Skip to content
June 23, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
IcePeony – A New China-Nexus APT Group Targeting Asian Nations IcePeony
  • Cyber Security
  • Malware

IcePeony – A New China-Nexus APT Group Targeting Asian Nations

Do Son October 20, 2024 0
A previously unknown China-nexus advanced persistent threat (APT) group, identified as “IcePeony,” according to a recent report...
Read More Read more about IcePeony – A New China-Nexus APT Group Targeting Asian Nations
Vulnhuntr: A Tool for Finding Exploitable Vulnerabilities with LLMs and Static Code Analysis Vulnhuntr
  • Open Source Tool

Vulnhuntr: A Tool for Finding Exploitable Vulnerabilities with LLMs and Static Code Analysis

Do Son October 19, 2024 0
In today’s ever-evolving cybersecurity landscape, identifying vulnerabilities in codebases is critical for maintaining secure software and infrastructure....
Read More Read more about Vulnhuntr: A Tool for Finding Exploitable Vulnerabilities with LLMs and Static Code Analysis
9.1 CVE-2024-10025 (CVSS 9.1): Critical Flaw in SICK Products Exposes Systems to Remote Attacks CVE-2024-10025 CVE-2025-27593 & CVE-2025-27595
  • Vulnerability

9.1 CVE-2024-10025 (CVSS 9.1): Critical Flaw in SICK Products Exposes Systems to Remote Attacks

Do Son October 19, 2024 0
A newly disclosed vulnerability in multiple SICK products, tracked as CVE-2024-10025, has raised significant cybersecurity concerns across...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.1</span> CVE-2024-10025 (CVSS 9.1): Critical Flaw in SICK Products Exposes Systems to Remote Attacks
Beware of Fake Google Meet Invites: ClickFix Campaign Spreading Infostealers The Phantom Meet
  • Malware

Beware of Fake Google Meet Invites: ClickFix Campaign Spreading Infostealers

Do Son October 19, 2024 0
A new and dangerous social engineering tactic, dubbed ClickFix, has emerged as a significant cybersecurity threat in...
Read More Read more about Beware of Fake Google Meet Invites: ClickFix Campaign Spreading Infostealers
Critical Critical Flaw in Synology Camera Firmware Expose Devices to RCE and DoS Attacks Synology Camera BC500 Firmware
  • Vulnerability

Critical Critical Flaw in Synology Camera Firmware Expose Devices to RCE and DoS Attacks

Do Son October 18, 2024 0
Synology has issued a security advisory, Synology-SA-24:17, warning of critical vulnerabilities in several of its camera firmware...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">Critical</span> Critical Flaw in Synology Camera Firmware Expose Devices to RCE and DoS Attacks
Gatekeeper Bypass: Malicious Apps Could Slip Through macOS Defenses Gatekeeper Bypass
  • Vulnerability

Gatekeeper Bypass: Malicious Apps Could Slip Through macOS Defenses

Do Son October 18, 2024 0
A new report from Unit 42 researchers has uncovered significant weaknesses in macOS’s Gatekeeper security mechanism, which...
Read More Read more about Gatekeeper Bypass: Malicious Apps Could Slip Through macOS Defenses
9.1 CVE-2024-48914 (CVSS 9.1): Critical File Read Flaw Discovered in Vendure E-commerce Platform CVE-2024-48914
  • Vulnerability

9.1 CVE-2024-48914 (CVSS 9.1): Critical File Read Flaw Discovered in Vendure E-commerce Platform

Do Son October 18, 2024 0
Vendure, a popular open-source headless commerce platform, has patched a critical security vulnerability that could allow attackers...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.1</span> CVE-2024-48914 (CVSS 9.1): Critical File Read Flaw Discovered in Vendure E-commerce Platform
Infostealers Use Telegram Bots for Data Exfiltration, Exploiting a Growing Threat Telegram Bots
  • Malware

Infostealers Use Telegram Bots for Data Exfiltration, Exploiting a Growing Threat

Do Son October 18, 2024 0
Cybercriminals are increasingly leveraging Telegram as a platform not only for communication but also as a server...
Read More Read more about Infostealers Use Telegram Bots for Data Exfiltration, Exploiting a Growing Threat
Hikvision HikCentral Master Lite and Professional Affected by Multi Vulnerabilities HikCentral Master Lite & HikCentral Professional
  • Vulnerability

