Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Hackers Exploit Social Security Administration Branding to Deliver ConnectWise RAT phishing-3390518_1280
  • Cyber Security

Hackers Exploit Social Security Administration Branding to Deliver ConnectWise RAT

Do Son January 5, 2025 0
Read More Read more about Hackers Exploit Social Security Administration Branding to Deliver ConnectWise RAT
Cybersecurity Alert: FireScam—The Android Malware Disguised as Telegram Premium BadBox 2.0, Android Botnet Alien spyware - CVE-2024-43093
  • Malware

Cybersecurity Alert: FireScam—The Android Malware Disguised as Telegram Premium

Do Son January 5, 2025 0
Read More Read more about Cybersecurity Alert: FireScam—The Android Malware Disguised as Telegram Premium
CVE-2024-10957 Exposes Over 3 Million WordPress Sites to Unauthenticated PHP Object Injection Exploits WordPress POP chain attack - CVE-2024-10957
  • Vulnerability

CVE-2024-10957 Exposes Over 3 Million WordPress Sites to Unauthenticated PHP Object Injection Exploits

Do Son January 4, 2025 0
Read More Read more about CVE-2024-10957 Exposes Over 3 Million WordPress Sites to Unauthenticated PHP Object Injection Exploits
MISP Unveils the Threat Actor Naming Standard Iranian Hacktivists Operation Epic Fury Cyber New Generation Warfare Russian Hybrid Escalation Plex data breach Water Systems Cybersecurity - Threat Actor Naming Standard
  • Cyber Security

MISP Unveils the Threat Actor Naming Standard

Do Son January 4, 2025 0
Read More Read more about MISP Unveils the Threat Actor Naming Standard
Atos Responds to Space Bears Ransomware Allegations Space Bears group
  • Cyber Security
  • Data Leak

Atos Responds to Space Bears Ransomware Allegations

Do Son January 4, 2025 0
Read More Read more about Atos Responds to Space Bears Ransomware Allegations
US Treasury Sanctions Chinese Cybersecurity Firm for Supporting Cyberattacks on Critical Infrastructure Harvester APT Linux Backdoor OT Cyberattack Iranian APT Operation Olalampo MuddyWater APT Prince of Persia APT, Tonnerre v50 Patchwork APT, DLL Sideloading Subtle Snail, cyber espionage ShadowSilk, cyber espionage Volt Typhoon APT Group - Chinese Cybersecurity Firm
  • Cyber Security

US Treasury Sanctions Chinese Cybersecurity Firm for Supporting Cyberattacks on Critical Infrastructure

Do Son January 3, 2025 0
Read More Read more about US Treasury Sanctions Chinese Cybersecurity Firm for Supporting Cyberattacks on Critical Infrastructure
Data Centers Get an AI Upgrade: Microsoft’s $80 Billion Commitment Microsoft, pricing change Microsoft Server Pricing, On-Premises Price Hike Security Core Priority - Microsoft data centers
  • Technology

Data Centers Get an AI Upgrade: Microsoft’s $80 Billion Commitment

Do Son January 3, 2025 0
Read More Read more about Data Centers Get an AI Upgrade: Microsoft’s $80 Billion Commitment
Next.js Patches Denial-of-Service Vulnerability (CVE-2024-56332) in Server Actions CVE-2024-56332 - CVE-2025-29927 Next.js, Cache Poisoning
  • Vulnerability

Next.js Patches Denial-of-Service Vulnerability (CVE-2024-56332) in Server Actions

Do Son January 3, 2025 0
Read More Read more about Next.js Patches Denial-of-Service Vulnerability (CVE-2024-56332) in Server Actions
CVE-2024-56513: Karmada Vulnerability Grants Attackers Control of Kubernetes Systems CVE-2024-56513
  • Vulnerability

CVE-2024-56513: Karmada Vulnerability Grants Attackers Control of Kubernetes Systems

Do Son January 3, 2025 0
Read More Read more about CVE-2024-56513: Karmada Vulnerability Grants Attackers Control of Kubernetes Systems
India’s VPN Crackdown: Popular Apps Vanish from App Stores India VPN
  • Technology

India’s VPN Crackdown: Popular Apps Vanish from App Stores

Do Son January 3, 2025 0
Read More Read more about India’s VPN Crackdown: Popular Apps Vanish from App Stores
Beware! Fake EditThisCookie Extension Steals User Data EditThisCookie
  • Malware

Beware! Fake EditThisCookie Extension Steals User Data

Do Son January 3, 2025 0
Read More Read more about Beware! Fake EditThisCookie Extension Steals User Data
ESET’s Warning: Windows 10 Users Urged to Switch to 11 or Linux Transition Windows 10 to Linux
  • Linux
  • Technology
  • Windows

