Skip to content
June 15, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
Critical Security Update: IBM Patches Multiple Vulnerabilities in Verify Identity and Access IBM Verify Root Escalation
  • Vulnerability Report

Critical Security Update: IBM Patches Multiple Vulnerabilities in Verify Identity and Access

Do Son April 8, 2026 0
IBM has released a comprehensive bulletin addressing a series of vulnerabilities within its Verify Identity Access and...
Read More Read more about Critical Security Update: IBM Patches Multiple Vulnerabilities in Verify Identity and Access
The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors Kimsuky Multi-stage LNK
  • Malware

The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors

Do Son April 8, 2026 0
The notorious Kimsuky threat group is refining its arsenal, shifting toward more complex, multi-stage execution chains to...
Read More Read more about The Python Pivot: Kimsuky’s New Multi-Stage LNK Maze for Stealthy Backdoors
Critical Alert: Iranian-Affiliated Actors Target U.S. Infrastructure via Industrial Control Systems Harvester APT Linux Backdoor OT Cyberattack Iranian APT Operation Olalampo MuddyWater APT Prince of Persia APT, Tonnerre v50 Patchwork APT, DLL Sideloading Subtle Snail, cyber espionage ShadowSilk, cyber espionage Volt Typhoon APT Group - Chinese Cybersecurity Firm
  • Cyber Security

Critical Alert: Iranian-Affiliated Actors Target U.S. Infrastructure via Industrial Control Systems

Do Son April 8, 2026 0
In a major joint advisory released on April 7, 2026, a coalition of U.S. federal agencies—including the...
Read More Read more about Critical Alert: Iranian-Affiliated Actors Target U.S. Infrastructure via Industrial Control Systems
The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows Telegram Bot-to-Bot communication
  • Technology

The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows

Do Son April 8, 2026 0
In its most recent iteration, the instant messaging platform Telegram has granted bots the faculty of inter-bot...
Read More Read more about The AI Collective: Telegram Unlocks Autonomous “Bot-to-Bot” Dialogue for Multi-Agent Workflows
The “Entertainment Only” Paradox: Why Microsoft’s Copilot Legal Terms Just Ignited a Viral Controversy Microsoft Copilot Terms of Service Satya Nadella SN Scratchpad, Microsoft Microslop backlash
  • Technology

The “Entertainment Only” Paradox: Why Microsoft’s Copilot Legal Terms Just Ignited a Viral Controversy

Do Son April 8, 2026 0
Since last week, users have observed that the 2025 Microsoft Copilot Terms of Service emphasize that the...
Read More Read more about The “Entertainment Only” Paradox: Why Microsoft’s Copilot Legal Terms Just Ignited a Viral Controversy
The Cloud-Only Safety Net: Microsoft to Bypass Local Recycle Bins in Major OneDrive Overhaul OneDrive cloud deletion 2026 OneDrive Facial Recognition, Three-Time Limit OneDrive Suspension, Data Loss
  • Technology

The Cloud-Only Safety Net: Microsoft to Bypass Local Recycle Bins in Major OneDrive Overhaul

Do Son April 8, 2026 0
According to Microsoft’s announcement in the Microsoft 365 Admin Center (MC1269861), commencing in May 2026, files deleted...
Read More Read more about The Cloud-Only Safety Net: Microsoft to Bypass Local Recycle Bins in Major OneDrive Overhaul
AI Against AI: Anthropic Unveils “Project Glasswing” to Stop the Next Great Cyber War Anthropic Project Glasswing
  • Technology

AI Against AI: Anthropic Unveils “Project Glasswing” to Stop the Next Great Cyber War

Do Son April 8, 2026 0
As generative AI technologies proliferate, global anxieties regarding their potential misuse—particularly as instruments for cyber warfare and...
Read More Read more about AI Against AI: Anthropic Unveils “Project Glasswing” to Stop the Next Great Cyber War
Alert: Social Engineering Campaign Targets Open Source Developers via Slack Social Engineering Developer Security
  • Cybercriminals

Alert: Social Engineering Campaign Targets Open Source Developers via Slack

Do Son April 8, 2026 0
A sophisticated, high-severity social engineering campaign is currently targeting the open source developer community. The attack, which...
Read More Read more about Alert: Social Engineering Campaign Targets Open Source Developers via Slack
OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed OpenSSL Vulnerability RSA Memory Leak OpenSSL Vulnerability CVE-2025-15467 CVE-2022-2274 OpenSSL Vulnerabilities, Timing Side-Channel
  • Vulnerability Report

OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed

Do Son April 8, 2026 0
OpenSSL has released a comprehensive security advisory detailing seven vulnerabilities ranging from Moderate to Low severity. The...
Read More Read more about OpenSSL Issues Major Security Advisory: RSA and Memory Vulnerabilities Fixed
APT28 Hijacks Home Routers to Steal Corporate Credentials GemStuffer RubyGems Campaign RubyGems Data Exfiltration TanStack npm Compromise Supply Chain Attack DNS Hijacking APT28 (Fancy Bear) OpenVSX Supply Chain Attack Checkmarx Plugin Breach Stryker Cyberattack CISA Alert Trans-Regional Cyber Conflict Operation Epic Fury Cyber Operation MacroMaze APT28 Cyber Espionage Notepad++ Supply Chain Attack Lotus Blossom Group Defense Industrial Base Threats GTIG Report APT28 Operation Neusploit CVE-2026-21509 Bookworm Malware
  • Cybercriminals

