Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja Screenshot 2024-12-27 163504
  • Vulnerability

Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja

Do Son December 27, 2024 0
Read More Read more about Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja
Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist Zoom Node Vulnerability CVE-2026-22844 CVE-2024-45421 & CVE-2024-45419 CVE-2025-27440
  • Cyber Security
  • Malware

Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist

Do Son December 27, 2024 0
Read More Read more about Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist
Paper Werewolf: From Espionage to Destruction – A New Threat Emerges Iranian Espionage Seedworm group
  • Cyber Security

Paper Werewolf: From Espionage to Destruction – A New Threat Emerges

Do Son December 27, 2024 0
Read More Read more about Paper Werewolf: From Espionage to Destruction – A New Threat Emerges
Microsoft Announces Critical Change to .NET Installer Distribution Domains .NET Installer Distribution Domains
  • Technology

Microsoft Announces Critical Change to .NET Installer Distribution Domains

Do Son December 27, 2024 0
Read More Read more about Microsoft Announces Critical Change to .NET Installer Distribution Domains
Xiaomi Limits HyperOS Bootloader Unlocking to One Device Per Account Xiaomi Bootloader Unlocking Chinese OS, Google alternative
  • Technology

Xiaomi Limits HyperOS Bootloader Unlocking to One Device Per Account

Do Son December 27, 2024 0
Read More Read more about Xiaomi Limits HyperOS Bootloader Unlocking to One Device Per Account
Cyberhaven Chrome Extension Compromised in Targeted Attack Cyberhaven Chrome Extension Attack
  • Cyber Security

Cyberhaven Chrome Extension Compromised in Targeted Attack

Do Son December 26, 2024 0
Read More Read more about Cyberhaven Chrome Extension Compromised in Targeted Attack
Rust Lands in Windows 11 Kernel: A New Era for OS Security? Microsoft Patch Tuesday CVE-2026-20805 RasMan Crash Flaw, 0patch Micropatch ASP.NET Core, HTTP smuggling Windows kernel Rust ActiveX, Microsoft 365
  • Windows

Rust Lands in Windows 11 Kernel: A New Era for OS Security?

Do Son December 26, 2024 0
Read More Read more about Rust Lands in Windows 11 Kernel: A New Era for OS Security?
.KG Domain Drama: US.KG Briefly Suspended, Now Restored sign-107860_1280
  • Technology

.KG Domain Drama: US.KG Briefly Suspended, Now Restored

Do Son December 26, 2024 0
Read More Read more about .KG Domain Drama: US.KG Briefly Suspended, Now Restored
CVE-2024-3393: PAN-OS Vulnerability Now Exploited in the Wild CVE-2024-3393 - Zservers sanctions
  • Vulnerability

CVE-2024-3393: PAN-OS Vulnerability Now Exploited in the Wild

Do Son December 26, 2024 0
Read More Read more about CVE-2024-3393: PAN-OS Vulnerability Now Exploited in the Wild
Google Impersonation Scams: Cybersecurity Expert Reveals Alarming Tactics phishing-3390518_1280
  • Cyber Security

Google Impersonation Scams: Cybersecurity Expert Reveals Alarming Tactics

Do Son December 26, 2024 0
Read More Read more about Google Impersonation Scams: Cybersecurity Expert Reveals Alarming Tactics
$3 Million Bitcoin Ransom: Brazilian Man Charged in US Cyber Extortion Open VSX Malware String-Fragment Reconstruction DarkCloud Stealer, steganography APT 35 Charming Kitten cyclops
  • Cyber Security

$3 Million Bitcoin Ransom: Brazilian Man Charged in US Cyber Extortion

Do Son December 26, 2024 0
Read More Read more about $3 Million Bitcoin Ransom: Brazilian Man Charged in US Cyber Extortion
“OtterCookie” Malware Nibbles at Developers in “Contagious Interview” Campaign SonicWall Reconnaissance Akira Ransomware residential proxy malware TraderTraitor BreachForums Honeypot, French Interior Ministry Leak
  • Cyber Security
  • Malware

“OtterCookie” Malware Nibbles at Developers in “Contagious Interview” Campaign

Do Son December 26, 2024 0
Read More Read more about “OtterCookie” Malware Nibbles at Developers in “Contagious Interview” Campaign
Japan Airlines Hit by Cyberattack: Ticket Sales Halted Japan Airlines Cyberattack
  • Cyber Security

