Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series Moxa Hard-Coded Credentials, Critical JWT Bypass CVE-2024-9137 and CVE-2024-9139 - CVE-2024-12297 CVE-2024-7695 CVE-2024-9404 CVE-2024-12297 CVE-2025-0415
  • Vulnerability

CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series

Do Son January 18, 2025 0
Read More Read more about CVE-2024-12297 (CVSS 9.2): Critical Authorization Vulnerability in Moxa EDS-508A Series
Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Malware

Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique

Do Son January 18, 2025 0
Read More Read more about Lazarus APT Targets Job Seekers with “Contagious Interview” Campaign Using ClickFix Technique
CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
  • Cyber Security
  • Vulnerability

CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks

Do Son January 18, 2025 0
Read More Read more about CL-UNK-0979 Exploit Zero-Day Flaw in Ivanti Connect Secure to Gain Access to Networks
CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw Undertow Vulnerability CVE-2025-12543 CVE-2025-0107: PoC Exploit Code Undersea Cable Security, China Tech Ban
  • Vulnerability

CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw

Do Son January 17, 2025 0
Read More Read more about CVE-2025-0107: PoC Exploit Code Released for Palo Alto Expedition RCE Flaw
Real Estate Scams on the Rise in the Middle East TASPEN, mobile malware North Korean IT Worker Fraud
  • Cyber Security

Real Estate Scams on the Rise in the Middle East

Do Son January 17, 2025 0
Read More Read more about Real Estate Scams on the Rise in the Middle East
CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw CVE-2024-53691 PoC exploit
  • Vulnerability

CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw

Do Son January 16, 2025 0
Read More Read more about CVE-2024-53691: PoC Exploit Released for Severe QNAP RCE Flaw
Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package CVE-2025-23013
  • Vulnerability

Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package

Do Son January 16, 2025 0
Read More Read more about Yubico Addresses Authentication Bypass Vulnerability CVE-2025-23013 in pam-u2f Package
The Rise of AI Search: Google Search Market Share Dips Below 90% Google Arkansas Investment, AI Data Center Google, privacy fine Ecosia Google Chrome Alphabet Earnings, AI Growth Google Hydropower, AI Data Centers Google Breakup Antitrust Workspace Flows Google Workspace Google remote work, return to office
  • Technology

The Rise of AI Search: Google Search Market Share Dips Below 90%

Do Son January 16, 2025 0
Read More Read more about The Rise of AI Search: Google Search Market Share Dips Below 90%
Microsoft 365 Drops Windows 10: What You Need to Know Before the Deadline Microsoft 365 Windows 10
  • Technology
  • Windows

Microsoft 365 Drops Windows 10: What You Need to Know Before the Deadline

Do Son January 16, 2025 0
Read More Read more about Microsoft 365 Drops Windows 10: What You Need to Know Before the Deadline
HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems CVE-2024-26305 _ CVE-2025-23058 Aruba 5G Core Open Redirect
  • Vulnerability

HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems

Do Son January 16, 2025 0
Read More Read more about HPE Aruba Networking Addresses Security Vulnerabilities in AOS Systems
AWS Patches Vulnerabilities in WorkSpaces, AppStream 2.0, and DCV Clients WorkSpaces Token Leak, Local Privilege Escalation CVE-2025-0500 & CVE-2025-0501
  • Vulnerability

AWS Patches Vulnerabilities in WorkSpaces, AppStream 2.0, and DCV Clients

Do Son January 16, 2025 0
Read More Read more about AWS Patches Vulnerabilities in WorkSpaces, AppStream 2.0, and DCV Clients
CVE-2024-52281: Rancher Vulnerability Exposes Users to Stored XSS Attacks CVE-2024-52281 Rancher CLI Vulnerability CVE-2025-67601
  • Vulnerability

CVE-2024-52281: Rancher Vulnerability Exposes Users to Stored XSS Attacks

Do Son January 16, 2025 0
Read More Read more about CVE-2024-52281: Rancher Vulnerability Exposes Users to Stored XSS Attacks
Is Google Too Big? CMA Investigates Search Giant Competition and Markets Authority Google
  • Technology

