Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Hackers exploit critical Apache Struts RCE flaw (CVE-2024-53677) after PoC exploit release CoinMarketCap Hack, Inferno Drainer CVE-2024-53677 PoC Exploit
  • Vulnerability

Hackers exploit critical Apache Struts RCE flaw (CVE-2024-53677) after PoC exploit release

Do Son December 16, 2024 0
Read More Read more about Hackers exploit critical Apache Struts RCE flaw (CVE-2024-53677) after PoC exploit release
CVE-2024-55661: RCE Vulnerability Discovered in Laravel Pulse Monitoring Tool Laravel Pulse - CVE-2024-55661
  • Vulnerability

CVE-2024-55661: RCE Vulnerability Discovered in Laravel Pulse Monitoring Tool

Do Son December 16, 2024 0
Read More Read more about CVE-2024-55661: RCE Vulnerability Discovered in Laravel Pulse Monitoring Tool
Threat Actors Exploit Fake Brand Collaborations to Target YouTube Channels YouTube deepfake YouTube AI YouTube Premium YouTube Ad Blockers, Fake Buffering Google Lens, YouTube Shorts
  • Cyber Security

Threat Actors Exploit Fake Brand Collaborations to Target YouTube Channels

Do Son December 16, 2024 0
Read More Read more about Threat Actors Exploit Fake Brand Collaborations to Target YouTube Channels
Easy Money Online? FTC Warns of Exploding “Task Scam” Threat task scam report
  • Cyber Security

Easy Money Online? FTC Warns of Exploding “Task Scam” Threat

Do Son December 16, 2024 0
Read More Read more about Easy Money Online? FTC Warns of Exploding “Task Scam” Threat
Critical Windows and Adobe ColdFusion Vulnerabilities Actively Exploited in the Wild, PoC Exploit Published Adobe ColdFusion Vulnerabilities
  • Vulnerability

Critical Windows and Adobe ColdFusion Vulnerabilities Actively Exploited in the Wild, PoC Exploit Published

Do Son December 16, 2024 0
Read More Read more about Critical Windows and Adobe ColdFusion Vulnerabilities Actively Exploited in the Wild, PoC Exploit Published
HeartCrypt: A Packer-as-a-Service Fueling Malware Campaigns Operation IconCat, UNG0801 AFP cyberattack -NetWalker Ransomware VShell RAT
  • Malware

HeartCrypt: A Packer-as-a-Service Fueling Malware Campaigns

Do Son December 16, 2024 0
Read More Read more about HeartCrypt: A Packer-as-a-Service Fueling Malware Campaigns
CVE-2024-55875 (CVSS 9.8): Critical XXE Vulnerability Found in http4k Toolkit CVE-2024-55875
  • Vulnerability

CVE-2024-55875 (CVSS 9.8): Critical XXE Vulnerability Found in http4k Toolkit

Do Son December 16, 2024 0
Read More Read more about CVE-2024-55875 (CVSS 9.8): Critical XXE Vulnerability Found in http4k Toolkit
SADBRIDGE Loader Unveils GOSAR Backdoor in Cyber Attacks XZ backdoor, Docker Hub MIFARE classic backdoor C++/CLI IIS Backdoor
  • Malware

SADBRIDGE Loader Unveils GOSAR Backdoor in Cyber Attacks

Do Son December 16, 2024 0
Read More Read more about SADBRIDGE Loader Unveils GOSAR Backdoor in Cyber Attacks
NodeLoader: A New Malware Family Exploits Node.js for Stealthy Attacks Screenshot 2024-12-15 150821
  • Malware

NodeLoader: A New Malware Family Exploits Node.js for Stealthy Attacks

Do Son December 16, 2024 0
Read More Read more about NodeLoader: A New Malware Family Exploits Node.js for Stealthy Attacks
Voice Phishing on Microsoft Teams Facilitates DarkGate Malware Attack voice phishing
  • Cyber Security
  • Malware

Voice Phishing on Microsoft Teams Facilitates DarkGate Malware Attack

Do Son December 16, 2024 0
Read More Read more about Voice Phishing on Microsoft Teams Facilitates DarkGate Malware Attack
Hackers Hack Hackers: MUT-1244 Steals Credentials in Deceptive GitHub Attack 67344006c9d78
  • Cyber Security
  • Malware