Hikvision HikCentral Master Lite and Professional Affected by Multi Vulnerabilities

Do Son October 18, 2024 0
Hikvision, a leading provider of AIoT and video surveillance solutions, has disclosed three vulnerabilities affecting its HikCentral...
Read More Read more about Hikvision HikCentral Master Lite and Professional Affected by Multi Vulnerabilities
Critical Critical Vulnerabilities in Bitdefender Total Security Expose Users to Man-in-the-Middle Attacks Bitdefender Total Security
  • Vulnerability

Critical Critical Vulnerabilities in Bitdefender Total Security Expose Users to Man-in-the-Middle Attacks

Do Son October 18, 2024 0
Bitdefender, a leading global cybersecurity technology company, has issued an urgent advisory regarding three critical vulnerabilities discovered...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">Critical</span> Critical Vulnerabilities in Bitdefender Total Security Expose Users to Man-in-the-Middle Attacks
Cybercriminal Arrested in Connection with SEC X Account Hack That Manipulated Bitcoin Market Elderly lottery fraud scam DOJ wire fraud conspiracy ALPHV BlackCat, Insider Threat Nefilim ransomware Artem Stryzhak guilty plea, Volodymyr Tymoshchuk $11M reward CoinDCX, Employee Arrest Operation PowerOFF Cybercrime, Self-Promotion Hacking
  • Cyber Security

Cybercriminal Arrested in Connection with SEC X Account Hack That Manipulated Bitcoin Market

Do Son October 18, 2024 0
The U.S. Department of Justice announced the arrest of Eric Council Jr., a 25-year-old from Athens, Alabama,...
Read More Read more about Cybercriminal Arrested in Connection with SEC X Account Hack That Manipulated Bitcoin Market
9.4 Patch Now! Grafana Hit by 9.9 Severity RCE Vulnerability (CVE-2024-9264) CVE-2024-9264
  • Vulnerability

9.4 Patch Now! Grafana Hit by 9.9 Severity RCE Vulnerability (CVE-2024-9264)

Do Son October 18, 2024 0
A critical security vulnerability (CVE-2024-9264) has been discovered in Grafana, the popular open-source platform for monitoring and...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.4</span> Patch Now! Grafana Hit by 9.9 Severity RCE Vulnerability (CVE-2024-9264)
9.8 SolarWinds Web Help Desk Hit With Critical RCE Flaw (CVE-2024-28988, CVSS 9.8) CVE-2024-28988
  • Vulnerability

9.8 SolarWinds Web Help Desk Hit With Critical RCE Flaw (CVE-2024-28988, CVSS 9.8)

Do Son October 17, 2024 0
SolarWinds, a major provider of IT management software, has issued a security advisory addressing a severe vulnerability...
Read More Read more about <span class="dcs-sev-badge" style="background:#ef4444;">9.8</span> SolarWinds Web Help Desk Hit With Critical RCE Flaw (CVE-2024-28988, CVSS 9.8)
UAT-5647 Unleashes RomCom Malware in Attacks on Ukraine and Poland UAT-5647 - RomCom malware
  • Cyber Security
  • Malware

UAT-5647 Unleashes RomCom Malware in Attacks on Ukraine and Poland

Do Son October 17, 2024 0
In a sophisticated and persistent cyber campaign, the UAT-5647 threat actor group, known for its ties to...
Read More Read more about UAT-5647 Unleashes RomCom Malware in Attacks on Ukraine and Poland
8.6 F5 BIG-IP Vulnerability (CVE-2024-45844): Access Control Bypass Risk, PoC Available CVE-2024-45844 command injection root access
  • Vulnerability

8.6 F5 BIG-IP Vulnerability (CVE-2024-45844): Access Control Bypass Risk, PoC Available

Do Son October 17, 2024 0
A critical vulnerability has been identified in F5 BIG-IP, a popular network traffic management and security solution....
Read More Read more about <span class="dcs-sev-badge" style="background:#f97316;">8.6</span> F5 BIG-IP Vulnerability (CVE-2024-45844): Access Control Bypass Risk, PoC Available
From Windows to Linux to ESXi: The Cicada3301 Ransomware Hits Them All Cicada3301 RaaS
  • Cyber Security
  • Malware