Is Google Too Big? CMA Investigates Search Giant

Do Son January 16, 2025 0
Read More Read more about Is Google Too Big? CMA Investigates Search Giant
NVIDIA Releases Security Update for Container Toolkit and GPU Operator NVIDIA acquisition rumors NVIDIA AI Security AI Framework Vulnerabilities Nvidia 595.76 Hotfix NVIDIA Megatron Bridge vulnerability GPU vs ASIC AI battle NVIDIA Driver Vulnerability CVE-2025-33217 NVIDIA biggest TSMC customer 2026, NVIDIA vs Apple TSMC revenue share NVIDIA CUDA Toolkit CVE-2025-33228 Groq NVIDIA licensing deal, Jonathan Ross acquihire 2025 NeMo Code Injection, AI Framework RCE NVIDIA App Privilege Escalation, CVE-2025-23358 NVIDIA Security Update, DLS Vulnerability CVE-2025-23316 NVIDIA NVDebug, vulnerabilities NVIDIA Driver Vulnerabilities, vGPU Security Nvidia Jetson, UEFI Vulnerabilities CVE-2024-0130 - CVE-2024-0136 CVE-2024-0148 NVIDIA Driver Support, Windows 10 EOL
  • Vulnerability

NVIDIA Releases Security Update for Container Toolkit and GPU Operator

Do Son January 16, 2025 0
Read More Read more about NVIDIA Releases Security Update for Container Toolkit and GPU Operator
North Korean Hackers Linked to Crowdfunding Scam Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cyber Security

North Korean Hackers Linked to Crowdfunding Scam

Do Son January 16, 2025 0
Read More Read more about North Korean Hackers Linked to Crowdfunding Scam
CVE-2024-9636: Popular WordPress Plugin ComboBlocks Exposes Thousands of Sites to Complete Takeover CVE-2024-9636
  • Vulnerability

CVE-2024-9636: Popular WordPress Plugin ComboBlocks Exposes Thousands of Sites to Complete Takeover

Do Son January 16, 2025 0
Read More Read more about CVE-2024-9636: Popular WordPress Plugin ComboBlocks Exposes Thousands of Sites to Complete Takeover
TikTok’s Last Dance: Inside the U.S. Ban TikTok USDS Joint Venture LLC divestiture, Project Texas 2.0 ByteDance stake TikTokRefugee TikTok Ban, US Extension
  • Technology

TikTok’s Last Dance: Inside the U.S. Ban

Do Son January 16, 2025 0
Read More Read more about TikTok’s Last Dance: Inside the U.S. Ban
Cybercriminals Exploit Fake Google Ads to Ransack Advertiser Accounts Google Ads Scam
  • Cyber Security

Cybercriminals Exploit Fake Google Ads to Ransack Advertiser Accounts

Do Son January 16, 2025 0
Read More Read more about Cybercriminals Exploit Fake Google Ads to Ransack Advertiser Accounts
Enhance Your Privacy with Rented USA Temp Numbers for SMS Img_2025_09_11_23_12_43
  • Technique

Enhance Your Privacy with Rented USA Temp Numbers for SMS

Do Son January 16, 2025
Read More Read more about Enhance Your Privacy with Rented USA Temp Numbers for SMS
PoC Exploit Released for Ivanti Connect Secure Flaw CVE-2025-0282 Used in Attacks Salt Typhoon Teleco Hack, Cisco Academy Link CVE-2025-0282 PoC exploit
  • Vulnerability

PoC Exploit Released for Ivanti Connect Secure Flaw CVE-2025-0282 Used in Attacks

Do Son January 16, 2025 0
Read More Read more about PoC Exploit Released for Ivanti Connect Secure Flaw CVE-2025-0282 Used in Attacks
Modern approaches to vulnerability management: MODUS X expertise in protecting businesses and critical infrastructure WD Discovery Vulnerability CVE-2025-30248 binary-parser Vulnerability CVE-2026-1245 H3C RCE Vulnerability CVE-2025-60262 Telenium RCE, CVE-2025-10659 Fuel station security, ICS vulnerabilities FreePBX vulnerability CVE-2024-9478 & CVE-2024-9479 SysTrack Vulnerability, Privilege Escalation
  • Technique

Modern approaches to vulnerability management: MODUS X expertise in protecting businesses and critical infrastructure

Do Son January 16, 2025 0
Read More Read more about Modern approaches to vulnerability management: MODUS X expertise in protecting businesses and critical infrastructure
New Tunneling Protocol Vulnerabilities Expose 4.2 Million Hosts to Cyberattacks Tunneling Protocol Vulnerability
  • Vulnerability

New Tunneling Protocol Vulnerabilities Expose 4.2 Million Hosts to Cyberattacks

Do Son January 16, 2025 0
Read More Read more about New Tunneling Protocol Vulnerabilities Expose 4.2 Million Hosts to Cyberattacks
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-79796CVSS 9.8
    Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76464CVSS 9.6
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51862CVSS 9.1
    DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51869CVSS 9.8
    DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
    📅 Updated: Oct 7, 2026
  • CVE-2026-76501CVSS 9.8
    A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76500CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.