Skip to content
July 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
Critical 9.8 CVSS Flaws Expose SICK Lector Scanners to Hijacking SICK Lector Vulnerability CVE-2026-2331 CVE-2022-0778 and CVE-2025-0867
  • Vulnerability Report

Critical 9.8 CVSS Flaws Expose SICK Lector Scanners to Hijacking

Do Son March 10, 2026 0
Read More Read more about Critical 9.8 CVSS Flaws Expose SICK Lector Scanners to Hijacking
Malicious “Hex Visualizer” Chrome Extension Targeting imToken Users Crypto Wallet Drainer ImToken Phishing
  • Cybercriminals

Malicious “Hex Visualizer” Chrome Extension Targeting imToken Users

Do Son March 10, 2026 0
Read More Read more about Malicious “Hex Visualizer” Chrome Extension Targeting imToken Users
Critical 9.3 CVSS Flaw in Gogs Turns Repositories into Malware Delivery Vectors Gogs LFS Vulnerability CVE-2026-25921
  • Vulnerability Report

Critical 9.3 CVSS Flaw in Gogs Turns Repositories into Malware Delivery Vectors

Do Son March 10, 2026 0
Read More Read more about Critical 9.3 CVSS Flaw in Gogs Turns Repositories into Malware Delivery Vectors
Agencies Issue Urgent Warning on INC Ransom Healthcare Attacks INC Ransom Pacific Cyber Threats OysterLoader Malware Rhysida Ransomware Black Basta Ransomware BYOVD Technique Velociraptor Abuse, Storm-2603 Ransomware Crypto24, Ransomware Ransomware Payments, UK Legislation ZACROS data breach
  • Cybercriminals

Agencies Issue Urgent Warning on INC Ransom Healthcare Attacks

Do Son March 10, 2026 0
Read More Read more about Agencies Issue Urgent Warning on INC Ransom Healthcare Attacks
Critical Request Smuggling & Cache Flaws Discovered in Cloudflare’s Pingora Pingora Vulnerabilities Cloudflare Pingora
  • Vulnerability Report

Critical Request Smuggling & Cache Flaws Discovered in Cloudflare’s Pingora

Do Son March 10, 2026 0
Read More Read more about Critical Request Smuggling & Cache Flaws Discovered in Cloudflare’s Pingora
The Spy in Your Sidebar: Fake AI Browser Extensions Steal Data from 900,000 Users Malicious AI Extensions Chromium Browser Security
  • Malware

The Spy in Your Sidebar: Fake AI Browser Extensions Steal Data from 900,000 Users

Do Son March 10, 2026 0
Read More Read more about The Spy in Your Sidebar: Fake AI Browser Extensions Steal Data from 900,000 Users
The ‘Contagious Interview’ Trap: How a Web3 CEO Unmasked North Korean Stealth Malware Contagious Interview North Korean Malware
  • Cybercriminals

The ‘Contagious Interview’ Trap: How a Web3 CEO Unmasked North Korean Stealth Malware

Do Son March 10, 2026 0
Read More Read more about The ‘Contagious Interview’ Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server ClipXDaemon Linux Malware
  • Malware

Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server

Do Son March 10, 2026 0
Read More Read more about Silently Swapped: How ClipXDaemon Hijacks Linux Cryptowallets Without a C2 Server
Security Risk Advisors Releases “The Purple Perspective 2026” Report purple-perspective-social-press2_1772821885s5aslCzJZX
  • Press Release

Security Risk Advisors Releases “The Purple Perspective 2026” Report

cybernewswire March 9, 2026 0
Read More Read more about Security Risk Advisors Releases “The Purple Perspective 2026” Report
AWS Console Alert: Real-Time “AiTM” Phishing Campaign Bypasses MFA with Rapid Precision AWS Phishing AiTM Attack
  • Cybercriminals

AWS Console Alert: Real-Time “AiTM” Phishing Campaign Bypasses MFA with Rapid Precision

Do Son March 9, 2026 0
Read More Read more about AWS Console Alert: Real-Time “AiTM” Phishing Campaign Bypasses MFA with Rapid Precision
Industrial Alert: Urgent Apache IoTDB Patches Fix RCE and “Open Door” Default Flaws Apache IoTDB JEXL injection Apache IoTDB, Security Vulnerabilities
  • Vulnerability

Industrial Alert: Urgent Apache IoTDB Patches Fix RCE and “Open Door” Default Flaws

Do Son March 9, 2026 0
Read More Read more about Industrial Alert: Urgent Apache IoTDB Patches Fix RCE and “Open Door” Default Flaws
The Hidden Toggle: Why Windows 11’s New One-Click Dark Mode is Hiding in Your Battery Settings Windows 11 Dark Mode toggle
  • Windows

The Hidden Toggle: Why Windows 11’s New One-Click Dark Mode is Hiding in Your Battery Settings

Do Son March 9, 2026 0
Read More Read more about The Hidden Toggle: Why Windows 11’s New One-Click Dark Mode is Hiding in Your Battery Settings
The AI Arms Race for Developers: OpenAI Counters Anthropic with “Codex for Open Source” Codex rate limit reset OpenAI Codex limits, flexible rate limit resets, Codex vs Claude Code Vibe coding software engineer jobs OpenAI Codex for Open Source
  • Technology

The AI Arms Race for Developers: OpenAI Counters Anthropic with “Codex for Open Source”

