Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Phishing Campaigns Exploit YouTube URLs and Microsoft 365 Themes to Steal Credentials Layoff Phishing Scam Remcos RAT Malware Aruba Phishing, Phishing-as-a-Service PyPI, phishing CVE-2024-25608 PyPI Phishing, Credential Theft
  • Cyber Security

Phishing Campaigns Exploit YouTube URLs and Microsoft 365 Themes to Steal Credentials

Do Son January 12, 2025 0
Read More Read more about Phishing Campaigns Exploit YouTube URLs and Microsoft 365 Themes to Steal Credentials
HexaLocker V2: Ransomware Reborn with Advanced Tactics ransom
  • Malware

HexaLocker V2: Ransomware Reborn with Advanced Tactics

Do Son January 12, 2025 0
Read More Read more about HexaLocker V2: Ransomware Reborn with Advanced Tactics
CVE-2025-22152 (CVSS 9.4): Severe Vulnerabilities Found in Atheos Web-Based IDE CVE-2025-22152
  • Vulnerability

CVE-2025-22152 (CVSS 9.4): Severe Vulnerabilities Found in Atheos Web-Based IDE

Do Son January 12, 2025 0
Read More Read more about CVE-2025-22152 (CVSS 9.4): Severe Vulnerabilities Found in Atheos Web-Based IDE
ZACROS Corporation Discloses Personal Information Leak Following Ransomware Attack INC Ransom Pacific Cyber Threats OysterLoader Malware Rhysida Ransomware Black Basta Ransomware BYOVD Technique Velociraptor Abuse, Storm-2603 Ransomware Crypto24, Ransomware Ransomware Payments, UK Legislation ZACROS data breach
  • Cyber Security
  • Data Leak

ZACROS Corporation Discloses Personal Information Leak Following Ransomware Attack

Do Son January 12, 2025 0
Read More Read more about ZACROS Corporation Discloses Personal Information Leak Following Ransomware Attack
RedDelta Leverages PlugX Backdoor in State-Sponsored Espionage Campaigns Kali365 phishing platform EmEditor Supply Chain Attack, WALSHAM INVESTMENTS LIMITED EggStreme, fileless malware North Korea Cybercrime, Remote IT Job Fraud RedDelta APT
  • Cyber Security
  • Malware

RedDelta Leverages PlugX Backdoor in State-Sponsored Espionage Campaigns

Do Son January 12, 2025 0
Read More Read more about RedDelta Leverages PlugX Backdoor in State-Sponsored Espionage Campaigns
RedCurl APT Group: Cyber Espionage with Living-Off-the-Land Techniques WhatsApp Worm, Brazilian Banking Trojan LAPSUS$ Alliance, Scattered Spider Ransomware, Cybercrime RedCurl APT group Russian Cyberespionage, ApolloShadow Malware
  • Cyber Security
  • Malware

RedCurl APT Group: Cyber Espionage with Living-Off-the-Land Techniques

Do Son January 12, 2025 0
Read More Read more about RedCurl APT Group: Cyber Espionage with Living-Off-the-Land Techniques
CVE-2025-22777 (CVSS 9.8): Critical Security Alert for GiveWP Plugin with 100,000 Active Installations CVE-2025-22777
  • Vulnerability

CVE-2025-22777 (CVSS 9.8): Critical Security Alert for GiveWP Plugin with 100,000 Active Installations

Do Son January 11, 2025 0
Read More Read more about CVE-2025-22777 (CVSS 9.8): Critical Security Alert for GiveWP Plugin with 100,000 Active Installations
FunkSec: The Rising Ransomware Group Blurring the Lines Between Cybercrime and Hacktivism Exploited VMware
  • Cyber Security

FunkSec: The Rising Ransomware Group Blurring the Lines Between Cybercrime and Hacktivism

Do Son January 11, 2025 0
Read More Read more about FunkSec: The Rising Ransomware Group Blurring the Lines Between Cybercrime and Hacktivism
GroupGreeting E-Card Platform Compromised in β€œzqxq” Campaign GroupGreeting e-card - β€œzqxq” campaign
  • Cyber Security
  • Malware

GroupGreeting E-Card Platform Compromised in β€œzqxq” Campaign

Do Son January 11, 2025 0
Read More Read more about GroupGreeting E-Card Platform Compromised in β€œzqxq” Campaign
CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published CVE-2024-12847 - CVE-2022-41545
  • Vulnerability

CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published

Do Son January 10, 2025 0
Read More Read more about CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published
Cracked Software: A Gateway to Malware and Data Theft ahost.exe DLL Sideloading Signed Application Abuse PS1Bot, malware ransomware attacks bill
  • Malware

