Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Cyber Espionage Campaign: North Korean Actors Deploy BeaverTail and InvisibleFerret North Korean Cyber Tactics
  • Malware

Cyber Espionage Campaign: North Korean Actors Deploy BeaverTail and InvisibleFerret

Do Son November 15, 2024 0
Read More Read more about Cyber Espionage Campaign: North Korean Actors Deploy BeaverTail and InvisibleFerret
New Melofee Backdoor Variant Targets Linux Systems with Advanced Stealth Tactics Melofee Backdoor
  • Malware

New Melofee Backdoor Variant Targets Linux Systems with Advanced Stealth Tactics

Do Son November 15, 2024 0
Read More Read more about New Melofee Backdoor Variant Targets Linux Systems with Advanced Stealth Tactics
CVE-2024-49369 (CVSS 9.8): Critical Flaw in Icinga 2 Allows for Impersonation and RCE CVE-2024-49369
  • Vulnerability

CVE-2024-49369 (CVSS 9.8): Critical Flaw in Icinga 2 Allows for Impersonation and RCE

Do Son November 15, 2024 0
Read More Read more about CVE-2024-49369 (CVSS 9.8): Critical Flaw in Icinga 2 Allows for Impersonation and RCE
PHP Reinfector Malware Wreaks Havoc on WordPress Sites Houzez theme - CVE-2024-22303 and CVE-2024-21743
  • Malware

PHP Reinfector Malware Wreaks Havoc on WordPress Sites

Do Son November 15, 2024 0
Read More Read more about PHP Reinfector Malware Wreaks Havoc on WordPress Sites
How Does GPS Tracking Improve the ROI for Trucking Companies?
  • Technique

How Does GPS Tracking Improve the ROI for Trucking Companies?

Do Son November 15, 2024 0
Read More Read more about How Does GPS Tracking Improve the ROI for Trucking Companies?
The Importance of Rapid Alarm Response in Emergency Situations PAN-OS vulnerability
  • Technique

The Importance of Rapid Alarm Response in Emergency Situations

Do Son November 15, 2024 0
Read More Read more about The Importance of Rapid Alarm Response in Emergency Situations
Palo Alto Networks Raises Alarm on Firewall Vulnerability Following Active Exploitation Palo Alto Networks Exploitation
  • Vulnerability

Palo Alto Networks Raises Alarm on Firewall Vulnerability Following Active Exploitation

Do Son November 15, 2024 0
Read More Read more about Palo Alto Networks Raises Alarm on Firewall Vulnerability Following Active Exploitation
CVE-2024-11120 (CVSS 9.8): OS Command Injection Flaw in GeoVision Devices Actively Exploited, No Patch Cisco SD-WAN Vulnerability CVE-2026-20133 FortiGate Compromise Ivanti EPMM Zero-Day CVE-2026-1281 SmarterMail Vulnerability Storm-2603 WatchGuard Zero-Day, IKEv2 Out-of-Bounds Write Cisco Zero-Day, UAT-9686 Chinese APT FortiWeb RCE Exploitation CVE-2025-58034 VMware Zero-Day, Privilege Escalation Sitecore, remote code execution CVE-2025-53690 Windows CLFS, Privilege Escalation CVE-2024-47575 & CVE-2024-11120 CVE-2025-24983 vulnerability
  • Vulnerability

CVE-2024-11120 (CVSS 9.8): OS Command Injection Flaw in GeoVision Devices Actively Exploited, No Patch

Do Son November 15, 2024 0
Read More Read more about CVE-2024-11120 (CVSS 9.8): OS Command Injection Flaw in GeoVision Devices Actively Exploited, No Patch
Bitfinex Hacker Sentenced to 5 Years for Massive Bitcoin Heist and Laundering Scheme CMDSS ZachXBT crypto theft, John Daghita U.S. Marshals investigation Bitfinex Hacker - DMM Bitcoin Cyberattack
  • Cyber Security

Bitfinex Hacker Sentenced to 5 Years for Massive Bitcoin Heist and Laundering Scheme

Do Son November 15, 2024 0
Read More Read more about Bitfinex Hacker Sentenced to 5 Years for Massive Bitcoin Heist and Laundering Scheme
Synology Issues Patches for Critical Camera Flaws Discovered at Pwn2Own Synology vulnerability
  • Vulnerability

Synology Issues Patches for Critical Camera Flaws Discovered at Pwn2Own

Do Son November 14, 2024 0
Read More Read more about Synology Issues Patches for Critical Camera Flaws Discovered at Pwn2Own
Critical Laravel Flaw (CVE-2024-52301) Exposes Millions of Web Applications to Attack CVE-2024-52301
  • Vulnerability

Critical Laravel Flaw (CVE-2024-52301) Exposes Millions of Web Applications to Attack

Do Son November 14, 2024 0
Read More Read more about Critical Laravel Flaw (CVE-2024-52301) Exposes Millions of Web Applications to Attack
CVE-2024-10924 (CVSS 9.8): Authentication Bypass in Really Simple Security Plugin Affects 4 Million Sites CVE-2024-10924
  • Vulnerability

