Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Romanian National Sentenced to 20 Years for NetWalker Ransomware Attacks Operation IconCat, UNG0801 AFP cyberattack -NetWalker Ransomware VShell RAT
  • Cyber Security

Romanian National Sentenced to 20 Years for NetWalker Ransomware Attacks

Do Son December 19, 2024 0
Read More Read more about Romanian National Sentenced to 20 Years for NetWalker Ransomware Attacks
CVE-2024-12727 and More: Sophos Issues Urgent Firewall Security Update CVE-2024-12727 CVE-2024-12728 CVE-2024-12729
  • Vulnerability

CVE-2024-12727 and More: Sophos Issues Urgent Firewall Security Update

Do Son December 19, 2024 0
Read More Read more about CVE-2024-12727 and More: Sophos Issues Urgent Firewall Security Update
PoC Exploit Released for Databricks Remote Code Execution Vulnerability CVE-2024-49194 CVE-2024-49194 PoC
  • Vulnerability

PoC Exploit Released for Databricks Remote Code Execution Vulnerability CVE-2024-49194

Do Son December 19, 2024 0
Read More Read more about PoC Exploit Released for Databricks Remote Code Execution Vulnerability CVE-2024-49194
Phishing Campaign Targets European Companies with Fake HubSpot and DocuSign Forms HubSpot phishing campaign
  • Cyber Security

Phishing Campaign Targets European Companies with Fake HubSpot and DocuSign Forms

Do Son December 19, 2024 0
Read More Read more about Phishing Campaign Targets European Companies with Fake HubSpot and DocuSign Forms
CVE-2024-49576 and CVE-2024-47810: Foxit Addresses Remote Code Execution Flaws CVE-2024-49576 and CVE-2024-47810
  • Vulnerability

CVE-2024-49576 and CVE-2024-47810: Foxit Addresses Remote Code Execution Flaws

Do Son December 19, 2024 0
Read More Read more about CVE-2024-49576 and CVE-2024-47810: Foxit Addresses Remote Code Execution Flaws
TA397 Leverages Sophisticated Spearphishing Techniques to Deploy Malware in Defense Sector TEMPEST attacks
  • Cyber Security
  • Malware

TA397 Leverages Sophisticated Spearphishing Techniques to Deploy Malware in Defense Sector

Do Son December 19, 2024 0
Read More Read more about TA397 Leverages Sophisticated Spearphishing Techniques to Deploy Malware in Defense Sector
Malicious App Found on Amazon Appstore Masquerades as Health Tool Fiverr Data Leak Claude Code Leak Anthropic DMCA Takedown Coupang 33.7M Breach South Korea Data Leak Red Hat Breach, Customer Data Theft Farmers Insurance, Salesforce ESLint Plugin -Mamont Android banking Trojan
  • Malware

Malicious App Found on Amazon Appstore Masquerades as Health Tool

Do Son December 19, 2024 0
Read More Read more about Malicious App Found on Amazon Appstore Masquerades as Health Tool
Beware of Malicious Extensions: Researcher Exposes VSCode Marketplace Threats MuddyWater APT ANY.RUN security incident
  • Malware

Beware of Malicious Extensions: Researcher Exposes VSCode Marketplace Threats

Do Son December 19, 2024 0
Read More Read more about Beware of Malicious Extensions: Researcher Exposes VSCode Marketplace Threats
CVE-2024-49775 (CVSS 9.8): Critical Vulnerability in Siemens UMC Exposes Systems to Remote Exploitation ROS# Path Traversal CVE-2026-41551 Siemens SIMATIC Auth Bypass, CVE-2025-40771 CVE-2024-22039 & CVE-2024-49775 CVE-2024-56336
  • Vulnerability

CVE-2024-49775 (CVSS 9.8): Critical Vulnerability in Siemens UMC Exposes Systems to Remote Exploitation

Do Son December 19, 2024 0
Read More Read more about CVE-2024-49775 (CVSS 9.8): Critical Vulnerability in Siemens UMC Exposes Systems to Remote Exploitation
cShell DDoS Bot Exploits Poorly Managed Linux SSH Servers exfiltrating AWS credentials - fabrice package
  • Malware

cShell DDoS Bot Exploits Poorly Managed Linux SSH Servers

Do Son December 19, 2024 0
Read More Read more about cShell DDoS Bot Exploits Poorly Managed Linux SSH Servers
Earth Koshchei’s Rogue RDP Campaign: A Sophisticated APT Attack Targets Governments and Enterprises threat group Earth Koshchei
  • Cyber Security

Earth Koshchei’s Rogue RDP Campaign: A Sophisticated APT Attack Targets Governments and Enterprises

Do Son December 19, 2024 0
Read More Read more about Earth Koshchei’s Rogue RDP Campaign: A Sophisticated APT Attack Targets Governments and Enterprises
Weaponized Hacktivism: How Countries Use Activists for Cyber Warfare IARPA Research Security Data Abyss Report Telecom threat, Secret Service cybersecurity news - Cyber Espionage Campaign
  • Cyber Security

Weaponized Hacktivism: How Countries Use Activists for Cyber Warfare

Do Son December 19, 2024 0
Read More Read more about Weaponized Hacktivism: How Countries Use Activists for Cyber Warfare
Kaspersky Uncovers Active Exploitation of Fortinet Vulnerability CVE-2023-48788 FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Cyber Security
  • Vulnerability