Japan Airlines Hit by Cyberattack: Ticket Sales Halted

Do Son December 26, 2024 0
Read More Read more about Japan Airlines Hit by Cyberattack: Ticket Sales Halted
Are CAPTCHAs Dead? The Rise of AI-Powered Bots CAPTCHA AI bot
  • Technology

Are CAPTCHAs Dead? The Rise of AI-Powered Bots

Do Son December 26, 2024 0
Read More Read more about Are CAPTCHAs Dead? The Rise of AI-Powered Bots
CVE-2024-52046 (CVSS 10): Critical Apache MINA Flaw Could Allow Remote Code Execution Apache_MINA_Logo.svg
  • Vulnerability

CVE-2024-52046 (CVSS 10): Critical Apache MINA Flaw Could Allow Remote Code Execution

Do Son December 25, 2024 0
Read More Read more about CVE-2024-52046 (CVSS 10): Critical Apache MINA Flaw Could Allow Remote Code Execution
CVE-2024-40896 (CVSS 9.1): Critical XXE Vulnerability Discovered in libxml2 CVE-2024-40896
  • Vulnerability

CVE-2024-40896 (CVSS 9.1): Critical XXE Vulnerability Discovered in libxml2

Do Son December 25, 2024 0
Read More Read more about CVE-2024-40896 (CVSS 9.1): Critical XXE Vulnerability Discovered in libxml2
Trio of SQL Injection Flaws Strike Amazon Redshift Drivers: Patch Immediately CVE-2024-12744, CVE-2024-12745, and CVE-2024-12746
  • Vulnerability

Trio of SQL Injection Flaws Strike Amazon Redshift Drivers: Patch Immediately

Do Son December 25, 2024 0
Read More Read more about Trio of SQL Injection Flaws Strike Amazon Redshift Drivers: Patch Immediately
CVE-2024-43441: Authentication Bypass Vulnerability Found in Apache HugeGraph-Server CVE-2024-43441
  • Vulnerability

CVE-2024-43441: Authentication Bypass Vulnerability Found in Apache HugeGraph-Server

Do Son December 25, 2024 0
Read More Read more about CVE-2024-43441: Authentication Bypass Vulnerability Found in Apache HugeGraph-Server
Dark Web Identity Farming Operation Exposed: A Sophisticated KYC Fraud identity farming
  • Cyber Security
  • Data Leak

Dark Web Identity Farming Operation Exposed: A Sophisticated KYC Fraud

Do Son December 25, 2024 0
Read More Read more about Dark Web Identity Farming Operation Exposed: A Sophisticated KYC Fraud
European Space Agency Online Store Compromised: Stripe Payment Page Hijacked PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
  • Cyber Security

European Space Agency Online Store Compromised: Stripe Payment Page Hijacked

Do Son December 25, 2024 0
Read More Read more about European Space Agency Online Store Compromised: Stripe Payment Page Hijacked
PyPI Poisoned: “Zebo” and “Cometlogger” Downloaded Hundreds of Times GuLoader Malware CloudEye Obfuscation npm, malware Ethereum, npm supply chain OAST techniques StilachiRAT macOS Malware PasivRobber
  • Malware

PyPI Poisoned: “Zebo” and “Cometlogger” Downloaded Hundreds of Times

Do Son December 25, 2024 0
Read More Read more about PyPI Poisoned: “Zebo” and “Cometlogger” Downloaded Hundreds of Times
“Glic”: Google Chrome to Get Gemini Live Integration Chrome, Antitrust Browser Security, Local Network Access CVE-2022-3075 history-sniffing vulnerability
  • Technology

“Glic”: Google Chrome to Get Gemini Live Integration

Do Son December 25, 2024 0
Read More Read more about “Glic”: Google Chrome to Get Gemini Live Integration
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-106016CVSS 9.8
    Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.
    📅 Updated: Oct 7, 2026
  • CVE-2026-103877CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105636CVSS 9.9
    Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105641CVSS 9.8
    Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly...
    📅 Updated: Oct 7, 2026
  • CVE-2020-9547CVSS 9.8
    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
    📅 Updated: Oct 7, 2026
  • CVE-2026-95106CVSS 9.1
    Gitea accepted pushed Git trees containing two entries with the same name, which Git's own consistency checks reject....
    📅 Updated: Oct 7, 2026
  • CVE-2026-94205CVSS 9.8
    Gitea Actions decided whether a fork pull request run needed approval based on the user who triggered the...
    📅 Updated: Oct 7, 2026
  • CVE-2026-86345CVSS 9.0
    A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.