Cracked Software: A Gateway to Malware and Data Theft

Do Son January 10, 2025 0
Read More Read more about Cracked Software: A Gateway to Malware and Data Theft
Ivanti Connect Secure Zero-Day Threat: 2,048 Vulnerable Devices and Critical Exploitation Details Unveiled NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Vulnerability

Ivanti Connect Secure Zero-Day Threat: 2,048 Vulnerable Devices and Critical Exploitation Details Unveiled

Do Son January 10, 2025 0
Read More Read more about Ivanti Connect Secure Zero-Day Threat: 2,048 Vulnerable Devices and Critical Exploitation Details Unveiled
Recruitment Scam Targets Job Seekers with Fake CrowdStrike Branding CrowdStrike phishing campaign
  • Cyber Security

Recruitment Scam Targets Job Seekers with Fake CrowdStrike Branding

Do Son January 10, 2025 0
Read More Read more about Recruitment Scam Targets Job Seekers with Fake CrowdStrike Branding
Microsoft to Cut 2,200 Jobs in Performance-Based Layoffs Microsoft Developer Account Suspension Microsoft Web Activation Portal Driver Signing Account Suspension Windows 11 Smart App Control Windows 11 SE end of support, Microsoft education hardware pivot Microsoft Product Activation Portal 2025, Windows telephone activation discontinued Windows Update Naming, Microsoft Update Microsoft earnings, OpenAI valuation VBScript deprecation Microsoft Pakistan, Office Closure Microsoft job cuts Microsoft Own AI Models
  • Technology

Microsoft to Cut 2,200 Jobs in Performance-Based Layoffs

Do Son January 9, 2025 0
Read More Read more about Microsoft to Cut 2,200 Jobs in Performance-Based Layoffs
Node.js to Issue CVE for End-of-Life Versions CVE-2024-36138 - Node.js vulnerability
  • Technology
  • Vulnerability

Node.js to Issue CVE for End-of-Life Versions

Do Son January 9, 2025 0
Read More Read more about Node.js to Issue CVE for End-of-Life Versions
Stealthy Malware Hides in WordPress Database, Steals Payment Data Credit Card Skimmer
  • Malware

Stealthy Malware Hides in WordPress Database, Steals Payment Data

Do Son January 9, 2025 0
Read More Read more about Stealthy Malware Hides in WordPress Database, Steals Payment Data
Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Malware

Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware

Do Son January 9, 2025 0
Read More Read more about Fake LDAPNightmare PoC Exploit Conceals Information-Stealing Malware
New PayPal Phishing Scam Bypasses Security Measures PayPal Industrial Bank, Fintech Crypto Lending PayPal, Hotel Booking Perplexity AI, PayPal
  • Cyber Security

New PayPal Phishing Scam Bypasses Security Measures

Do Son January 9, 2025 0
Read More Read more about New PayPal Phishing Scam Bypasses Security Measures
The Linux Foundation to Manage New Chromium Fund Chrome 14-day update cycle Chromium JPEG-XL Image Format Debate Chromium DoS, document.title Browser Muting, iframe Media Supporters of Chromium-based Browsers
  • Technology

The Linux Foundation to Manage New Chromium Fund

Do Son January 9, 2025 0
Read More Read more about The Linux Foundation to Manage New Chromium Fund
Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail XCharge C6 vulnerabilities EV charger security flaws GNU libtasn1 Vulnerability CVE-2025-13151 Credit Card Skimmer Malware CVE-2024-13892
  • Malware

Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail

Do Son January 9, 2025 0
Read More Read more about Malicious npm Packages Target Solana Developers, Stealing Private Keys via Gmail
Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies Play Ransomware Tactics
  • Malware

Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies

Do Son January 9, 2025 0
Read More Read more about Unmasking Play Ransomware: Tactics, Techniques, and Mitigation Strategies
Muddling Malspam: Unveiling the Use of Spoofed Domains in Malicious Spam Campaigns Gmail Scam
  • Cyber Security

Muddling Malspam: Unveiling the Use of Spoofed Domains in Malicious Spam Campaigns

Do Son January 9, 2025 0
Read More Read more about Muddling Malspam: Unveiling the Use of Spoofed Domains in Malicious Spam Campaigns
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-79796CVSS 9.8
    Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76464CVSS 9.6
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51862CVSS 9.1
    DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51869CVSS 9.8
    DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
    📅 Updated: Oct 7, 2026
  • CVE-2026-76501CVSS 9.8
    A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76500CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.