Kaspersky Uncovers Active Exploitation of Fortinet Vulnerability CVE-2023-48788

Do Son December 19, 2024 0
Read More Read more about Kaspersky Uncovers Active Exploitation of Fortinet Vulnerability CVE-2023-48788
CVE-2023-34990 (CVSS 9.8): Critical Security Flaw Found in Fortinet FortiWLM CVE-2026-25089 CVE-2023-45590
  • Vulnerability

CVE-2023-34990 (CVSS 9.8): Critical Security Flaw Found in Fortinet FortiWLM

Do Son December 18, 2024 0
Read More Read more about CVE-2023-34990 (CVSS 9.8): Critical Security Flaw Found in Fortinet FortiWLM
CVE-2024-51479: Next.js Authorization Bypass Vulnerability Affects Millions of Developers CVE-2024-51479
  • Vulnerability

CVE-2024-51479: Next.js Authorization Bypass Vulnerability Affects Millions of Developers

Do Son December 18, 2024 0
Read More Read more about CVE-2024-51479: Next.js Authorization Bypass Vulnerability Affects Millions of Developers
VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns UAT-8099 BadIIS Malware Pacific Islands Forum Cyberattack
  • Malware
  • Vulnerability

VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns

Do Son December 18, 2024 0
Read More Read more about VIPKeyLogger: A New Infostealer Targeting Sensitive Data via Phishing Campaigns
Azure Key Vault Vulnerability: Exploiting Role Misconfigurations for Privilege Escalation Azure outage, Front Door Microsoft Azure Surveillance, Gaza Call Records Red Sea cables, Azure outage MFA enforcement Azure outage, Red Sea cables Azure Key Vault Azure, Surveillance
  • Vulnerability

Azure Key Vault Vulnerability: Exploiting Role Misconfigurations for Privilege Escalation

Do Son December 18, 2024 0
Read More Read more about Azure Key Vault Vulnerability: Exploiting Role Misconfigurations for Privilege Escalation
CVE-2024-10205: Critical Authentication Bypass Flaw Found in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer CVE-2024-10205
  • Vulnerability

CVE-2024-10205: Critical Authentication Bypass Flaw Found in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer

Do Son December 18, 2024 0
Read More Read more about CVE-2024-10205: Critical Authentication Bypass Flaw Found in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer
“Mamont” Android Banking Trojan Disguised as Parcel Tracking App Targets Thousands in Russia Fiverr Data Leak Claude Code Leak Anthropic DMCA Takedown Coupang 33.7M Breach South Korea Data Leak Red Hat Breach, Customer Data Theft Farmers Insurance, Salesforce ESLint Plugin -Mamont Android banking Trojan
  • Malware

“Mamont” Android Banking Trojan Disguised as Parcel Tracking App Targets Thousands in Russia

Do Son December 18, 2024 0
Read More Read more about “Mamont” Android Banking Trojan Disguised as Parcel Tracking App Targets Thousands in Russia
CVE-2024-12356 (CVSS 9.8): Critical Vulnerability in BeyondTrust PRA and RS Enables Remote Code Execution BeyondTrust Vulnerability CVE-2026-1731 CVE-2024-12356 - CVE-2025-0889 BeyondTrust Privilege Escalation, Windows Security
  • Vulnerability

CVE-2024-12356 (CVSS 9.8): Critical Vulnerability in BeyondTrust PRA and RS Enables Remote Code Execution

Do Son December 18, 2024 0
Read More Read more about CVE-2024-12356 (CVSS 9.8): Critical Vulnerability in BeyondTrust PRA and RS Enables Remote Code Execution
BADBOX Botnet Rises Again: 192,000+ Android Devices Compromised BADBOX Botnet
  • Malware

BADBOX Botnet Rises Again: 192,000+ Android Devices Compromised

Do Son December 18, 2024 0
Read More Read more about BADBOX Botnet Rises Again: 192,000+ Android Devices Compromised
Data Exfiltration and RCE Risks Found in Azure Data Factory’s Airflow Integration Azure Data Factory Apache Airflow - Dirty DAG vulnerabilities
  • Vulnerability

Data Exfiltration and RCE Risks Found in Azure Data Factory’s Airflow Integration

Do Son December 18, 2024 0
Read More Read more about Data Exfiltration and RCE Risks Found in Azure Data Factory’s Airflow Integration
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105763CVSS 9.6
    Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /metadata GraphQL connectedAccounts query...
    📅 Updated: Oct 8, 2026
  • CVE-2025-71383CVSS 9.8
    Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed via a request (from the local...
    📅 Updated: Oct 8, 2026
  • CVE-2026-106016CVSS 9.8
    Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.
    📅 Updated: Oct 7, 2026
  • CVE-2026-103877CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105636CVSS 9.9
    Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post()...
    📅 Updated: Oct 7, 2026
  • CVE-2026-105641CVSS 9.8
    Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly...
    📅 Updated: Oct 7, 2026
  • CVE-2020-9547CVSS 9.8
    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
    📅 Updated: Oct 7, 2026
  • CVE-2026-107282CVSS 9.4
    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.