Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
US Sanctions Chinese Hackers for Cyber Espionage Campaign IARPA Research Security Data Abyss Report Telecom threat, Secret Service cybersecurity news - Cyber Espionage Campaign
  • Cyber Security

US Sanctions Chinese Hackers for Cyber Espionage Campaign

Do Son January 20, 2025 0
Read More Read more about US Sanctions Chinese Hackers for Cyber Espionage Campaign
Silver Fox APT Targets Organizations with PNGPlug and ValleyRAT Malware WHILL Wheelchair Hijacking, CVE-2025-14346 MAS typosquatting malware, get.activate.win vs get.activated.win OpenShift GitOps RCE, Cluster Takeover Flaw Twonky Server, CVE-2025-13315 AI agents CVE-2024-52875 PoC
  • Cyber Security
  • Malware

Silver Fox APT Targets Organizations with PNGPlug and ValleyRAT Malware

Do Son January 20, 2025 0
Read More Read more about Silver Fox APT Targets Organizations with PNGPlug and ValleyRAT Malware
Exploring the AI-Powered Windows Search Copilot+ PCs Feature Task Manager Ghost Process WinRE Input Fix Windows Search Copilot+ PCs
  • Windows

Exploring the AI-Powered Windows Search Copilot+ PCs Feature

Do Son January 20, 2025 0
Read More Read more about Exploring the AI-Powered Windows Search Copilot+ PCs Feature
Oracle’s January 2025 Critical Patch Update: Addressing 320 Security Vulnerabilities Oracle Critical Patch Update 2025
  • Vulnerability

Oracle’s January 2025 Critical Patch Update: Addressing 320 Security Vulnerabilities

Do Son January 20, 2025 0
Read More Read more about Oracle’s January 2025 Critical Patch Update: Addressing 320 Security Vulnerabilities
ChatGPT Crawler Vulnerability: DDoS Attacks via HTTP Requests ChatGPT Crawler Vulnerability
  • Vulnerability

ChatGPT Crawler Vulnerability: DDoS Attacks via HTTP Requests

Do Son January 20, 2025 0
Read More Read more about ChatGPT Crawler Vulnerability: DDoS Attacks via HTTP Requests
o3-mini: OpenAI’s New AI Model Coming Soon o3-mini GPT-5 GPT-4 retirement, GPT-4o ChatGPT quota, OpenAI update
  • Technology

o3-mini: OpenAI’s New AI Model Coming Soon

Do Son January 20, 2025 0
Read More Read more about o3-mini: OpenAI’s New AI Model Coming Soon
TikTok Ban Extended as Trump Pushes for U.S. Equity in Joint Venture TikTok acquisition TikTok, U.S.-China deal TikTok M2, US DivestmentTrump saves TikTok
  • Technology

TikTok Ban Extended as Trump Pushes for U.S. Equity in Joint Venture

Do Son January 19, 2025 0
Read More Read more about TikTok Ban Extended as Trump Pushes for U.S. Equity in Joint Venture
Zero-Day Vulnerability in Windows Exploited: CVE-2024-49138 PoC Code Released CVE-2024-49138 PoC
  • Vulnerability
  • Windows

Zero-Day Vulnerability in Windows Exploited: CVE-2024-49138 PoC Code Released

Do Son January 19, 2025 0
Read More Read more about Zero-Day Vulnerability in Windows Exploited: CVE-2024-49138 PoC Code Released
Star Blizzard Shifts Tactics: Spear-Phishing Campaign Targets WhatsApp Accounts AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Cyber Security

Star Blizzard Shifts Tactics: Spear-Phishing Campaign Targets WhatsApp Accounts

Do Son January 19, 2025 0
Read More Read more about Star Blizzard Shifts Tactics: Spear-Phishing Campaign Targets WhatsApp Accounts
CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection CVE-2025-23061
  • Vulnerability

CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection

Do Son January 19, 2025 0
Read More Read more about CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection
Malicious PyPI Package Targets Discord Developers with Token Theft and Backdoor Exploit Malicious Discord PyPI Package
  • Malware

Malicious PyPI Package Targets Discord Developers with Token Theft and Backdoor Exploit

Do Son January 19, 2025 0
Read More Read more about Malicious PyPI Package Targets Discord Developers with Token Theft and Backdoor Exploit
Sneaky 2FA: A New Adversary-in-the-Middle Phishing-as-a-Service Threat micro
  • Cyber Security

Sneaky 2FA: A New Adversary-in-the-Middle Phishing-as-a-Service Threat

Do Son January 19, 2025 0
Read More Read more about Sneaky 2FA: A New Adversary-in-the-Middle Phishing-as-a-Service Threat
Black Basta Exploits Microsoft Teams for Phishing Attacks SloppyLemming
  • Cyber Security
  • Malware

Black Basta Exploits Microsoft Teams for Phishing Attacks

Do Son January 19, 2025 0
Read More Read more about Black Basta Exploits Microsoft Teams for Phishing Attacks
Critical Vulnerabilities in QNX Software Development Platform Image Codecs Expose Systems to Attacks CVE-2024-48856
  • Vulnerability

Critical Vulnerabilities in QNX Software Development Platform Image Codecs Expose Systems to Attacks

Do Son January 19, 2025 0
Read More Read more about Critical Vulnerabilities in QNX Software Development Platform Image Codecs Expose Systems to Attacks
Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns Truth Social Fraud
  • Cyber Security

Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns

Do Son January 19, 2025 0
Read More Read more about Scammers Exploit Truth Social to Launch Phishing and Fraud Campaigns
IoT Botnet Fuels Large-Scale DDoS Attacks Targeting Global Organizations IoT Botnet
  • Malware

IoT Botnet Fuels Large-Scale DDoS Attacks Targeting Global Organizations

Do Son January 19, 2025 0
Read More Read more about IoT Botnet Fuels Large-Scale DDoS Attacks Targeting Global Organizations
State Management Architecture. Part 2. From RTK Query to Zustand CVE-2024-31070 & CVE-2024-36491
  • Technique

State Management Architecture. Part 2. From RTK Query to Zustand

Dan Agbo January 19, 2025
Read More Read more about State Management Architecture. Part 2. From RTK Query to Zustand
Cyber Security Services: Protecting Your Business in the Digital Age web-8989999_1280
  • Technique

Cyber Security Services: Protecting Your Business in the Digital Age

Do Son January 19, 2025 0
Read More Read more about Cyber Security Services: Protecting Your Business in the Digital Age
CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability

CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series

Do Son January 18, 2025 0
Read More Read more about CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series
Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Malware

Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique

Do Son January 18, 2025 0
Read More Read more about Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique
CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
  • Cyber Security
  • Vulnerability

CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks

Do Son January 18, 2025 0
Read More Read more about CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks
CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw Undertow Vulnerability CVE-2025-12543 CVE-2025-0107: PoC Exploit Code Undersea Cable Security, China Tech Ban
  • Vulnerability

CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw

Do Son January 17, 2025 0
Read More Read more about CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105192CVSS 9.8
    LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and...
    📅 Updated: Oct 7, 2026
  • CVE-2026-59346CVSS 9.3
    VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102667CVSS 9.0
    Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView....
    📅 Updated: Oct 7, 2026
  • CVE-2026-92414CVSS 9.3
    : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102782CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass...
    📅 Updated: Oct 7, 2026
  • CVE-2026-107204CVSS 9.3
    LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code...
    📅 Updated: Oct 7, 2026
  • CVE-2026-79796CVSS 9.8
    Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51882CVSS 9.1
    The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.