Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
AI Dev Gallery: Microsoft Unleashes On-Device AI for Windows 11 Microsoft AI Dev Gallery
  • Technology
  • Windows

AI Dev Gallery: Microsoft Unleashes On-Device AI for Windows 11

Do Son December 30, 2024 0
Read More Read more about AI Dev Gallery: Microsoft Unleashes On-Device AI for Windows 11
Volkswagen’s Cariad Exposes Location Data of 800,000 Electric Vehicles Volkswagen's Cariad Exposes Location Data
  • Data Leak

Volkswagen’s Cariad Exposes Location Data of 800,000 Electric Vehicles

Do Son December 29, 2024 0
Read More Read more about Volkswagen’s Cariad Exposes Location Data of 800,000 Electric Vehicles
Global Cyber Collaboration Takes Down PlugX Worm CVE-2024-41988 & CVE-2024-41987
  • Malware

Global Cyber Collaboration Takes Down PlugX Worm

Do Son December 29, 2024 0
Read More Read more about Global Cyber Collaboration Takes Down PlugX Worm
Linux Kernel Vulnerability CVE-2023-4147: PoC Exploit Published for Privilege Escalation Flaw Sudo vulnerability, Privilege Escalation CVE-2023-4147 PoC exploit
  • Linux
  • Vulnerability

Linux Kernel Vulnerability CVE-2023-4147: PoC Exploit Published for Privilege Escalation Flaw

Do Son December 29, 2024 0
Read More Read more about Linux Kernel Vulnerability CVE-2023-4147: PoC Exploit Published for Privilege Escalation Flaw
CVE-2024-56512: Apache NiFi Vulnerability Exposes Sensitive Data to Unauthorized Users Apache NiFi RCE CVE-2026-39816 Apache NiFi Vulnerability CVE-2026-25903 Apache NiFi Deserialization, GetAsanaObject Vulnerability CVE-2024-52067 - CVE-2024-56512 CVE-2025-27017
  • Vulnerability

CVE-2024-56512: Apache NiFi Vulnerability Exposes Sensitive Data to Unauthorized Users

Do Son December 29, 2024 0
Read More Read more about CVE-2024-56512: Apache NiFi Vulnerability Exposes Sensitive Data to Unauthorized Users
Postman Security Lapse: 30,000 Workspaces Leak API Keys & More Postman_(software)
  • Data Leak
  • Vulnerability

Postman Security Lapse: 30,000 Workspaces Leak API Keys & More

Do Son December 29, 2024 0
Read More Read more about Postman Security Lapse: 30,000 Workspaces Leak API Keys & More
CVE-2024-45387: PoC Published for Critical SQL Injection in Apache Traffic Control CVE-2024-45387 PoC exploit
  • Vulnerability

CVE-2024-45387: PoC Published for Critical SQL Injection in Apache Traffic Control

Do Son December 29, 2024 0
Read More Read more about CVE-2024-45387: PoC Published for Critical SQL Injection in Apache Traffic Control
Four-Faith Industrial Routers Under Attack: CVE-2024-12856 Exploited in the Wild CVE-2024-12856
  • Vulnerability

Four-Faith Industrial Routers Under Attack: CVE-2024-12856 Exploited in the Wild

Do Son December 29, 2024 0
Read More Read more about Four-Faith Industrial Routers Under Attack: CVE-2024-12856 Exploited in the Wild
CVE-2024-55950: Tabby Terminal Emulator Vulnerability Exposes macOS Users to Privacy and Security Risks TCC Bypass - CVE-2024-55950
  • Vulnerability

CVE-2024-55950: Tabby Terminal Emulator Vulnerability Exposes macOS Users to Privacy and Security Risks

Do Son December 29, 2024 0
Read More Read more about CVE-2024-55950: Tabby Terminal Emulator Vulnerability Exposes macOS Users to Privacy and Security Risks
Linux Systems at Risk: GStreamer Vulnerabilities Threaten Millions GStreamer vulnerability
  • Vulnerability

Linux Systems at Risk: GStreamer Vulnerabilities Threaten Millions

Do Son December 29, 2024 0
Read More Read more about Linux Systems at Risk: GStreamer Vulnerabilities Threaten Millions
The Dark Side of Virtual Offices: How Criminals Exploit Flexibility Virtual Offices
  • Cyber Security

The Dark Side of Virtual Offices: How Criminals Exploit Flexibility

Do Son December 29, 2024 0
Read More Read more about The Dark Side of Virtual Offices: How Criminals Exploit Flexibility
OpenAI Restructures for Profit to Fuel AGI Development OpenAI token price reduction OpenAI Deployment Company DeployCo OpenAI IPO strategy OpenAI Privacy Filter 1.5B OpenAI $122 billion funding OpenAI GitHub alternative OpenAI military agreement 2026 OpenAI Stargate project collapse NVIDIA OpenAI investment stall ChatGPT Go $8 subscription, OpenAI GPT-5.2 Instant ads OpenAI Torch acquisition, Unified Medical Memory OpenAI Head of Preparedness 2025, Sam Altman AI safety lawsuits ChatGPT Advertising Speculation OpenAI Ad Code Denial OpenAI AI Confession Hallucination Mitigation ChatGPT Quality Focus OpenAI Gemini Red Alert ChatGPT Login, AI ecosystem OpenAI Mental Health, AI Well-Being Council ChatGPT Instant Checkout, Agentic Commerce OpenAI cloud computing OpenAI, startup incubator OpenAI chips, NVIDIA competition AI competition, antitrust lawsuit GPT-5, OpenAI Livestream OpenAI Open-Weight, AI Models OpenAI Infrastructure, AI Data Centers ChatGPT Business, Office Productivity OpenAI Open-Weight Model, WindSurf Acquisition OpenAI AI Browser, ChatGPT Integration Mattel AI, OpenAI Partnership OpenAI o3, Price Cut OpenAI's Next-Gen AI: O3-Pro's Enhanced Reasoning PowerOpenAI profit OpenAI Bid OpenAI Social Network ChatGPT Social OpenAI Non-profit OpenAI UAE ChatGPT Plus free
  • Technology

