Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Manjaro 24.2 “Yonada” Released: A Refined and Feature-Rich Update Manjaro 24.2
  • Linux

Manjaro 24.2 “Yonada” Released: A Refined and Feature-Rich Update

Do Son December 8, 2024 0
Read More Read more about Manjaro 24.2 “Yonada” Released: A Refined and Feature-Rich Update
CVE-2024-12209 (CVSS 9.8): WP Umbrella Plugin Vulnerability Exposes 30,000 Websites to Compromise CVE-2024-12209 - WP Umbrella
  • Vulnerability

CVE-2024-12209 (CVSS 9.8): WP Umbrella Plugin Vulnerability Exposes 30,000 Websites to Compromise

Do Son December 7, 2024 0
Read More Read more about CVE-2024-12209 (CVSS 9.8): WP Umbrella Plugin Vulnerability Exposes 30,000 Websites to Compromise
Google’s Vanir: A Powerful New Open-Source Tool for Supercharging Security Patch Validation Google Vanir Tool
  • Open Source Tool
  • Technology

Google’s Vanir: A Powerful New Open-Source Tool for Supercharging Security Patch Validation

Do Son December 7, 2024 0
Read More Read more about Google’s Vanir: A Powerful New Open-Source Tool for Supercharging Security Patch Validation
SystemRescue 11.03 Boots Up with a Powerful New Kernel and Updated Tools! SystemRescue 11.03
  • Linux

SystemRescue 11.03 Boots Up with a Powerful New Kernel and Updated Tools!

Do Son December 7, 2024 0
Read More Read more about SystemRescue 11.03 Boots Up with a Powerful New Kernel and Updated Tools!
BlueAlpha Exploits Cloudflare Tunnels for GammaDrop Malware Infrastructure UAT-8099 BadIIS Malware Pacific Islands Forum Cyberattack
  • Cyber Security
  • Malware

BlueAlpha Exploits Cloudflare Tunnels for GammaDrop Malware Infrastructure

Do Son December 7, 2024 0
Read More Read more about BlueAlpha Exploits Cloudflare Tunnels for GammaDrop Malware Infrastructure
FSB-Tampered Device Returned with Monokle-Type Spyware, Experts Reveal Monokle spyware
  • Malware

FSB-Tampered Device Returned with Monokle-Type Spyware, Experts Reveal

Do Son December 7, 2024 0
Read More Read more about FSB-Tampered Device Returned with Monokle-Type Spyware, Experts Reveal
Earth Minotaur: MOONSHINE Exploit Kit and DarkNimbus Backdoor Threaten Multi-Platform Security CRussian Market, "Fly" (Flyded) hange Healthcare Cyberattack - CVE-2024-50603 Exploit
  • Cyber Security
  • Malware

Earth Minotaur: MOONSHINE Exploit Kit and DarkNimbus Backdoor Threaten Multi-Platform Security

Do Son December 6, 2024 0
Read More Read more about Earth Minotaur: MOONSHINE Exploit Kit and DarkNimbus Backdoor Threaten Multi-Platform Security
US Organization in China Falls Victim to Suspected Chinese Espionage Campaign Cisco SD-WAN Vulnerability CVE-2026-20127 CVE-2024-20481 - Daggerfly group
  • Cyber Security

US Organization in China Falls Victim to Suspected Chinese Espionage Campaign

Do Son December 6, 2024 0
Read More Read more about US Organization in China Falls Victim to Suspected Chinese Espionage Campaign
Sophisticated Campaign Targets Manufacturing Industry with Lumma Stealer and Amadey Bot XCharge C6 vulnerabilities EV charger security flaws GNU libtasn1 Vulnerability CVE-2025-13151 Credit Card Skimmer Malware CVE-2024-13892
  • Cyber Security
  • Malware

Sophisticated Campaign Targets Manufacturing Industry with Lumma Stealer and Amadey Bot

Do Son December 6, 2024 0
Read More Read more about Sophisticated Campaign Targets Manufacturing Industry with Lumma Stealer and Amadey Bot
Unpatched Zero-Day Vulnerability in Mitel MiCollab Exposes Businesses to Serious Security Risks Zyxel security - Mitel MiCollab Vulnerability
  • Vulnerability

Unpatched Zero-Day Vulnerability in Mitel MiCollab Exposes Businesses to Serious Security Risks

Do Son December 6, 2024 0
Read More Read more about Unpatched Zero-Day Vulnerability in Mitel MiCollab Exposes Businesses to Serious Security Risks
Kroah-Hartman Confirms: Linux Kernel 6.12 is Now LTS Linux Kernel legacy driver removal Linux kernel x86 page fault, interrupt state asymmetry fix Linux ISO, false positive CVE-2023-6200 - Linux Kernel 6.12 LTS 6.14
  • Linux

Kroah-Hartman Confirms: Linux Kernel 6.12 is Now LTS

Do Son December 6, 2024 0
Read More Read more about Kroah-Hartman Confirms: Linux Kernel 6.12 is Now LTS
Critical Zero-Day Vulnerability in Windows Exposes User Credentials Critical Zero-Day Vulnerability
  • Vulnerability