From Windows to Linux to ESXi: The Cicada3301 Ransomware Hits Them All

Do Son October 17, 2024 0
A sophisticated ransomware group, Cicada3301, has rapidly risen to prominence in the cybercrime landscape, targeting critical infrastructure...
Read More Read more about From Windows to Linux to ESXi: The Cicada3301 Ransomware Hits Them All
7.5 Spring Framework Vulnerability CVE-2024-38819: Path Traversal Risk in Web Apps Spring Data vulnerabilities Spring Cloud Config CVE-2026-22739 Spring Gateway SpEL, STOMP WebSocket CSRF Spring Security, vulnerability CVE-2024-38819 CVE-2025-41243 Spring Cloud Gateway, vulnerability
  • Vulnerability

7.5 Spring Framework Vulnerability CVE-2024-38819: Path Traversal Risk in Web Apps

Do Son October 17, 2024 0
A newly disclosed path traversal vulnerability, tracked as CVE-2024-38819, has been found in the widely used Spring...
Read More Read more about <span class="dcs-sev-badge" style="background:#f97316;">7.5</span> Spring Framework Vulnerability CVE-2024-38819: Path Traversal Risk in Web Apps
North Korean IT Worker Schemes Evolve: From Salary Scams to Cyber Extortion NICKEL TAPESTRY
  • Cyber Security

North Korean IT Worker Schemes Evolve: From Salary Scams to Cyber Extortion

Do Son October 17, 2024 0
A new report from Secureworks® Counter Threat Unit™ (CTU) researchers has revealed a disturbing escalation in the...
Read More Read more about North Korean IT Worker Schemes Evolve: From Salary Scams to Cyber Extortion
HORUS Protector: The New Undetectable Malware Crypter Threatening Cybersecurity HORUS Protector
  • Malware

HORUS Protector: The New Undetectable Malware Crypter Threatening Cybersecurity

Do Son October 17, 2024 0
In a recent discovery by the SonicWall Capture Labs threat research team, a new malware crypter known...
Read More Read more about HORUS Protector: The New Undetectable Malware Crypter Threatening Cybersecurity
Cisco ATA 190 Series Analog Telephone Adapter Firmware Flaws Exposed: Patch Now! Cisco CCX RCE and Java RMI Flaw CVE-2024-20458 - CVE-2025-20111 Cisco Smart Licensing Utility Flaw
  • Vulnerability

Cisco ATA 190 Series Analog Telephone Adapter Firmware Flaws Exposed: Patch Now!

Do Son October 17, 2024 0
Cisco has recently disclosed a series of high-severity vulnerabilities in the Cisco ATA 190 Series Analog Telephone...
Read More Read more about Cisco ATA 190 Series Analog Telephone Adapter Firmware Flaws Exposed: Patch Now!
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-56315CVSS 9.8
    picklescan before 1.0.4 fails to block at least seven Python standard library...
  • CVE-2026-56274CVSS 9.9
    Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom...
  • CVE-2026-11374CVSS 9.0
    In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus,...
  • CVE-2026-12866CVSS 9.8
    All versions of the package expr-eval are vulnerable to Code Execution via...
  • CVE-2026-54352CVSS 9.6
    ## Summary `POST /api/pwa/process-zip` at `packages/server/src/api/routes/static.ts:24` accepts a builder-uploaded `.zip`, extracts it...
  • CVE-2026-48746CVSS 9.1
    vLLM is an inference and serving engine for large language models (LLMs)....
  • CVE-2026-48170CVSS 9.1
    ## Summary `scim-patch` performs prototype pollution when applying a SCIM PATCH operation...
  • CVE-2026-46495
    ## Summary **Description** A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ's...
  • CVE-2026-56348CVSS 9.1
    n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options...
  • CVE-2026-46488
    ### Summary An authentication bypass vulnerability exists due to improper trust in...
Powered by CVE WATCHTOWER

🚨 Active Exploits in the Wild

  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-10735
    Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated attackers to...
  • CVE-2026-20262CVSS 6.5
    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,...
  • CVE-2026-54420CVSS 8.5
    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a...
  • CVE-2026-53435CVSS 8.8
    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize...
  • CVE-2026-10795CVSS 8.1
    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions...
  • CVE-2026-11645
    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
  • CVE-2026-50751CVSS 9.3
    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows...
  • CVE-2026-20245CVSS 7.8
    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local...
Powered by CVE Watchtower

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.