Skip to content
September 29, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Six Vulnerabilities Uncovered in Ollama: Risks of AI Model Theft and Poisoning Ollama vulnerability
  • Vulnerability

Six Vulnerabilities Uncovered in Ollama: Risks of AI Model Theft and Poisoning

Do Son November 3, 2024 0
Read More Read more about Six Vulnerabilities Uncovered in Ollama: Risks of AI Model Theft and Poisoning
Typosquat Campaign Targets Puppeteer Users: Researcher Warns of Malware in npm Packages Puppeteer malware
  • Malware

Typosquat Campaign Targets Puppeteer Users: Researcher Warns of Malware in npm Packages

Do Son November 3, 2024 0
Read More Read more about Typosquat Campaign Targets Puppeteer Users: Researcher Warns of Malware in npm Packages
Pacific Rim: Sophos Exposes 5 Years of Chinese Cyber Espionage Pacific Rim APT
  • Cyber Security

Pacific Rim: Sophos Exposes 5 Years of Chinese Cyber Espionage

Do Son November 3, 2024 0
Read More Read more about Pacific Rim: Sophos Exposes 5 Years of Chinese Cyber Espionage
Nvidia Releases Security Update for ConnectX and BlueField DPUs Amid High-Severity Flaws NVIDIA Nsight Vulnerability CVE-2025-33206 NVIDIA ConnectX Firmware - CVE-2024-0105
  • Vulnerability

Nvidia Releases Security Update for ConnectX and BlueField DPUs Amid High-Severity Flaws

Do Son November 3, 2024 0
Read More Read more about Nvidia Releases Security Update for ConnectX and BlueField DPUs Amid High-Severity Flaws
CrossBarking Vulnerability in Opera Browser Allows Malicious Extensions to Hijack User Accounts CrossBarking vulnerability
  • Vulnerability

CrossBarking Vulnerability in Opera Browser Allows Malicious Extensions to Hijack User Accounts

Do Son November 2, 2024 0
Read More Read more about CrossBarking Vulnerability in Opera Browser Allows Malicious Extensions to Hijack User Accounts
SYS01 Infostealer Campaign Exploits Meta Ads to Target Millions Worldwide SYS01 Infostealer
  • Cyber Security
  • Malware

SYS01 Infostealer Campaign Exploits Meta Ads to Target Millions Worldwide

Do Son November 2, 2024 0
Read More Read more about SYS01 Infostealer Campaign Exploits Meta Ads to Target Millions Worldwide
Okta Discloses Authentication Vulnerability in AD/LDAP DelAuth, Urges Customer Review Okta Authentication Vulnerability
  • Vulnerability

Okta Discloses Authentication Vulnerability in AD/LDAP DelAuth, Urges Customer Review

Do Son November 2, 2024 0
Read More Read more about Okta Discloses Authentication Vulnerability in AD/LDAP DelAuth, Urges Customer Review
PoC Exploit Releases for Spring WebFlux Authorization Bypass – CVE-2024-38821 CVE-2024-38821 PoC exploit
  • Vulnerability

PoC Exploit Releases for Spring WebFlux Authorization Bypass – CVE-2024-38821

Do Son November 1, 2024 0
Read More Read more about PoC Exploit Releases for Spring WebFlux Authorization Bypass – CVE-2024-38821
LUNAR SPIDER Resurfaces: Financial Sector Targeted in Latest Malvertising Campaign LUNAR SPIDER
  • Cyber Security
  • Malware

LUNAR SPIDER Resurfaces: Financial Sector Targeted in Latest Malvertising Campaign

Do Son November 1, 2024 0
Read More Read more about LUNAR SPIDER Resurfaces: Financial Sector Targeted in Latest Malvertising Campaign
PythonRatLoader: The Malware Loader That’s Turning Phishing Into a Multi-Stage Attack At
  • Malware

PythonRatLoader: The Malware Loader That’s Turning Phishing Into a Multi-Stage Attack

Do Son November 1, 2024 0
Read More Read more about PythonRatLoader: The Malware Loader That’s Turning Phishing Into a Multi-Stage Attack
CVE-2024-38094 Exploited: Attackers Gain Domain Access via Microsoft SharePoint Server Microsoft SharePoint server
  • Cyber Security
  • Vulnerability

CVE-2024-38094 Exploited: Attackers Gain Domain Access via Microsoft SharePoint Server

Do Son October 31, 2024 0
Read More Read more about CVE-2024-38094 Exploited: Attackers Gain Domain Access via Microsoft SharePoint Server
PoC Exploit Releases for Critical Flaw in Synology TC500 and BC500 Camera to Get Shell Synology TC500
  • Vulnerability

PoC Exploit Releases for Critical Flaw in Synology TC500 and BC500 Camera to Get Shell

Do Son October 31, 2024 0
Read More Read more about PoC Exploit Releases for Critical Flaw in Synology TC500 and BC500 Camera to Get Shell
Iranian Cyber Group Emennet Pasargad’s Expanding Operations Targeting Global Networks CRussian Market, "Fly" (Flyded) hange Healthcare Cyberattack - CVE-2024-50603 Exploit
  • Cyber Security

