Expose Networks to Attack
From Dream Jobs to Dangerous Passwords: Lazarus Group’s LinkedIn Attacks Operation Dream Job
  • Cyber Security

From Dream Jobs to Dangerous Passwords: Lazarus Group’s LinkedIn Attacks

Do Son January 21, 2025 0
Read More Read more about From Dream Jobs to Dangerous Passwords: Lazarus Group’s LinkedIn Attacks
Black Myth: Wukong DDoS Attackers Return with New AIRASHI Botnet AISURU botnet, known as AIRASHI
  • Malware

Black Myth: Wukong DDoS Attackers Return with New AIRASHI Botnet

Do Son January 21, 2025 0
Read More Read more about Black Myth: Wukong DDoS Attackers Return with New AIRASHI Botnet
NTLMv1 Group Policy Bypass Discovered: A Wake-Up Call for Active Directory Administrators Screenshot 2025-01-18 164933
  • Vulnerability

NTLMv1 Group Policy Bypass Discovered: A Wake-Up Call for Active Directory Administrators

Do Son January 21, 2025 0
Read More Read more about NTLMv1 Group Policy Bypass Discovered: A Wake-Up Call for Active Directory Administrators
DLL Sideloading & Proxying: New Campaign Delivers Sliver Implants to German Targets exfiltrating AWS credentials - fabrice package
  • Cyber Security

DLL Sideloading & Proxying: New Campaign Delivers Sliver Implants to German Targets

Do Son January 21, 2025 0
Read More Read more about DLL Sideloading & Proxying: New Campaign Delivers Sliver Implants to German Targets
Meta’s Advertising System Exploited by Russian Propaganda Network Meta Horizon Worlds Quest shutdown Meta AI, Child Safety Meta Robotics, Android of Robotics Meta AI, Llama 4.X Meta, AI regulation Meta AI, Data Center Impact Meta AI, Superintelligence Meta Copyrighted Data AI chatbot
  • Cyber Security

Meta’s Advertising System Exploited by Russian Propaganda Network

Do Son January 21, 2025 0
Read More Read more about Meta’s Advertising System Exploited by Russian Propaganda Network
ModiLoader Malware Leveraging CAB Header Batch Files to Evade Detection SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Malware

ModiLoader Malware Leveraging CAB Header Batch Files to Evade Detection

Do Son January 21, 2025 0
Read More Read more about ModiLoader Malware Leveraging CAB Header Batch Files to Evade Detection
TikTok’s U.S. Ban Postponed: ByteDance Scrambles for a Long-Term Solution TikTok's U.S. Ban Postponed
  • Technology

TikTok’s U.S. Ban Postponed: ByteDance Scrambles for a Long-Term Solution

Do Son January 21, 2025 0
Read More Read more about TikTok’s U.S. Ban Postponed: ByteDance Scrambles for a Long-Term Solution
Homebrew Phishing Site Appears in Google Search, Raising Concerns Homebrew Phishing Site
  • Malware

Homebrew Phishing Site Appears in Google Search, Raising Concerns

Do Son January 21, 2025 0
Read More Read more about Homebrew Phishing Site Appears in Google Search, Raising Concerns
KB5052819: Fixing Boot Issues on Windows Server 2022 Windows 10 extended support Windows 10 MSMQ Bug, KB5071546 Write Permissions Windows 10 EOL, LTSB Support Windows User Base, Active Devices KB5052819
  • Windows

KB5052819: Fixing Boot Issues on Windows Server 2022

Do Son January 21, 2025 0
Read More Read more about KB5052819: Fixing Boot Issues on Windows Server 2022
Google Requires JavaScript for Search: Bots and Crawlers Impacted Google Search JavaScript
  • Technology

Google Requires JavaScript for Search: Bots and Crawlers Impacted

Do Son January 21, 2025 0
Read More Read more about Google Requires JavaScript for Search: Bots and Crawlers Impacted
Top 3 Malware Targeting Businesses in the Last 12 Months Top Malware
  • Malware

Top 3 Malware Targeting Businesses in the Last 12 Months

Do Son January 21, 2025 0
Read More Read more about Top 3 Malware Targeting Businesses in the Last 12 Months
CVE-2025-0411: 7-Zip Security Vulnerability Enables Code Execution – Update Now 7-Zip heap buffer overflow CVE-2025-0411 7-Zip path traversal
  • Vulnerability

