Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
$5 Million Reward Offered After Indictment of North Korean Cyber Operatives North Korean Cyber Operatives
  • Cyber Security

$5 Million Reward Offered After Indictment of North Korean Cyber Operatives

Do Son December 12, 2024 0
Read More Read more about $5 Million Reward Offered After Indictment of North Korean Cyber Operatives
Secure Email Gateways Fail to Stop Advanced Phishing Campaign Targeting Multiple Industries BiDi Swap, phishing attacks Cybersecurity Threats
  • Cyber Security

Secure Email Gateways Fail to Stop Advanced Phishing Campaign Targeting Multiple Industries

Do Son December 12, 2024 0
Read More Read more about Secure Email Gateways Fail to Stop Advanced Phishing Campaign Targeting Multiple Industries
International Cybercrime Ring Dismantled: Rydox Marketplace Seized and Administrators Arrested Rydox Marketplace Seize
  • Cyber Security

International Cybercrime Ring Dismantled: Rydox Marketplace Seized and Administrators Arrested

Do Son December 12, 2024 0
Read More Read more about International Cybercrime Ring Dismantled: Rydox Marketplace Seized and Administrators Arrested
APT-C-60 Exploits Legitimate Services in Sophisticated Malware Attack Targeting Japanese Organizations SpyGrace malware
  • Cyber Security
  • Malware

APT-C-60 Exploits Legitimate Services in Sophisticated Malware Attack Targeting Japanese Organizations

Do Son December 12, 2024 0
Read More Read more about APT-C-60 Exploits Legitimate Services in Sophisticated Malware Attack Targeting Japanese Organizations
State Management Architecture. Part 1. From Traditional Redux to RTK tech-computer
  • Technique

State Management Architecture. Part 1. From Traditional Redux to RTK

Dan Agbo December 12, 2024
Read More Read more about State Management Architecture. Part 1. From Traditional Redux to RTK
Operation PowerOFF: Europol Cracks Down on Global DDoS-for-Hire Platforms DDoS-for-Hire Platform
  • Cyber Security

Operation PowerOFF: Europol Cracks Down on Global DDoS-for-Hire Platforms

Do Son December 12, 2024 0
Read More Read more about Operation PowerOFF: Europol Cracks Down on Global DDoS-for-Hire Platforms
EagleMsgSpy: Unmasking a Sophisticated Chinese Surveillance Tool Honeywell CCTV Vulnerability CVE-2026-1670 EagleMsgSpy Spyware Tool ResidentBat Spyware, Belarusian KGB Surveillance
  • Data Leak
  • Malware

EagleMsgSpy: Unmasking a Sophisticated Chinese Surveillance Tool

Do Son December 12, 2024 0
Read More Read more about EagleMsgSpy: Unmasking a Sophisticated Chinese Surveillance Tool
CVE-2024-53677 (CVSS 9.5): Critical Vulnerability in Apache Struts Allows Remote Code Execution CVE-2024-53677 Apache Struts 2 DoS, File Leak Vulnerability
  • Vulnerability

CVE-2024-53677 (CVSS 9.5): Critical Vulnerability in Apache Struts Allows Remote Code Execution

Do Son December 11, 2024 0
Read More Read more about CVE-2024-53677 (CVSS 9.5): Critical Vulnerability in Apache Struts Allows Remote Code Execution
PoC Exploit Code Releases Cleo Zero-Day Vulnerability (CVE-2024-50623) FortiClient EMS exploitation Cisco FIRESTARTER Backdoor Arcane Door Campaign Dell RecoverPoint Zero-Day UNC6201 Espionage Notepad++ Compromise Supply Chain Attack Magento SessionReaper CVE-2025-54236 ShadowRay 2.0, AI-Generated Malware WordPress Auth Bypass, CVE-2025-5947 Exploited EcoStruxure Vulnerabilities, Industrial Control System UNC5820 - CVE-2014-2120 - CVE-2021-44207
  • Vulnerability

PoC Exploit Code Releases Cleo Zero-Day Vulnerability (CVE-2024-50623)

Do Son December 11, 2024 0
Read More Read more about PoC Exploit Code Releases Cleo Zero-Day Vulnerability (CVE-2024-50623)
“Aggressive Inventory Zombies”: Unmasking a Massive Phishing and Pig-Butchering Network Evil Corp
  • Cyber Security

“Aggressive Inventory Zombies”: Unmasking a Massive Phishing and Pig-Butchering Network

Do Son December 11, 2024 0
Read More Read more about “Aggressive Inventory Zombies”: Unmasking a Massive Phishing and Pig-Butchering Network
BadRAM Vulnerability (CVE-2024-21944): Researchers Uncover Security Flaw in AMD SEV CVE-2024-21944 - BadRAM vulnerability
  • Vulnerability

BadRAM Vulnerability (CVE-2024-21944): Researchers Uncover Security Flaw in AMD SEV

Do Son December 11, 2024 0
Read More Read more about BadRAM Vulnerability (CVE-2024-21944): Researchers Uncover Security Flaw in AMD SEV
Zloader Trojan Employs Novel DNS Tunneling Protocol for Enhanced Evasion Chinese espionage groups APT35 Phishing, Stormshield CTI
  • Malware

Zloader Trojan Employs Novel DNS Tunneling Protocol for Enhanced Evasion

Do Son December 11, 2024 0
Read More Read more about Zloader Trojan Employs Novel DNS Tunneling Protocol for Enhanced Evasion
Malicious npm Package Mimics ESLint Plugin, Steals Sensitive Data Fiverr Data Leak Claude Code Leak Anthropic DMCA Takedown Coupang 33.7M Breach South Korea Data Leak Red Hat Breach, Customer Data Theft Farmers Insurance, Salesforce ESLint Plugin -Mamont Android banking Trojan
  • Malware

