Skip to content
June 15, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers Keycloak vulnerabilities Keycloak Security MFA Bypass
  • Vulnerability Report

Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers

Do Son April 6, 2026 0
The popular open-source identity and access management solution Keycloak has released a critical security update, version 26.5.7,...
Read More Read more about Keycloak Under Siege: Patch Now to Stop Token Theft and Account Takeovers
CVE-2026-34838 (CVSS 10): Critical RCE Flaw Uncovered in GroupOffice CRM GroupOffice RCE, Insecure Deserialization
  • Vulnerability Report

CVE-2026-34838 (CVSS 10): Critical RCE Flaw Uncovered in GroupOffice CRM

Do Son April 6, 2026 0
In a significant discovery for enterprises and public sector organizations, a critical security vulnerability has been unmasked...
Read More Read more about CVE-2026-34838 (CVSS 10): Critical RCE Flaw Uncovered in GroupOffice CRM
Critical RCE and SQLi Flaws Shatter mbCONNECT24 Industrial Security mbCONNECT24 Vulnerabilities Industrial RCE
  • Vulnerability Report

Critical RCE and SQLi Flaws Shatter mbCONNECT24 Industrial Security

Do Son April 6, 2026 0
In a significant alert for the industrial automation sector, CERT@VDE has disclosed a series of high-severity vulnerabilities...
Read More Read more about Critical RCE and SQLi Flaws Shatter mbCONNECT24 Industrial Security
Whitespace Flaw Re-Opens Critical JWT “Algorithm Confusion” Bypass fast-jwt JWT Algorithm Confusion
  • Vulnerability Report

Whitespace Flaw Re-Opens Critical JWT “Algorithm Confusion” Bypass

Do Son April 6, 2026 0
Security researchers have disclosed two major vulnerabilities within fast-jwt, a high-performance library used to implement JSON Web...
Read More Read more about Whitespace Flaw Re-Opens Critical JWT “Algorithm Confusion” Bypass
Speeding Up the Web: Chrome 148 Extends “Lazy Loading” to Video and Audio Tags Chrome 148 lazy loading Chrome for Linux ARM64 Chrome 145 Update Chrome Security Fixes Chrome Security Update CVE-2026-1220 Chrome 144 Security Update CVE-2026-0899 Chrome Memory Safety, WebGPU UAF Chrome V8 Type Confusion, Google Updater Flaw Chrome V8 Flaw, CVE-2025-13042 Chrome V8, Type Confusion, Chrome 142 Update Chrome V8 Flaw, CVE-2025-12036 Chrome 141, WebGPU Overflow Google Chrome preloading Chrome, V8 vulnerability CVE-2025-9132 Chrome Security Update, Use-After-Free Chrome V8, Type Confusion Chrome Telemetry, Windows 10 EOL Microsoft Family Safety, Chrome Blocking Chrome Security Update, High-Severity Google Chrome, Antitrust CVE-2024-10487 and CVE-2024-10488 Google Chrome Root Program Chrome Update, CVE-2025-3619 Chrome Acquisition, Perplexity.ai
  • Technology

Speeding Up the Web: Chrome 148 Extends “Lazy Loading” to Video and Audio Tags

Do Son April 6, 2026 0
To address the common challenge of contemporary web pages becoming encumbered by excessive multimedia content—a burden that...
Read More Read more about Speeding Up the Web: Chrome 148 Extends “Lazy Loading” to Video and Audio Tags
Exploit Code Live: Full Technical Details and PoC Disclosed for Critical CWP RCE Vulnerability CWP RCE PoC Disclosed
  • Vulnerability

Exploit Code Live: Full Technical Details and PoC Disclosed for Critical CWP RCE Vulnerability

Do Son April 6, 2026 0
A severe security failure has been unearthed in Control Web Panel (CWP)—formerly known as CentOS Web Panel—that...
Read More Read more about Exploit Code Live: Full Technical Details and PoC Disclosed for Critical CWP RCE Vulnerability
Iran-Linked “Password Spraying” Targets Municipal Response to Missile Strikes Mercenary Akula European Financial Targeting AI-Generated Malware React2Shell Exploit UAT-8837 Critical Infrastructure Attack APT36, BOSS Linux BRICKSTORM Malware, China Espionage Curly COMrades, MucorAgent Chinese APT - HTTP Client Tools Shuckworm Cyber Espionage
  • Cyber Security