OpenAI Restructures for Profit to Fuel AGI Development

Do Son December 29, 2024 0
Read More Read more about OpenAI Restructures for Profit to Fuel AGI Development
Google’s Gemini: Pichai Bets Big on AI in 2025 Google Self-Preferencing Fine Idealo Antitrust Damages Anthropic, Google TPUs Google DMA Compliance, Search Self-Preferencing Google Play Store Ruling, Epic Games Victory Google fine, ad tech Google lawsuit, privacy violation Gmail security, false alarm Google Play EU regulation Google Security, Phone Number Leak Google 2025 - Google China’s Anti-Monopoly Law Google monopoly, ad tech Pixel 7a battery, battery swelling
  • Technology

Google’s Gemini: Pichai Bets Big on AI in 2025

Do Son December 29, 2024 0
Read More Read more about Google’s Gemini: Pichai Bets Big on AI in 2025
CVE-2024-33112 and More: How FICORA and CAPSAICIN Botnets Are Exploiting D-Link Devices Artivion cybersecurity - Zero-Day Attacks
  • Malware
  • Vulnerability

CVE-2024-33112 and More: How FICORA and CAPSAICIN Botnets Are Exploiting D-Link Devices

Do Son December 28, 2024 0
Read More Read more about CVE-2024-33112 and More: How FICORA and CAPSAICIN Botnets Are Exploiting D-Link Devices
NFC Nightmare: New NGate Trojan Drains Bank Accounts via ATMs NGate banking trojan
  • Malware

NFC Nightmare: New NGate Trojan Drains Bank Accounts via ATMs

Do Son December 28, 2024 0
Read More Read more about NFC Nightmare: New NGate Trojan Drains Bank Accounts via ATMs
reNgine: The Ultimate Web App Recon Suite Web App Recon
  • Open Source Tool

reNgine: The Ultimate Web App Recon Suite

Do Son December 28, 2024 0
Read More Read more about reNgine: The Ultimate Web App Recon Suite
FTC Probes Microsoft for Bundling Office with Cloud Services FTC Microsoft Bundling Office
  • Technology

FTC Probes Microsoft for Bundling Office with Cloud Services

Do Son December 28, 2024 0
Read More Read more about FTC Probes Microsoft for Bundling Office with Cloud Services
eSIMs: The Future of Connectivity, But Are Consumers Ready? SK Telecom data breach, long-term intrusion
  • Technology

eSIMs: The Future of Connectivity, But Are Consumers Ready?

Do Son December 28, 2024 0
Read More Read more about eSIMs: The Future of Connectivity, But Are Consumers Ready?
Can Trump Save TikTok? President-Elect Takes on Tech Giant’s Future TikTok USDS Joint Venture LLC, TikTok U.S. divestment 2026 TikTok Deal, ByteDance Divestment U.S. ban TikTok TikTok Sale, Trump Announcement TikTok lawsuit Trump Amazon Acquisition
  • Technology

Can Trump Save TikTok? President-Elect Takes on Tech Giant’s Future

Do Son December 28, 2024 0
Read More Read more about Can Trump Save TikTok? President-Elect Takes on Tech Giant’s Future
Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja Screenshot 2024-12-27 163504
  • Vulnerability

Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja

Do Son December 27, 2024 0
Read More Read more about Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja
Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist Zoom Node Vulnerability CVE-2026-22844 CVE-2024-45421 & CVE-2024-45419 CVE-2025-27440
  • Cyber Security
  • Malware

Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist

Do Son December 27, 2024 0
Read More Read more about Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist
Paper Werewolf: From Espionage to Destruction – A New Threat Emerges Iranian Espionage Seedworm group
  • Cyber Security

Paper Werewolf: From Espionage to Destruction – A New Threat Emerges

Do Son December 27, 2024 0
Read More Read more about Paper Werewolf: From Espionage to Destruction – A New Threat Emerges
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-106016CVSS 9.8
    Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.
    📅 Updated: Oct 7, 2026
  • CVE-2026-103877CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105636CVSS 9.9
    Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105641CVSS 9.8
    Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly...
    📅 Updated: Oct 7, 2026
  • CVE-2020-9547CVSS 9.8
    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
    📅 Updated: Oct 7, 2026
  • CVE-2026-95106CVSS 9.1
    Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject....
    📅 Updated: Oct 7, 2026
  • CVE-2026-94205CVSS 9.8
    Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the...
    📅 Updated: Oct 7, 2026
  • CVE-2026-86345CVSS 9.0
    A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.