Iranian Cyber Group Emennet Pasargad’s Expanding Operations Targeting Global Networks

Do Son October 31, 2024 0
Read More Read more about Iranian Cyber Group Emennet Pasargad’s Expanding Operations Targeting Global Networks
Cryptocurrency Users Targeted by Invasive New Malware Campaign CryptoAITools
  • Cyber Security
  • Malware

Cryptocurrency Users Targeted by Invasive New Malware Campaign

Do Son October 31, 2024 0
Read More Read more about Cryptocurrency Users Targeted by Invasive New Malware Campaign
FakeCall Malware: Sophisticated Vishing Attack Targets Mobile Users in Banking Fraud FakeCall malware
  • Malware

FakeCall Malware: Sophisticated Vishing Attack Targets Mobile Users in Banking Fraud

Do Son October 31, 2024 0
Read More Read more about FakeCall Malware: Sophisticated Vishing Attack Targets Mobile Users in Banking Fraud
CVE-2024-9632: 18-Year-Old Bug in X.Org Server Leaves Systems Vulnerable to Attack CVE-2024-9632
  • Vulnerability

CVE-2024-9632: 18-Year-Old Bug in X.Org Server Leaves Systems Vulnerable to Attack

Do Son October 31, 2024 0
Read More Read more about CVE-2024-9632: 18-Year-Old Bug in X.Org Server Leaves Systems Vulnerable to Attack
EMERALDWHALE Operation Exposes Over 15,000 Cloud Credentials in Widespread Git Exploit EMERALDWHALE
  • Cyber Security

EMERALDWHALE Operation Exposes Over 15,000 Cloud Credentials in Widespread Git Exploit

Do Son October 31, 2024 0
Read More Read more about EMERALDWHALE Operation Exposes Over 15,000 Cloud Credentials in Widespread Git Exploit
Hikvision Patches Security Flaw in Network Cameras, Preventing Cleartext Credential Transmission Hikvision Vulnerability CVE-2026-0709 Hikvision Vulnerability CVE-2025-66176 Hikvision, vulnerability Canada Hikvision Ban, National Security Hikvision firmware updates
  • Vulnerability

Hikvision Patches Security Flaw in Network Cameras, Preventing Cleartext Credential Transmission

Do Son October 31, 2024 0
Read More Read more about Hikvision Patches Security Flaw in Network Cameras, Preventing Cleartext Credential Transmission
North Korean Threat Group “Jumpy Pisces” Linked to Play Ransomware Attack Andariel hacking group - Jumpy Pisces
  • Cyber Security
  • Malware

North Korean Threat Group “Jumpy Pisces” Linked to Play Ransomware Attack

Do Son October 31, 2024 0
Read More Read more about North Korean Threat Group “Jumpy Pisces” Linked to Play Ransomware Attack
Critical Vulnerability in Waitress WSGI Server: CVE-2024-49768 – What You Need to Know Python asyncio Vulnerability Windows Buffer Overflow ormar SQL Injection CVE-2026-26198 CVE-2024-49768 - Waitress WSGI server
  • Vulnerability

Critical Vulnerability in Waitress WSGI Server: CVE-2024-49768 – What You Need to Know

Do Son October 31, 2024 0
Read More Read more about Critical Vulnerability in Waitress WSGI Server: CVE-2024-49768 – What You Need to Know
Supply Chain Attack on Popular Animation Library Lottie-Player Targets Web3 Users lottie-player supply chain attack
  • Cyber Security
  • Malware

Supply Chain Attack on Popular Animation Library Lottie-Player Targets Web3 Users

Do Son October 31, 2024 0
Read More Read more about Supply Chain Attack on Popular Animation Library Lottie-Player Targets Web3 Users
Operation Magnus Dismantles RedLine and META Infostealer Networks Operation Magnus
  • Cyber Security
  • Malware

Operation Magnus Dismantles RedLine and META Infostealer Networks

Do Son October 31, 2024 0
Read More Read more about Operation Magnus Dismantles RedLine and META Infostealer Networks
❮ Prev Page
Next Page ❯

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intel📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-97359CVSS 10.0
    HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated...
    📅 Updated: Sep 29, 2026
  • CVE-2026-67231CVSS 9.1
    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store...
    📅 Updated: Sep 29, 2026
  • CVE-2026-67404CVSS 9.2
    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no...
    📅 Updated: Sep 29, 2026
  • CVE-2026-96759CVSS 9.3
    orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options...
    📅 Updated: Sep 29, 2026
  • CVE-2026-96754CVSS 9.3
    orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102240CVSS 10.0
    A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of...
    📅 Updated: Sep 29, 2026
  • CVE-2026-101354CVSS 9.4
    A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of...
    📅 Updated: Sep 29, 2026
  • CVE-2026-102361CVSS 9.3
    mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.