Critical Zero-Day Vulnerability in Windows Exposes User Credentials

Do Son December 5, 2024 0
Read More Read more about Critical Zero-Day Vulnerability in Windows Exposes User Credentials
Django Releases Patches for CVE-2024-53907 and CVE-2024-53908 to Mitigate DoS and SQLi Threats CVE-2024-53908 & CVE-2024-53907
  • Vulnerability

Django Releases Patches for CVE-2024-53907 and CVE-2024-53908 to Mitigate DoS and SQLi Threats

Do Son December 5, 2024 0
Read More Read more about Django Releases Patches for CVE-2024-53907 and CVE-2024-53908 to Mitigate DoS and SQLi Threats
Browser Isolation Bypassed: QR Codes Used in Novel C2 Attacks QR-Code
  • Cyber Security
  • Vulnerability

Browser Isolation Bypassed: QR Codes Used in Novel C2 Attacks

Do Son December 5, 2024 0
Read More Read more about Browser Isolation Bypassed: QR Codes Used in Novel C2 Attacks
Phishing, Fraud, and Stolen Data: Europol Takes Down Cybercrime Network Fraudulent shopping sites
  • Cyber Security

Phishing, Fraud, and Stolen Data: Europol Takes Down Cybercrime Network

Do Son December 5, 2024 0
Read More Read more about Phishing, Fraud, and Stolen Data: Europol Takes Down Cybercrime Network
CVE-2024-43222 (CVSS 9.8): Critical Flaw in Sweet Date WordPress Theme Exposes Thousands of Sites to Potential Takeovers CVE-2024-43222
  • Vulnerability

CVE-2024-43222 (CVSS 9.8): Critical Flaw in Sweet Date WordPress Theme Exposes Thousands of Sites to Potential Takeovers

Do Son December 5, 2024 0
Read More Read more about CVE-2024-43222 (CVSS 9.8): Critical Flaw in Sweet Date WordPress Theme Exposes Thousands of Sites to Potential Takeovers
iVerify Unveils Disturbing Prevalence of Pegasus Spyware on Mobile Devices Pegasus spyware sample
  • Malware

iVerify Unveils Disturbing Prevalence of Pegasus Spyware on Mobile Devices

Do Son December 5, 2024 0
Read More Read more about iVerify Unveils Disturbing Prevalence of Pegasus Spyware on Mobile Devices
Multiple Vulnerabilities in SonicWall SMA 100 Could Lead to Remote Code Execution SonicWall ES RCE, Code Integrity Bypass SonicWall SMA, Arbitrary File Upload SonicWall SMA100 - CVE-2024-40764
  • Vulnerability

Multiple Vulnerabilities in SonicWall SMA 100 Could Lead to Remote Code Execution

Do Son December 5, 2024 0
Read More Read more about Multiple Vulnerabilities in SonicWall SMA 100 Could Lead to Remote Code Execution
Russian Hacker Secret Blizzard Hijack C2 Infrastructure in New Espionage Campaign Secret Blizzard
  • Cyber Security
  • Malware

Russian Hacker Secret Blizzard Hijack C2 Infrastructure in New Espionage Campaign

Do Son December 5, 2024 0
Read More Read more about Russian Hacker Secret Blizzard Hijack C2 Infrastructure in New Espionage Campaign
CVE-2024-53990 (CVSS 9.2): AsyncHttpClient Vulnerability Puts Java Applications at Risk CVE-2024-53990
  • Vulnerability

CVE-2024-53990 (CVSS 9.2): AsyncHttpClient Vulnerability Puts Java Applications at Risk

Do Son December 5, 2024 0
Read More Read more about CVE-2024-53990 (CVSS 9.2): AsyncHttpClient Vulnerability Puts Java Applications at Risk
DroidBot: A New Android Threat Exposes Global Financial Institutions Forum post advertising a new Android bot
  • Malware

DroidBot: A New Android Threat Exposes Global Financial Institutions

Do Son December 5, 2024 0
Read More Read more about DroidBot: A New Android Threat Exposes Global Financial Institutions
Black Basta Resurgence: Social Engineering Campaign Delivers Zbot, DarkGate, and Custom Malware Screenshot 2024-12-05 145929
  • Malware

Black Basta Resurgence: Social Engineering Campaign Delivers Zbot, DarkGate, and Custom Malware

Do Son December 5, 2024 0
Read More Read more about Black Basta Resurgence: Social Engineering Campaign Delivers Zbot, DarkGate, and Custom Malware
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-107510CVSS 9.1
    An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.
    📅 Updated: Oct 8, 2026
  • CVE-2026-105110CVSS 9.3
    OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote...
    📅 Updated: Oct 8, 2026
  • CVE-2026-12260CVSS 10.0
    SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in...
    📅 Updated: Oct 8, 2026
  • CVE-2026-85097CVSS 9.8
    The Bricksforge plugin for WordPress is vulnerable to unauthenticated arbitrary file upload in versions up to, and including,...
    📅 Updated: Oct 8, 2026
  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17609CVSS 9.1
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102782CVSS 9.3
    Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass...
    📅 Updated: Oct 8, 2026
  • CVE-2026-48908CVSS 10.0
    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in...
    CISA KEV📅 Added to KEV: Jul 7, 2026📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.