Skip to content
October 8, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Evasive Malware Campaign Leverages CleverSoar Installer & Nidhogg Rootkit CleverSoar Attack
  • Cyber Security
  • Malware

Evasive Malware Campaign Leverages CleverSoar Installer & Nidhogg Rootkit

Do Son November 28, 2024 0
Read More Read more about Evasive Malware Campaign Leverages CleverSoar Installer & Nidhogg Rootkit
Malicious npm Packages Threaten Crypto Developers: Keylogging and Wallet Theft Revealed Crypto Developers
  • Malware

Malicious npm Packages Threaten Crypto Developers: Keylogging and Wallet Theft Revealed

Do Son November 28, 2024 0
Read More Read more about Malicious npm Packages Threaten Crypto Developers: Keylogging and Wallet Theft Revealed
Integer Overflow Vulnerability in Windows Driver Enables Privilege Escalation, PoC Published Windows Secure Lock Screen Clock Lag Windows 11 KB5079391 error Windows 11 Kernel Driver Trust Microslop Windows 11 Windows 11 modem driver removal 2026, CVE-2025-24052 Agere driver exploit Windows 11 Password Icon Bug Lock Screen Glitch Windows 11 26H1 ARM Snapdragon X2 Windows 11 Reboot-Free, Insider Build Windows Update Error, 0x80070103 File Explorer, NTLM leak Windows bug, WinRE Windows Update, UAC prompts Secure Boot Certificate, Windows Security Windows 11 22H2 Installation security updates Windows UEFI CA 2023 Windows 11 25H2
  • Vulnerability
  • Windows

Integer Overflow Vulnerability in Windows Driver Enables Privilege Escalation, PoC Published

Do Son November 28, 2024 0
Read More Read more about Integer Overflow Vulnerability in Windows Driver Enables Privilege Escalation, PoC Published
Godot Engine Compromised: Malware Distributed via GodLoader mal
  • Malware

Godot Engine Compromised: Malware Distributed via GodLoader

Do Son November 28, 2024 0
Read More Read more about Godot Engine Compromised: Malware Distributed via GodLoader
Beyond FUD Links: Rockstar PaaS Kit Exploits Trusted Platforms for Phishing Rockstar kit
  • Cyber Security

Beyond FUD Links: Rockstar PaaS Kit Exploits Trusted Platforms for Phishing

Do Son November 28, 2024 0
Read More Read more about Beyond FUD Links: Rockstar PaaS Kit Exploits Trusted Platforms for Phishing
Contiki-NG IoT OS Patches Critical Vulnerabilities Contiki-NG - CVE-2024-41125 & CVE-2024-41126
  • Vulnerability

Contiki-NG IoT OS Patches Critical Vulnerabilities

Do Son November 28, 2024 0
Read More Read more about Contiki-NG IoT OS Patches Critical Vulnerabilities
Credit Card Skimmer Malware Uncovered: Targeting Magento Checkout Pages XCharge C6 vulnerabilities EV charger security flaws GNU libtasn1 Vulnerability CVE-2025-13151 Credit Card Skimmer Malware CVE-2024-13892
  • Malware

Credit Card Skimmer Malware Uncovered: Targeting Magento Checkout Pages

Do Son November 28, 2024 0
Read More Read more about Credit Card Skimmer Malware Uncovered: Targeting Magento Checkout Pages
TikTok Takes Aim at Appearance-Altering Filters and Underage Users in Latest Safety Push TikTok Appearance Filters
  • Technology

TikTok Takes Aim at Appearance-Altering Filters and Underage Users in Latest Safety Push

Do Son November 28, 2024 0
Read More Read more about TikTok Takes Aim at Appearance-Altering Filters and Underage Users in Latest Safety Push
CVE-2024-42330 (CVSS 9.1): Zabbix Patches Critical Remote Code Execution Vulnerability CVE-2024-42330 Zabbix Privilege Escalation CVE-2025-27237
  • Vulnerability

CVE-2024-42330 (CVSS 9.1): Zabbix Patches Critical Remote Code Execution Vulnerability

Do Son November 28, 2024 0
Read More Read more about CVE-2024-42330 (CVSS 9.1): Zabbix Patches Critical Remote Code Execution Vulnerability
Massive Illegal Streaming Network Dismantled in Europe-Wide Operation Massive Illegal Streaming Network
  • Cyber Security

Massive Illegal Streaming Network Dismantled in Europe-Wide Operation

Do Son November 27, 2024 0
Read More Read more about Massive Illegal Streaming Network Dismantled in Europe-Wide Operation
Black Friday Fake Stores Surge 110%: How LLMs and Cheap Domains Empower Cybercrime Black Friday Fake Stores
  • Cyber Security

Black Friday Fake Stores Surge 110%: How LLMs and Cheap Domains Empower Cybercrime

Do Son November 27, 2024 0
Read More Read more about Black Friday Fake Stores Surge 110%: How LLMs and Cheap Domains Empower Cybercrime
PixPirate Resurfaces: Spreading via WhatsApp and Expanding Beyond Brazil PixPirate malware WhatsApp
  • Malware