CVE-2025-0411: 7-Zip Security Vulnerability Enables Code Execution – Update Now

Do Son January 20, 2025 0
Read More Read more about CVE-2025-0411: 7-Zip Security Vulnerability Enables Code Execution – Update Now
TP-Link Vulnerability: PoC Exploit for CVE-2024-54887 Reveals Remote Code Execution Risks CVE-2024-54887 PoC exploit
  • Vulnerability

TP-Link Vulnerability: PoC Exploit for CVE-2024-54887 Reveals Remote Code Execution Risks

Do Son January 20, 2025 0
Read More Read more about TP-Link Vulnerability: PoC Exploit for CVE-2024-54887 Reveals Remote Code Execution Risks
CVE-2025-22146 (CVSS 9.1): Critical Sentry Vulnerability Allowed Account Takeovers CVE-2025-22146
  • Vulnerability

CVE-2025-22146 (CVSS 9.1): Critical Sentry Vulnerability Allowed Account Takeovers

Do Son January 20, 2025 0
Read More Read more about CVE-2025-22146 (CVSS 9.1): Critical Sentry Vulnerability Allowed Account Takeovers
IntelBroker’s Digital Trail: OSINT Analysis Exposes Cybercriminal’s Operations TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Cyber Security
  • Data Leak

IntelBroker’s Digital Trail: OSINT Analysis Exposes Cybercriminal’s Operations

Do Son January 20, 2025 0
Read More Read more about IntelBroker’s Digital Trail: OSINT Analysis Exposes Cybercriminal’s Operations
Bluesky Launches Trending Videos to Compete with TikTok’s Short-Video Market Bluesky Trending Videos
  • Technology

Bluesky Launches Trending Videos to Compete with TikTok’s Short-Video Market

Do Son January 20, 2025 0
Read More Read more about Bluesky Launches Trending Videos to Compete with TikTok’s Short-Video Market
IBM Sterling Secure Proxy Faces Multiple Critical Vulnerabilities: A Call for Immediate Action CVE-2024-41783 & CVE-2024-38337
  • Vulnerability

IBM Sterling Secure Proxy Faces Multiple Critical Vulnerabilities: A Call for Immediate Action

Do Son January 20, 2025 0
Read More Read more about IBM Sterling Secure Proxy Faces Multiple Critical Vulnerabilities: A Call for Immediate Action
Gootloader Malware Expands Its Reach with Advanced Social Engineering and SEO Poisoning SloppyLemming
  • Malware

Gootloader Malware Expands Its Reach with Advanced Social Engineering and SEO Poisoning

Do Son January 20, 2025 0
Read More Read more about Gootloader Malware Expands Its Reach with Advanced Social Engineering and SEO Poisoning
OWASP Unveils Top 10 Smart Contract Vulnerabilities for 2025 O
  • Vulnerability

OWASP Unveils Top 10 Smart Contract Vulnerabilities for 2025

Do Son January 20, 2025 0
Read More Read more about OWASP Unveils Top 10 Smart Contract Vulnerabilities for 2025
MintsLoader Campaign Targets Critical Sectors with Sophisticated Malware Delivery StealC operator panel
  • Malware

MintsLoader Campaign Targets Critical Sectors with Sophisticated Malware Delivery

Do Son January 20, 2025 0
Read More Read more about MintsLoader Campaign Targets Critical Sectors with Sophisticated Malware Delivery
US Sanctions Chinese Hackers for Cyber Espionage Campaign IARPA Research Security Data Abyss Report Telecom threat, Secret Service cybersecurity news - Cyber Espionage Campaign
  • Cyber Security

US Sanctions Chinese Hackers for Cyber Espionage Campaign

Do Son January 20, 2025 0
Read More Read more about US Sanctions Chinese Hackers for Cyber Espionage Campaign
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-106446CVSS 9.8
    Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106501CVSS 9.6
    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102115CVSS 9.8
    Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who...
    📅 Updated: Oct 7, 2026
  • CVE-2026-107194CVSS 9.2
    Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106239CVSS 9.6
    Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 7, 2026
  • CVE-2026-106241CVSS 9.6
    Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging...
    📅 Updated: Oct 7, 2026
  • CVE-2026-62874CVSS 10.0
    Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
    📅 Updated: Oct 7, 2026
  • CVE-2026-106372CVSS 9.6
    Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.