Iran-Linked “Password Spraying” Targets Municipal Response to Missile Strikes

Do Son April 6, 2026 0
Check Point Research (CPR) has been tracking an extensive password-spraying operation targeting Microsoft 365 environments, conducted by...
Read More Read more about Iran-Linked “Password Spraying” Targets Municipal Response to Missile Strikes
Double Agents in the Cloud: Unit 42 Unmasks Critical AI Vulnerabilities in Google Vertex AI Vertex AI Security AI Double Agents
  • Vulnerability Report

Double Agents in the Cloud: Unit 42 Unmasks Critical AI Vulnerabilities in Google Vertex AI

Do Son April 6, 2026 0
As organizations race to integrate autonomous systems into their workflows, a new and subtle threat is emerging...
Read More Read more about Double Agents in the Cloud: Unit 42 Unmasks Critical AI Vulnerabilities in Google Vertex AI
The “Special Invitation” Trap: STAC6405 Abuses Legitimate RMM Tools to Hijack Your PC STAC6405 Phishing RMM Abuse
  • Cybercriminals

The “Special Invitation” Trap: STAC6405 Abuses Legitimate RMM Tools to Hijack Your PC

Do Son April 6, 2026 0
Cybercriminals are increasingly trading custom-built malware for legitimate software to slip past corporate defenses. A new investigation...
Read More Read more about The “Special Invitation” Trap: STAC6405 Abuses Legitimate RMM Tools to Hijack Your PC
Operation DualScript Bypasses Defenses to Hijack Crypto and Cash AccountDumpling Phishing Google AppSheet Abuse AI-Generated Malware PureRAT Campaign RondoDoX Botnet, Next.js React2Shell EchoGather, Paper Werewolf Salt Typhoon, Telecom Espionage BreachForums, Conor Fitzpatrick Ransomware Negotiation, DOJ Investigation MirrorFace group - Earth Kasha Emperor Dragonfly
  • Malware

Operation DualScript Bypasses Defenses to Hijack Crypto and Cash

Do Son April 6, 2026 0
A sophisticated, multi-stage malware campaign dubbed Operation DualScript is currently bypassing traditional defenses to siphon funds from...
Read More Read more about Operation DualScript Bypasses Defenses to Hijack Crypto and Cash
The DNS Trap: How a “Hidden” Path Allowed ChatGPT to Silently Leak Your Private Data ChatGPT Lockdown Mode OpenAI OpenClaw acquisition OpenAI Prism GPT-5.2 LaTeX, scientific research AI workspace OpenAI, Mixpanel Breach ChatGPT Data Preservation, NYT Lawsuit ChatGPT Apps SDK, super app OpenAI Jony Ive, AI Hardware Delay Musk Apple lawsuit, App Store antitrust UK AI Partnership, OpenAI Collaboration Jony Ive OpenAI, DoD Contract OpenAI Lawsuit, ChatGPT Privacy North Korea ChatGPT - GPT-4.5 model OpenAI Models, AI Advancements OpenAI pricing, Flex API
  • Data Leak

The DNS Trap: How a “Hidden” Path Allowed ChatGPT to Silently Leak Your Private Data

Do Son April 6, 2026 0
In the world of AI, trust is built on a simple, unspoken agreement: what stays in the...
Read More Read more about The DNS Trap: How a “Hidden” Path Allowed ChatGPT to Silently Leak Your Private Data
ResokerRAT Uses Telegram to Hijack Your PC and Disable Your Security Keys GuLoader Malware CloudEye Obfuscation npm, malware Ethereum, npm supply chain OAST techniques StilachiRAT macOS Malware PasivRobber
  • Malware

ResokerRAT Uses Telegram to Hijack Your PC and Disable Your Security Keys

Do Son April 6, 2026 0
A new and sophisticated threat has emerged in the digital landscape, turning a popular messaging app into...
Read More Read more about ResokerRAT Uses Telegram to Hijack Your PC and Disable Your Security Keys
The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026 PXA Stealer Surge Q1 2026 Malware Trends
  • Malware