PixPirate Resurfaces: Spreading via WhatsApp and Expanding Beyond Brazil

Do Son November 27, 2024 0
Read More Read more about PixPirate Resurfaces: Spreading via WhatsApp and Expanding Beyond Brazil
CVE-2024-42327 (CVSS 9.9): Critical SQL Injection Vulnerability Found in Zabbix CVE-2024-42327
  • Vulnerability

CVE-2024-42327 (CVSS 9.9): Critical SQL Injection Vulnerability Found in Zabbix

Do Son November 27, 2024 0
Read More Read more about CVE-2024-42327 (CVSS 9.9): Critical SQL Injection Vulnerability Found in Zabbix
35 Million Devices Vulnerable: Matrix DDoS Campaign Highlights Growing IoT Threat Matrix DDoS Campaign
  • Cyber Security
  • Malware
  • Vulnerability

35 Million Devices Vulnerable: Matrix DDoS Campaign Highlights Growing IoT Threat

Do Son November 27, 2024 0
Read More Read more about 35 Million Devices Vulnerable: Matrix DDoS Campaign Highlights Growing IoT Threat
Elpaco Ransomware: A New Threat Actor Leverages CVE-2020-1472 for Global Attacks NATS-as-C2 Sysdig CVE-2026-33017 Langflow RCE Microsoft Phone Link Hijack CloudZ Pheno Plugin Insider Threat BlackCat (ALPHV) OFAC Sanctions DPRK IT Workers Transparent Tribe APT36 React2Shell, EtherRAT SideWinder Espionage, Netlify Phishing DDNS Abuse, C2 Infrastructure Hacking Health Club
  • Malware
  • Vulnerability

Elpaco Ransomware: A New Threat Actor Leverages CVE-2020-1472 for Global Attacks

Do Son November 27, 2024 0
Read More Read more about Elpaco Ransomware: A New Threat Actor Leverages CVE-2020-1472 for Global Attacks
ANEL Backdoor Reactivated in Earth Kasha Cyber-Espionage Campaign ANEL backdoor
  • Cyber Security
  • Malware

ANEL Backdoor Reactivated in Earth Kasha Cyber-Espionage Campaign

Do Son November 27, 2024 0
Read More Read more about ANEL Backdoor Reactivated in Earth Kasha Cyber-Espionage Campaign
HPE Insight Remote Support Hit with Critical Vulnerabilities, Urgent Patch Released CVE-2024-53676
  • Vulnerability

HPE Insight Remote Support Hit with Critical Vulnerabilities, Urgent Patch Released

Do Son November 27, 2024 0
Read More Read more about HPE Insight Remote Support Hit with Critical Vulnerabilities, Urgent Patch Released
Cybercrime as an Industry: A Deep Dive into the Organizational Structure of Chinese Cybercrime Chinese cybercrime
  • Cyber Security

Cybercrime as an Industry: A Deep Dive into the Organizational Structure of Chinese Cybercrime

Do Son November 27, 2024 0
Read More Read more about Cybercrime as an Industry: A Deep Dive into the Organizational Structure of Chinese Cybercrime
Jenkins Users Beware: Multiple Security Vulnerabilities Discovered Jenkins RCE vulnerabilities Jenkins plugin security flaws CVE-2024-47855
  • Vulnerability

Jenkins Users Beware: Multiple Security Vulnerabilities Discovered

Do Son November 27, 2024 0
Read More Read more about Jenkins Users Beware: Multiple Security Vulnerabilities Discovered
XorBot Botnet Resurfaces with Advanced Evasion and Exploits, Threatens IoT Devices XorBot botnet
  • Malware
  • Vulnerability

XorBot Botnet Resurfaces with Advanced Evasion and Exploits, Threatens IoT Devices

Do Son November 27, 2024 0
Read More Read more about XorBot Botnet Resurfaces with Advanced Evasion and Exploits, Threatens IoT Devices
Year-Long Supply Chain Attack: Malicious NPM Package Compromises Cryptocurrency Wallets NPM Supply Chain
  • Malware

Year-Long Supply Chain Attack: Malicious NPM Package Compromises Cryptocurrency Wallets

Do Son November 27, 2024 0
Read More Read more about Year-Long Supply Chain Attack: Malicious NPM Package Compromises Cryptocurrency Wallets
SMOKEDHAM Backdoor: UNC2465’s Stealth Weapon for Extortion and Ransomware Campaigns SMOKEDHAM backdoor
  • Cyber Security
  • Malware

SMOKEDHAM Backdoor: UNC2465’s Stealth Weapon for Extortion and Ransomware Campaigns

Do Son November 27, 2024 0
Read More Read more about SMOKEDHAM Backdoor: UNC2465’s Stealth Weapon for Extortion and Ransomware Campaigns
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-107459CVSS 9.3
    The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary...
    📅 Updated: Oct 8, 2026
  • CVE-2026-14990CVSS 9.3
    IBM DataPower Gateway 10.6.0.0 through 10.6.0.10Β is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed...
    📅 Updated: Oct 8, 2026
  • CVE-2026-14991CVSS 9.8
    IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable...
    📅 Updated: Oct 8, 2026
  • CVE-2026-17635CVSS 9.1
    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102106CVSS 9.1
    Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102105CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102104CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
  • CVE-2026-102103CVSS 9.1
    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery...
    📅 Updated: Oct 8, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.