Do Son March 9, 2026 0
Read More Read more about The AI Arms Race for Developers: OpenAI Counters Anthropic with “Codex for Open Source”
The Robotics Revolt: Why OpenAI’s Top Hardware Executive Quit Over the Pentagon’s New AI Pact OpenAI confidential IPO filing OpenAI code signing certificate rotation AI private equity joint ventures OpenAI Axios Supply Chain Attack OpenAI Promptfoo acquisition OpenAI military resignation ChatGPT Plus military fraud OpenAI smart speaker Jony Ive OpenAI Frontier platform ChatGPT AI age prediction 2026, OpenAI Persona age verification Sarah Friar OpenAI infrastructure, AI Scaling Law revenue OpenAI Gumdrop AI pen, Jony Ive OpenAI hardware 2027 OpenAI New CRO, Denise Dresser Monetization Strategy OpenAI Competitive Pressure Gemini 3 Overtake OpenAI Infrastructure, AI Closed Loop Economy
  • Technology

The Robotics Revolt: Why OpenAI’s Top Hardware Executive Quit Over the Pentagon’s New AI Pact

Do Son March 9, 2026 0
Read More Read more about The Robotics Revolt: Why OpenAI’s Top Hardware Executive Quit Over the Pentagon’s New AI Pact
The Ethics Embargo: Why the Pentagon Blacklisted Anthropic and the Tech Giants Struck Back Anthropic confidential IPO filing Anthropic Google $200 billion deal Anthropic Mythos Preview Anthropic Pentagon blacklist Claude Max 20x open-source Model Distillation Anthropic vs DeepSeek Claude Free tier update 2026
  • Technology

The Ethics Embargo: Why the Pentagon Blacklisted Anthropic and the Tech Giants Struck Back

Do Son March 9, 2026 0
Read More Read more about The Ethics Embargo: Why the Pentagon Blacklisted Anthropic and the Tech Giants Struck Back
Nintendo Sues the U.S. Government Over “Unlawful” Trump Tariffs Nintendo tariff lawsuit 2026 Nintendo Switch 2, MIG Tool Nintendo Switch 2, USB-C Restrictions Nintendo Switch 2, Vulnerability
  • Technology

Nintendo Sues the U.S. Government Over “Unlawful” Trump Tariffs

Do Son March 9, 2026 0
Read More Read more about Nintendo Sues the U.S. Government Over “Unlawful” Trump Tariffs
Torrent of Threats: China-Nexus APT UAT-9244 Hijacks South American Telecoms with PeerTime Backdoor BingX cyberattack FortiGate SSO Attacks Firewall Config Theft
  • Cyber Security
  • Malware

Torrent of Threats: China-Nexus APT UAT-9244 Hijacks South American Telecoms with PeerTime Backdoor

Do Son March 9, 2026 0
Read More Read more about Torrent of Threats: China-Nexus APT UAT-9244 Hijacks South American Telecoms with PeerTime Backdoor
Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive Vulnerability Digest Zero-Day Exploits Seedworm APT Dindoor Backdoor RedKitten Campaign AI-Generated Malware WSUS RCE ShadowPad CVE-2025-59287
  • Cyber Security
  • Malware

Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive

Do Son March 9, 2026 0
Read More Read more about Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive
Fake GitHub Repositories Unleash BoryptGrab Stealer and TunnesshClient Backdoor TanStack Typosquatting npm Supply Chain Attack Axios Supply Chain Attack npm Poisoning eScan Supply Chain Attack Antivirus Compromise APT-36, NCERT WhatsApp Advisory FBI alert, Salesforce Salt Typhoon, APT group ConnectWise ScreenConnect hack Nation-state cyberattack FortiGate Leak - zkLend vulnerability - TRIPLESTRENGTH Threat Actor Group Dark Storm
  • Malware

Fake GitHub Repositories Unleash BoryptGrab Stealer and TunnesshClient Backdoor

Do Son March 9, 2026 0
Read More Read more about Fake GitHub Repositories Unleash BoryptGrab Stealer and TunnesshClient Backdoor
Critical 9.4 CVSS Zephyr RTOS Flaw Exposes Millions of IoT Devices to RCE Zephyr RTOS Vulnerability CVE-2026-1678
  • Vulnerability Report

Critical 9.4 CVSS Zephyr RTOS Flaw Exposes Millions of IoT Devices to RCE

Do Son March 9, 2026 0
Read More Read more about Critical 9.4 CVSS Zephyr RTOS Flaw Exposes Millions of IoT Devices to RCE
Vault Unlocked: High-Severity Flaws in Vaultwarden Expose Encrypted Secrets and Allow Privilege Escalation Vaultwarden Vulnerabilities CVE-2026-27898
  • Vulnerability Report

Vault Unlocked: High-Severity Flaws in Vaultwarden Expose Encrypted Secrets and Allow Privilege Escalation

Do Son March 9, 2026 0
Read More Read more about Vault Unlocked: High-Severity Flaws in Vaultwarden Expose Encrypted Secrets and Allow Privilege Escalation
Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection SiYuan XSS Vulnerability CVE-2026-29183
  • Vulnerability Report

Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection

Do Son March 9, 2026 0
Read More Read more about Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-0770CVSS 9.8
    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2021-27137CVSS 8.1
    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality...
    CISA KEV📅 Added to KEV: Jul 21, 2026
  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-66013CVSS 9.3
    OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration...
  • CVE-2026-66012CVSS 10.0
    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp...
  • CVE-2026-61884CVSS 9.8
    The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation...
  • CVE-2026-62379CVSS 9.8
    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote...
  • CVE-2026-62263
    ### Summary The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter`...
  • CVE-2026-62835CVSS 9.3
    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information...
  • CVE-2026-48021CVSS 9.1
    In epa4all, prior to version 2026-05-20, an attacker who can intercept the...
  • CVE-2026-59940CVSS 9.8
    ## Summary A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input...
  • CVE-2026-58630CVSS 10.0
    Improper access control in Azure App Service allows an unauthorized attacker to...
  • CVE-2026-57106CVSS 10.0
    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.