Malicious npm Package Mimics ESLint Plugin, Steals Sensitive Data

Do Son December 11, 2024 0
Read More Read more about Malicious npm Package Mimics ESLint Plugin, Steals Sensitive Data
CVE-2024-11274: GitLab Vulnerability Exposes User Accounts GitLab Security Update CVE-2025-7659 CVE-2024-5655 GitLab Vulnerabilities, XSS & Data Exposure
  • Vulnerability

CVE-2024-11274: GitLab Vulnerability Exposes User Accounts

Do Son December 11, 2024 0
Read More Read more about CVE-2024-11274: GitLab Vulnerability Exposes User Accounts
ChatGPT and Sora Go Offline: OpenAI Scrambles to Restore Service Amid Global Outage ChatGPT and Sora Outage
  • Technology

ChatGPT and Sora Go Offline: OpenAI Scrambles to Restore Service Amid Global Outage

Do Son December 11, 2024 0
Read More Read more about ChatGPT and Sora Go Offline: OpenAI Scrambles to Restore Service Amid Global Outage
CVE-2024-53247: Splunk Secure Gateway App Vulnerability Allows Remote Code Execution Splunk Enterprise vulnerabilities, CVSS 9.8 flaw, CVE-2026-20253, CVE-2026-20251, CVE-2026-20258 Splunk Enterprise Vulnerabilities CVE-2026-20240 Splunk RCE CVE-2026-20204 Splunk RCE Vulnerability CVE-2026-20163 Splunk Enterprise Vulnerabilities CVE-2026-20140 Splunk Permission Flaw, Local Privilege Escalation Splunk Vulnerabilities CVE-2024-53247 - Splunk Secure Gateway App CVE-2025-20229 & CVE-2025-20231
  • Vulnerability

CVE-2024-53247: Splunk Secure Gateway App Vulnerability Allows Remote Code Execution

Do Son December 11, 2024 0
Read More Read more about CVE-2024-53247: Splunk Secure Gateway App Vulnerability Allows Remote Code Execution
Android Users Targeted: AppLite Trojan Disguised as Popular Apps tech-threat
  • Malware

Android Users Targeted: AppLite Trojan Disguised as Popular Apps

Do Son December 11, 2024 0
Read More Read more about Android Users Targeted: AppLite Trojan Disguised as Popular Apps
CVE-2020-12271 Exploited: FBI Seeks Chinese Hacker Behind 81,000 Device Breach CVE 2020-12271 - Guan Tianfeng
  • Cyber Security
  • Vulnerability

CVE-2020-12271 Exploited: FBI Seeks Chinese Hacker Behind 81,000 Device Breach

Do Son December 11, 2024 0
Read More Read more about CVE-2020-12271 Exploited: FBI Seeks Chinese Hacker Behind 81,000 Device Breach
Operation Digital Eye: Chinese APT Exploits Visual Studio Code Tunnels in High-Stakes Espionage Campaign Operation Digital Eye
  • Cyber Security
  • Malware

Operation Digital Eye: Chinese APT Exploits Visual Studio Code Tunnels in High-Stakes Espionage Campaign

Do Son December 11, 2024 0
Read More Read more about Operation Digital Eye: Chinese APT Exploits Visual Studio Code Tunnels in High-Stakes Espionage Campaign
CVE-2024-11639 (CVSS 10) – Critical Flaw in Ivanti Cloud Services Application: Immediate Patch Recommended CVE-2023-35081 & CVE-2024-11639
  • Vulnerability

CVE-2024-11639 (CVSS 10) – Critical Flaw in Ivanti Cloud Services Application: Immediate Patch Recommended

Do Son December 10, 2024 0
Read More Read more about CVE-2024-11639 (CVSS 10) – Critical Flaw in Ivanti Cloud Services Application: Immediate Patch Recommended
UAC-0185 APT Leverages Social Engineering to Target Ukrainian Defense Industrial Base UAC-0185 - MESHAGENT RAT
  • Cyber Security
  • Malware

UAC-0185 APT Leverages Social Engineering to Target Ukrainian Defense Industrial Base

Do Son December 10, 2024 0
Read More Read more about UAC-0185 APT Leverages Social Engineering to Target Ukrainian Defense Industrial Base
Ivanti Connect Secure and Policy Secure Updates Address Critical Vulnerabilities Ivanti EPMM security updates Ivanti ITSM vulnerability authenticated privilege escalation Ivanti Xtraction vulnerability CVE-2026-8043 Ivanti EPM RCE, SQL Injection Ivanti EPM, remote code execution CVE-2024-50330 - CVE-2025-0282 and CVE-2025-0283
  • Vulnerability

Ivanti Connect Secure and Policy Secure Updates Address Critical Vulnerabilities

Do Son December 10, 2024 0
Read More Read more about Ivanti Connect Secure and Policy Secure Updates Address Critical Vulnerabilities
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-85097CVSS 9.8
    The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including,...
    📅 Updated: Oct 8, 2026
  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17609CVSS 9.1
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102782CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass...
    📅 Updated: Oct 8, 2026
  • CVE-2026-48908CVSS 10.0
    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
  • CVE-2026-56290CVSS 10.0
    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
  • CVE-2026-93674CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper...
    📅 Updated: Oct 8, 2026
  • CVE-2026-79805CVSS 9.8
    An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.