The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026

Do Son April 6, 2026 0
Following the high-profile takedowns of major players like Lumma and RedLine in 2025, CyberProof MDR analysts have...
Read More Read more about The Python Predator: PXA Stealer Surges 10% as it Targets Global Finance and Crypto in 2026
The CVE Watchtower: Weekly Threat Intelligence Briefing (March 30 – April 5, 2026) Vulnerability Digest Zero-Day Exploits Seedworm APT Dindoor Backdoor RedKitten Campaign AI-Generated Malware WSUS RCE ShadowPad CVE-2025-59287
  • Weekly Recap

The CVE Watchtower: Weekly Threat Intelligence Briefing (March 30 – April 5, 2026)

Do Son April 6, 2026 0
Welcome to this week’s vulnerability digest. Whether you are a CISO charting out your risk management roadmap...
Read More Read more about The CVE Watchtower: Weekly Threat Intelligence Briefing (March 30 – April 5, 2026)
The $17 Million Bounty: Google Smashes Records and Launches AI Frontier for 15th VRP Anniversary Google VRP 2025 Bug Bounty Records
  • Vulnerability Report

The $17 Million Bounty: Google Smashes Records and Launches AI Frontier for 15th VRP Anniversary

Do Son April 5, 2026 0
In an era of increasingly complex digital threats, Google’s strategy of “inviting the world to find its...
Read More Read more about The $17 Million Bounty: Google Smashes Records and Launches AI Frontier for 15th VRP Anniversary
Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database Dgraph Vulnerability CVSS 10.0 Dgraph Admin Leak CVE-2026-40173
  • Vulnerability Report

Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database

Do Son April 5, 2026 2
A security vulnerability was found in Dgraph, the high-performance, horizontally scalable GraphQL database. The flaw, designated as...
Read More Read more about Zero Authentication, Total Control: Critical CVSS 10 Flaw Uncovered in Dgraph Database
Hackers are Using “Legit” IT Tools to Hijack the 2026 Tax Season 2026 Tax Phishing RMM Abuse
  • Cybercriminals

Hackers are Using “Legit” IT Tools to Hijack the 2026 Tax Season

Do Son April 5, 2026 0
As the 2026 tax season reaches its peak, cybersecurity researchers have identified a massive surge in digital...
Read More Read more about Hackers are Using “Legit” IT Tools to Hijack the 2026 Tax Season
Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild Knowledge Deliver RCE vulnerability FortiClient EMS Vulnerability CVE-2026-35616 Cisco SD-WAN Vulnerability CVE-2026-20122 PCPcat, Next.js RCE Salesloft breach, Salesforce CRM WIREFIRE web shell
  • Vulnerability Report

Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild

Do Son April 4, 2026 0
Security teams are on high alert as Fortinet confirms that a critical vulnerability in its FortiClient EMS...
Read More Read more about Under Active Attack: Critical 9.1 CVSS FortiClient EMS Flaw Exploited in the Wild
Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws Apache Traffic Server Vulnerabilities CVE-2024-56195 and CVE-2024-56196
  • Vulnerability Report

Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws

Do Son April 3, 2026 0
Apache Traffic Server, the high-performance web proxy cache responsible for keeping the modern web fast, is facing...
Read More Read more about Apache Traffic Server Patches “Double-Header” DoS and Request Smuggling Flaws
Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw Payload CMS Vulnerability CVE-2026-34751
  • Vulnerability Report

Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw

Do Son April 3, 2026 0
The rapid-growth, fullstack Next.js framework Payload—known for giving developers “instant backend superpowers” —is facing a serious security...
Read More Read more about Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-9862CVSS 9.8
    Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in...
  • CVE-2026-52704CVSS 10.0
    Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas...
  • CVE-2018-25436CVSS 9.8
    WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload...
  • CVE-2026-8935CVSS 9.8
    The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX...
  • CVE-2026-11526CVSS 9.8
    GD versions before 2.86 for Perl allow OS command injection and file...
  • CVE-2026-12183CVSS 9.8
    Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux...
  • CVE-2026-53609CVSS 9.1
    ApostropheCMS is an open-source Node.js content management system. In versions up to...
  • CVE-2026-53519CVSS 9.1
    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M...
  • CVE-2026-41157CVSS 9.8
    A web page that contains unusual WebGPU content loaded into the GPU...
  • CVE-2026-46716CVSS 9.9
    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.