APT28 Hijacks Home Routers to Steal Corporate Credentials

Do Son April 8, 2026 0
In a major technical disclosure, the UK National Cyber Security Centre (NCSC) has detailed a sophisticated campaign...
Read More Read more about APT28 Hijacks Home Routers to Steal Corporate Credentials
Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets Venom Stealer Crypto Drainer MaaS
  • Malware

Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets

Do Son April 8, 2026 0
A new Malware-as-a-Service (MaaS) platform is making waves in the cybercrime underground, promising operators an automated pipeline...
Read More Read more about Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets
The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry Contagious Interview Malicious Packages
  • Malware

The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry

Do Son April 8, 2026 0
Researchers at Socket have identified a massive new cluster of malicious packages linked to North Korea’s notorious...
Read More Read more about The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
Malicious VeloraDEX SDK Compromises Developer Machines via npm npm Supply Chain Attack @velora-dex/sdk Malware
  • Malware

Malicious VeloraDEX SDK Compromises Developer Machines via npm

Do Son April 8, 2026 0
Security researchers at StepSecurity have sounded the alarm on a compromised version of the @velora-dex/sdk package. On...
Read More Read more about Malicious VeloraDEX SDK Compromises Developer Machines via npm
From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints TA416 PlugX Backdoor
  • Cyber Security
  • Malware

From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints

Do Son April 8, 2026 0
A new intelligence report from Proofpoint reveals that TA416, a sophisticated threat actor aligned with Chinese state...
Read More Read more about From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
Budibase Patches Critical RCE and SSRF Vulnerabilities Budibase RCE SSRF Vulnerability Budibase Vulnerabilities Authentication Bypass
  • Vulnerability Report

Budibase Patches Critical RCE and SSRF Vulnerabilities

Do Son April 7, 2026 0
Budibase, the popular open-source low-code platform used by engineers to rapidly build internal tools, has released urgent...
Read More Read more about Budibase Patches Critical RCE and SSRF Vulnerabilities
10.0 CVSS Flaw in Kestra Grants Full Server Control Kestra RCE SQL Injection Vulnerability
  • Vulnerability Report

10.0 CVSS Flaw in Kestra Grants Full Server Control

Do Son April 7, 2026 0
A critical security vulnerability has been unmasked in Kestra, the popular open-source, event-driven orchestration platform. The flaw,...
Read More Read more about 10.0 CVSS Flaw in Kestra Grants Full Server Control
Critical JWT Bypass in Convoy Panel Allows Full Account Takeover Convoy Vulnerability JWT Authentication Bypass
  • Vulnerability Report

Critical JWT Bypass in Convoy Panel Allows Full Account Takeover

Do Son April 7, 2026 0
A critical security vulnerability has been unmasked in Convoy, the modern KVM server management panel used by...
Read More Read more about Critical JWT Bypass in Convoy Panel Allows Full Account Takeover
Breaking the App Shell: Five New Electron Vulnerabilities Shatter Context Isolation Electron Security Sandbox Escape Electron Vulnerabilities, Desktop App Security
  • Vulnerability Report

Breaking the App Shell: Five New Electron Vulnerabilities Shatter Context Isolation

Do Son April 7, 2026 0
The Electron framework—the powerhouse behind heavyweights like Visual Studio Code and countless other cross-platform desktop applications —has...
Read More Read more about Breaking the App Shell: Five New Electron Vulnerabilities Shatter Context Isolation
Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims CrystalX RAT Prankware
  • Malware

Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims

Do Son April 7, 2026 0
In the world of cybercrime, malware is typically designed for one of two things: stealthy espionage or...
Read More Read more about Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims
BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender BlueHammer Exploit Windows Defender 0-day
  • Vulnerability Report

BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender

Do Son April 7, 2026 0
A researcher has publicly disclosed a functional zero-day exploit targeting the internal signature update mechanism of Windows...
Read More Read more about BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-9862CVSS 9.8
    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in...
  • CVE-2026-52704CVSS 10.0
    Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas...
  • CVE-2018-25436CVSS 9.8
    WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload...
  • CVE-2026-12183CVSS 9.8
    Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux...
  • CVE-2026-53609CVSS 9.1
    ApostropheCMS is an open-source Node.js content management system. In versions up to...
  • CVE-2026-53519CVSS 9.1
    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M...
  • CVE-2026-46716CVSS 9.9
    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M...
  • CVE-2026-44990CVSS 9.3
    ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a...
  • CVE-2026-28742CVSS 9.8
    Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide...
  • CVE-2026-48558CVSS 10.0
    SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.