Hackers Hack Hackers: MUT-1244 Steals Credentials in Deceptive GitHub Attack

Do Son December 16, 2024 0
Read More Read more about Hackers Hack Hackers: MUT-1244 Steals Credentials in Deceptive GitHub Attack
OpenAI Services Hit by Major Outage Due to Telemetry Service Deployment OpenAI Major Outage - Time Bandit GPT-4.5 Phase-Out
  • Technology

OpenAI Services Hit by Major Outage Due to Telemetry Service Deployment

Do Son December 15, 2024 0
Read More Read more about OpenAI Services Hit by Major Outage Due to Telemetry Service Deployment
CVE-2024-38819: Spring Framework Path Traversal PoC Exploit Released CVE-2024-38819 PoC
  • Vulnerability

CVE-2024-38819: Spring Framework Path Traversal PoC Exploit Released

Do Son December 15, 2024 0
Read More Read more about CVE-2024-38819: Spring Framework Path Traversal PoC Exploit Released
Open Sesame Attack: Ruijie Networks Devices Vulnerable to Remote Takeover Open Sesame attack - CVE-2024-52324
  • Vulnerability

Open Sesame Attack: Ruijie Networks Devices Vulnerable to Remote Takeover

Do Son December 15, 2024 0
Read More Read more about Open Sesame Attack: Ruijie Networks Devices Vulnerable to Remote Takeover
CVE-2024-45337: Golang Crypto Library Flawed, Risks Authorization Bypass CVE-2024-45337
  • Vulnerability

CVE-2024-45337: Golang Crypto Library Flawed, Risks Authorization Bypass

Do Son December 15, 2024 0
Read More Read more about CVE-2024-45337: Golang Crypto Library Flawed, Risks Authorization Bypass
Russian APT “Secret Blizzard” Leverages Cybercriminal Tools in Ukraine Attacks exfiltrating AWS credentials - fabrice package
  • Cyber Security
  • Malware

Russian APT “Secret Blizzard” Leverages Cybercriminal Tools in Ukraine Attacks

Do Son December 15, 2024 0
Read More Read more about Russian APT “Secret Blizzard” Leverages Cybercriminal Tools in Ukraine Attacks
Google Ads Abused in Graphic Design Malvertising Attack Ongoing Malvertising Campaign
  • Cyber Security
  • Malware

Google Ads Abused in Graphic Design Malvertising Attack

Do Son December 15, 2024 0
Read More Read more about Google Ads Abused in Graphic Design Malvertising Attack
CVE-2024-55884 (CVSS 9.0): Critical Vulnerability Found in Mullvad VPN Mullvad_logo.svg
  • Vulnerability

CVE-2024-55884 (CVSS 9.0): Critical Vulnerability Found in Mullvad VPN

Do Son December 15, 2024 0
Read More Read more about CVE-2024-55884 (CVSS 9.0): Critical Vulnerability Found in Mullvad VPN
Passkeys: Microsoft’s Solution to 7,000 Password Attacks Per Second Microsoft passkey
  • Technology

Passkeys: Microsoft’s Solution to 7,000 Password Attacks Per Second

Do Son December 15, 2024 0
Read More Read more about Passkeys: Microsoft’s Solution to 7,000 Password Attacks Per Second
336,000 Prometheus Servers at Risk: Urgent Security Alert Screenshot 2024-12-15 135137
  • Vulnerability

336,000 Prometheus Servers at Risk: Urgent Security Alert

Do Son December 15, 2024 0
Read More Read more about 336,000 Prometheus Servers at Risk: Urgent Security Alert
The Zero-Detection PHP Backdoor Glutton Exposed Glutton backdoor
  • Cyber Security
  • Malware

The Zero-Detection PHP Backdoor Glutton Exposed

Do Son December 15, 2024 0
Read More Read more about The Zero-Detection PHP Backdoor Glutton Exposed
Multiple Critical Vulnerabilities Expose GLPI to Widespread Attacks GLPI - CVE-2024-50339
  • Vulnerability

Multiple Critical Vulnerabilities Expose GLPI to Widespread Attacks

Do Son December 15, 2024 0
Read More Read more about Multiple Critical Vulnerabilities Expose GLPI to Widespread Attacks
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17609CVSS 9.1
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102782CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass...
    📅 Updated: Oct 8, 2026
  • CVE-2026-48908CVSS 10.0
    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
  • CVE-2026-56290CVSS 10.0
    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 8, 2026
  • CVE-2026-79805CVSS 9.8
    An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read...
    📅 Updated: Oct 8, 2026
  • CVE-2026-79801CVSS 9.8
    A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.