Skip to content
July 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
APT28 Hijacks Home Routers to Steal Corporate Credentials GemStuffer RubyGems Campaign RubyGems Data Exfiltration TanStack npm Compromise Supply Chain Attack DNS Hijacking APT28 (Fancy Bear) OpenVSX Supply Chain Attack Checkmarx Plugin Breach Stryker Cyberattack CISA Alert Trans-Regional Cyber Conflict Operation Epic Fury Cyber Operation MacroMaze APT28 Cyber Espionage Notepad++ Supply Chain Attack Lotus Blossom Group Defense Industrial Base Threats GTIG Report APT28 Operation Neusploit CVE-2026-21509 Bookworm Malware
  • Cybercriminals

APT28 Hijacks Home Routers to Steal Corporate Credentials

Do Son April 8, 2026 0
Read More Read more about APT28 Hijacks Home Routers to Steal Corporate Credentials
Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets Venom Stealer Crypto Drainer MaaS
  • Malware

Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets

Do Son April 8, 2026 0
Read More Read more about Venom Stealer Bypasses Chrome and “Auto-Cracks” Tonkeeper Wallets
The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry Contagious Interview Malicious Packages
  • Malware

The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry

Do Son April 8, 2026 0
Read More Read more about The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
Malicious VeloraDEX SDK Compromises Developer Machines via npm npm Supply Chain Attack @velora-dex/sdk Malware
  • Malware

Malicious VeloraDEX SDK Compromises Developer Machines via npm

Do Son April 8, 2026 0
Read More Read more about Malicious VeloraDEX SDK Compromises Developer Machines via npm
From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints TA416 PlugX Backdoor
  • Cyber Security
  • Malware

From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints

Do Son April 8, 2026 0
Read More Read more about From Taiwan to Tehran: How TA416 Pivots its PlugX Backdoor to Global Flashpoints
Budibase Patches Critical RCE and SSRF Vulnerabilities Budibase RCE SSRF Vulnerability Budibase Vulnerabilities Authentication Bypass
  • Vulnerability Report

Budibase Patches Critical RCE and SSRF Vulnerabilities

Do Son April 7, 2026 0
Read More Read more about Budibase Patches Critical RCE and SSRF Vulnerabilities
10.0 CVSS Flaw in Kestra Grants Full Server Control Kestra RCE SQL Injection Vulnerability
  • Vulnerability Report

10.0 CVSS Flaw in Kestra Grants Full Server Control

Do Son April 7, 2026 0
Read More Read more about 10.0 CVSS Flaw in Kestra Grants Full Server Control
Critical JWT Bypass in Convoy Panel Allows Full Account Takeover Convoy Vulnerability JWT Authentication Bypass
  • Vulnerability Report

Critical JWT Bypass in Convoy Panel Allows Full Account Takeover

Do Son April 7, 2026 0
Read More Read more about Critical JWT Bypass in Convoy Panel Allows Full Account Takeover
Breaking the App Shell: Five New Electron Vulnerabilities Shatter Context Isolation Electron Security Sandbox Escape Electron Vulnerabilities, Desktop App Security
  • Vulnerability Report

Breaking the App Shell: Five New Electron Vulnerabilities Shatter Context Isolation

Do Son April 7, 2026 0
Read More Read more about Breaking the App Shell: Five New Electron Vulnerabilities Shatter Context Isolation
Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims CrystalX RAT Prankware
  • Malware

Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims

Do Son April 7, 2026 0
Read More Read more about Trolling as a Service: How the New CrystalX RAT Uses “Prankware” to Torture Its Victims
BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender BlueHammer Exploit Windows Defender 0-day
  • Vulnerability Report

BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender

Do Son April 7, 2026 0
Read More Read more about BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender
UAT-10608 Uses a Next.js “React2Shell” Flaw to Map Your Entire Cloud NEXUS Listener React2Shell Vulnerability
  • Cybercriminals

UAT-10608 Uses a Next.js “React2Shell” Flaw to Map Your Entire Cloud

Do Son April 7, 2026 0
Read More Read more about UAT-10608 Uses a Next.js “React2Shell” Flaw to Map Your Entire Cloud
The Hidden Hand: Why Adobe is Surreptitiously Modifying Your System Hosts File Adobe Creative Cloud hosts file Adobe Firefly, AI video
  • Technology

The Hidden Hand: Why Adobe is Surreptitiously Modifying Your System Hosts File

Do Son April 7, 2026 0
Read More Read more about The Hidden Hand: Why Adobe is Surreptitiously Modifying Your System Hosts File
The Evolution of an Infostealer: Xloader 8.7 Unmasked Xloader Malware Information Stealer Phantom Stealer v3.5.0 DLL Sideloading Attack
  • Malware