ESET’s Warning: Windows 10 Users Urged to Switch to 11 or Linux

Do Son January 3, 2025 0
Read More Read more about ESET’s Warning: Windows 10 Users Urged to Switch to 11 or Linux
CVE-2025-22275 (CVSS 9.3): iTerm2 Patches Critical Security Flaw Exposing User Input and Output iTerm2 vulnerability
  • Vulnerability

CVE-2025-22275 (CVSS 9.3): iTerm2 Patches Critical Security Flaw Exposing User Input and Output

Do Son January 2, 2025 0
Read More Read more about CVE-2025-22275 (CVSS 9.3): iTerm2 Patches Critical Security Flaw Exposing User Input and Output
SysBumps: Breaking Kernel Address Space Layout Randomization on macOS for Apple Silicon DarkSword exploit kit iOS 18.7.7 security update CVE-2024-44308 & CVE-2024-44309 Apple appeal, Epic Games lawsuit
  • Vulnerability

SysBumps: Breaking Kernel Address Space Layout Randomization on macOS for Apple Silicon

Do Son January 2, 2025 0
Read More Read more about SysBumps: Breaking Kernel Address Space Layout Randomization on macOS for Apple Silicon
Supply Chain Attack on Ethereum Developers via Malicious npm Packages npm Supply Chain Attack
  • Malware

Supply Chain Attack on Ethereum Developers via Malicious npm Packages

Do Son January 2, 2025 0
Read More Read more about Supply Chain Attack on Ethereum Developers via Malicious npm Packages
Patched But Still Vulnerable: Windows BitLocker Encryption Bypassed Again Bypass Windows BitLocker - CVE-2023-21563
  • Vulnerability
  • Windows

Patched But Still Vulnerable: Windows BitLocker Encryption Bypassed Again

Do Son January 2, 2025 0
Read More Read more about Patched But Still Vulnerable: Windows BitLocker Encryption Bypassed Again
35+ Chrome Extensions Compromised: 2.5 Million Users at Risk Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security

35+ Chrome Extensions Compromised: 2.5 Million Users at Risk

Do Son January 2, 2025 0
Read More Read more about 35+ Chrome Extensions Compromised: 2.5 Million Users at Risk
CVE-2024-12912 & CVE-2024-13062: ASUS Routers at Risk ASUS CVE-2025-13348 File Shredder Removal ASUS LPE Flaw CVE-2025-59373 ASUS Armoury Crate vulnerability Asus CVE Numbering Authority - CVE-2024-12912 and CVE-2024-13062 AMI BMC vulnerability, CVE-2024-54085
  • Vulnerability

CVE-2024-12912 & CVE-2024-13062: ASUS Routers at Risk

Do Son January 2, 2025 0
Read More Read more about CVE-2024-12912 & CVE-2024-13062: ASUS Routers at Risk
Project Quarantine: PyPI’s New Line of Defense Against Malware Project Quarantine PyPI Security Privilege Escalation
  • Malware
  • Technology

Project Quarantine: PyPI’s New Line of Defense Against Malware

Do Son January 2, 2025 0
Read More Read more about Project Quarantine: PyPI’s New Line of Defense Against Malware
Unmasking Fraudulent Popularity: Study Exposes 4.5 Million Fake Stars on GitHub Screenshot 2025-01-02 170012
  • Cyber Security
  • Malware

Unmasking Fraudulent Popularity: Study Exposes 4.5 Million Fake Stars on GitHub

Do Son January 2, 2025 0
Read More Read more about Unmasking Fraudulent Popularity: Study Exposes 4.5 Million Fake Stars on GitHub
Starlink V3 Satellites Promise Blazing Fast Internet Speeds Starlink V3 Satellites
  • Technology

Starlink V3 Satellites Promise Blazing Fast Internet Speeds

Do Son January 2, 2025 0
Read More Read more about Starlink V3 Satellites Promise Blazing Fast Internet Speeds
PoC Exploit Released for Zero-Click Vulnerability CVE-2024-49113 in Windows CVE-2024-49112 PoC exploit
  • Vulnerability

PoC Exploit Released for Zero-Click Vulnerability CVE-2024-49113 in Windows

Do Son January 1, 2025 0
Read More Read more about PoC Exploit Released for Zero-Click Vulnerability CVE-2024-49113 in Windows
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-76268CVSS 9.8
    In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational...
    📅 Updated: Oct 7, 2026
  • CVE-2026-82533CVSS 9.6
    DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API that allows attackers...
    📅 Updated: Oct 7, 2026
  • CVE-2026-63992CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-92414CVSS 9.3
    : Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached...
    📅 Updated: Oct 7, 2026
  • CVE-2026-63994CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102268CVSS 9.1
    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76751CVSS 9.8
    A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76752CVSS 9.8
    Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.