CVE-2024-10924 (CVSS 9.8): Authentication Bypass in Really Simple Security Plugin Affects 4 Million Sites

Do Son November 14, 2024 0
Read More Read more about CVE-2024-10924 (CVSS 9.8): Authentication Bypass in Really Simple Security Plugin Affects 4 Million Sites
CISA Flags Critical Exploits in Palo Alto Networks’ Expedition with Public PoC Code actively exploited vulnerabilities Android privilege escalation flaw DELMIA Apriso RCE, CISA KEV Exploitation ServiceNow Vulnerabilities
  • Vulnerability

CISA Flags Critical Exploits in Palo Alto Networks’ Expedition with Public PoC Code

Do Son November 14, 2024 0
Read More Read more about CISA Flags Critical Exploits in Palo Alto Networks’ Expedition with Public PoC Code
TAG-112 Targets Tibetan Community via Waterholing Attack TAG-112 threat actor
  • Cyber Security

TAG-112 Targets Tibetan Community via Waterholing Attack

Do Son November 14, 2024 0
Read More Read more about TAG-112 Targets Tibetan Community via Waterholing Attack
macOS Security Compromised: Novel Exploit Bypasses Sandbox Protections macOS security
  • Vulnerability

macOS Security Compromised: Novel Exploit Bypasses Sandbox Protections

Do Son November 14, 2024 0
Read More Read more about macOS Security Compromised: Novel Exploit Bypasses Sandbox Protections
Inside China’s Cyber Threat Ecosystem: New Report Exposes State Actors China’s state-sponsored cyber operations
  • Cyber Security

Inside China’s Cyber Threat Ecosystem: New Report Exposes State Actors

Do Son November 14, 2024 0
Read More Read more about Inside China’s Cyber Threat Ecosystem: New Report Exposes State Actors
APT41’s LightSpy Campaign Expands with Advanced DeepData Framework in Targeted Espionage Against Southern Asia DeepData framework
  • Cyber Security
  • Malware

APT41’s LightSpy Campaign Expands with Advanced DeepData Framework in Targeted Espionage Against Southern Asia

Do Son November 14, 2024 0
Read More Read more about APT41’s LightSpy Campaign Expands with Advanced DeepData Framework in Targeted Espionage Against Southern Asia
Volt Typhoon APT Group Resurfaces: A Persistent Threat to Critical Infrastructure Harvester APT Linux Backdoor OT Cyberattack Iranian APT Operation Olalampo MuddyWater APT Prince of Persia APT, Tonnerre v50 Patchwork APT, DLL Sideloading Subtle Snail, cyber espionage ShadowSilk, cyber espionage Volt Typhoon APT Group - Chinese Cybersecurity Firm
  • Cyber Security

Volt Typhoon APT Group Resurfaces: A Persistent Threat to Critical Infrastructure

Do Son November 14, 2024 0
Read More Read more about Volt Typhoon APT Group Resurfaces: A Persistent Threat to Critical Infrastructure
LodaRAT Strikes Again: New Campaign Targets Global Victims with Updated Capabilities GuLoader Malware CloudEye Obfuscation npm, malware Ethereum, npm supply chain OAST techniques StilachiRAT macOS Malware PasivRobber
  • Malware

LodaRAT Strikes Again: New Campaign Targets Global Victims with Updated Capabilities

Do Son November 14, 2024 0
Read More Read more about LodaRAT Strikes Again: New Campaign Targets Global Victims with Updated Capabilities
Bitdefender Releases Decryptor for ShrinkLocker Ransomware ShrinkLocker decryptor
  • Malware

Bitdefender Releases Decryptor for ShrinkLocker Ransomware

Do Son November 14, 2024 0
Read More Read more about Bitdefender Releases Decryptor for ShrinkLocker Ransomware
CVE-2024-10571 (CVSS 9.8): Critical Flaw in WordPress Chart Plugin Under Active Attack CVE-2024-10571
  • Vulnerability

CVE-2024-10571 (CVSS 9.8): Critical Flaw in WordPress Chart Plugin Under Active Attack

Do Son November 14, 2024 0
Read More Read more about CVE-2024-10571 (CVSS 9.8): Critical Flaw in WordPress Chart Plugin Under Active Attack
Google Boosts Real-Time Protection Against Scams and Malware on Android Devices Scam Detection
  • Android
  • Technology

Google Boosts Real-Time Protection Against Scams and Malware on Android Devices

Do Son November 14, 2024 0
Read More Read more about Google Boosts Real-Time Protection Against Scams and Malware on Android Devices
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-101894CVSS 9.1
    The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101891CVSS 9.3
    An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker...
    📅 Updated: Sep 28, 2026
  • CVE-2026-86102CVSS 9.3
    An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100721CVSS 9.5
    vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101081CVSS 9.4
    A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100684CVSS 9.2
    Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate,...
    📅 Updated: Sep 28, 2026
  • CVE-2026-63374CVSS 9.3
    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101075CVSS 10.0
    A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.