The Evolution of an Infostealer: Xloader 8.7 Unmasked

Do Son April 7, 2026 0
Read More Read more about The Evolution of an Infostealer: Xloader 8.7 Unmasked
GPUBreach Rowhammer Hijacks GPUs for Full System Root GPUBreach GPU Rowhammer
  • Vulnerability Report

GPUBreach Rowhammer Hijacks GPUs for Full System Root

Do Son April 7, 2026 0
Read More Read more about GPUBreach Rowhammer Hijacks GPUs for Full System Root
End of an Era: Linux Kernel 7.1 Finally Bids Farewell to the Iconic Intel 486 Linux Kernel 7.1 release Linux Kernel update, AMD ZEN 6 support, Linux driver fixes Linux Kernel 7.1 i486 support Linux 7.0 HIPPI support removal, legacy networking protocol retirement Linus Torvalds AI slop Linux kernel, Lorenzo Stoakes AI tool debate Linux Kernel Rust CVE-2025-68260, Android Binder Rust Race Condition TSEM Security Module Controversy, Linus Torvalds LSM Dispute Kernel Panic, PoC released Linux Kernel 6.16, File System Fixes CVE-2023-42753 - Linux Kernel Developers
  • Linux

End of an Era: Linux Kernel 7.1 Finally Bids Farewell to the Iconic Intel 486

Do Son April 7, 2026 0
Read More Read more about End of an Era: Linux Kernel 7.1 Finally Bids Farewell to the Iconic Intel 486
Browser Wars 2026: The “Choice Alliance” Slams Microsoft’s Predatory Edge Auto-Launch Browser Choice Alliance Microsoft CVE-2024-30055 Microsoft Edge, Copilot Mode
  • Windows

Browser Wars 2026: The “Choice Alliance” Slams Microsoft’s Predatory Edge Auto-Launch

Do Son April 7, 2026 0
Read More Read more about Browser Wars 2026: The “Choice Alliance” Slams Microsoft’s Predatory Edge Auto-Launch
The $4.5 Million Squeeze: How Via LA’s Secret H.264 Fee Hike is Shaking the Streaming Industry Via LA H.264 licensing fees
  • Technology

The $4.5 Million Squeeze: How Via LA’s Secret H.264 Fee Hike is Shaking the Streaming Industry

Do Son April 7, 2026 0
Read More Read more about The $4.5 Million Squeeze: How Via LA’s Secret H.264 Fee Hike is Shaking the Streaming Industry
The Unkillable Spy: How “Operation NoVoice” Rootkits Hijack Androids and Clone WhatsApp Operation NoVoice Android Rootkit
  • Malware

The Unkillable Spy: How “Operation NoVoice” Rootkits Hijack Androids and Clone WhatsApp

Do Son April 7, 2026 0
Read More Read more about The Unkillable Spy: How “Operation NoVoice” Rootkits Hijack Androids and Clone WhatsApp
Android Security Bulletin April 2026: Critical Framework Patch Targets “Zero-Interaction” DoS Vulnerability Android CLI Android Security Zero-Interaction DoS CVE-2026-21385 Android Security Update UK CMA Apple Google regulation Google Aluminum OS Android 16 leak, ALOS Android ChromeOS merger Android sideloading certification 2026, Google developer verification APK Android AOSP biannual release, AOSP source code latency 2026 Android Zero-Day, Critical DoS Flaw Android Universal Clipboard Cross-Device Sync Gemini Nano Block, Unlocked Bootloader Android, Calling Cards Android Security Bulletin, RCE Vulnerability Android Linux GUI, Debian VM Android System Services, Google Transparency Android 16, Pixel Update
  • Android
  • Vulnerability Report

Android Security Bulletin April 2026: Critical Framework Patch Targets “Zero-Interaction” DoS Vulnerability

Do Son April 7, 2026 0
Read More Read more about Android Security Bulletin April 2026: Critical Framework Patch Targets “Zero-Interaction” DoS Vulnerability
The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation CNB Bot Malware REF1695 Threat Actor
  • Malware

The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation

Do Son April 7, 2026 0
Read More Read more about The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation
Microsoft Edge Trials Controversial Auto-Startup Without User Consent Microsoft Edge Google account login interface and synchronization settings Browser Choice Alliance letter Microsoft Edge cleartext credentials memory dump Microsoft Edge auto-startup Microsoft Edge Collections sunset, export Edge Collections CSV Edge IE Mode Zero-Day, Chakra Exploit Windows Search, Microsoft Edge AI video translation, Edge browser Microsoft Editor, Edge Edge Developer tools Windows 10 ESU, Microsoft Edge Microsoft Edge, FCP Optimization CVE-2023-36735 Edge, AI Search
  • Windows

Microsoft Edge Trials Controversial Auto-Startup Without User Consent

Do Son April 7, 2026 0
Read More Read more about Microsoft Edge Trials Controversial Auto-Startup Without User Consent
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
  • CVE-2026-56163CVSS 10.0
    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.