Skip to content
June 18, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass Gogs Vulnerability CVE-2025-8110 CVE-2025-64111
  • Vulnerability Report

Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass

Do Son February 10, 2026 0
A triple threat of security vulnerabilities has been uncovered in Gogs, the popular self-hosted Git service known...
Read More Read more about Triple Threat: Critical Gogs Flaws (CVSS 9.3) Allow RCE & 2FA Bypass
Virtual Invasion: SolarWinds WHD Exploited to Host Hidden QEMU VMs SolarWinds Web Help Desk QEMU Persistence
  • Vulnerability Report

Virtual Invasion: SolarWinds WHD Exploited to Host Hidden QEMU VMs

Do Son February 10, 2026 0
In a striking display of “living off the land” gone wrong, threat actors are turning legitimate administrative...
Read More Read more about Virtual Invasion: SolarWinds WHD Exploited to Host Hidden QEMU VMs
Trust Broken: Critical Keylime Flaw (CVSS 9.4) Disables mTLS Authentication Keylime Vulnerability CVE-2026-1709
  • Vulnerability Report

Trust Broken: Critical Keylime Flaw (CVSS 9.4) Disables mTLS Authentication

Do Son February 10, 2026 0
A critical-severity vulnerability has been discovered in Keylime, the open-source tool used by cloud tenants to verify...
Read More Read more about Trust Broken: Critical Keylime Flaw (CVSS 9.4) Disables mTLS Authentication
Silent Killer: Black Basta Bundles “BYOVD” Driver to Blind Antivirus INC Ransom Pacific Cyber Threats OysterLoader Malware Rhysida Ransomware Black Basta Ransomware BYOVD Technique Velociraptor Abuse, Storm-2603 Ransomware Crypto24, Ransomware Ransomware Payments, UK Legislation ZACROS data breach
  • Malware

Silent Killer: Black Basta Bundles “BYOVD” Driver to Blind Antivirus

Do Son February 10, 2026 0
The notorious Black Basta ransomware group has upgraded its arsenal with a dangerous new capability, embedding defense...
Read More Read more about Silent Killer: Black Basta Bundles “BYOVD” Driver to Blind Antivirus
CVE-2026-25592: Critical Semantic Kernel Flaw (CVSS 10.0) Allows File Overwrite Semantic Kernel Vulnerability CVE-2026-25592
  • Vulnerability Report

CVE-2026-25592: Critical Semantic Kernel Flaw (CVSS 10.0) Allows File Overwrite

Do Son February 10, 2026 0
Microsoft has issued a critical security advisory for developers using its Semantic Kernel .NET SDK, warning of...
Read More Read more about CVE-2026-25592: Critical Semantic Kernel Flaw (CVSS 10.0) Allows File Overwrite
Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI dYdX Supply Chain Attack Malicious npm Package
  • Malware

Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI

Do Son February 10, 2026 0
A sophisticated supply chain attack has struck the dYdX decentralized exchange protocol, injecting malicious code into official...
Read More Read more about Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens Payload CMS Vulnerability CVE-2026-25544
  • Vulnerability Report

CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens

Do Son February 10, 2026 0
A massive security hole has been blown open in Payload, the popular “Next.js native CMS” designed to...
Read More Read more about CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens
Marco Stealer: The New “Data Raider” Targeting Crypto & Cloud Storage PromptMink Campaign AI Agent Deception LIMINAL PANDA UNC1549 DLL Hijacking, VDI Breakout
  • Malware

Marco Stealer: The New “Data Raider” Targeting Crypto & Cloud Storage

Do Son February 10, 2026 0
A new information-stealing malware has entered the chat, and it is aggressively targeting the digital wallets and...
Read More Read more about Marco Stealer: The New “Data Raider” Targeting Crypto & Cloud Storage
Criminal IP Integrates with IBM QRadar to Deliver Real-Time Threat Intelligence Across SIEM and SOAR 2_1200_700_2_1770606217wfV7bGFmpC
  • Press Release

Criminal IP Integrates with IBM QRadar to Deliver Real-Time Threat Intelligence Across SIEM and SOAR

cybernewswire February 9, 2026 0
Torrance, United States / California, 9th February 2026, CyberNewswire
Read More Read more about Criminal IP Integrates with IBM QRadar to Deliver Real-Time Threat Intelligence Across SIEM and SOAR
Siri’s New Soul: Why iOS 27 is the “Snow Leopard” Moment Your iPhone Desperately Needs Mac Pro discontinued 2026 iOS 27 Snow Leopard update iOS 27 Maintenance Apple Stability Focus M5 MacBook, Studio Display macOS update, Mac Studio M3 Ultra Perplexity Apple, Perplexity AI Acquisition Mac Mini M2, Power Issue macOS, Intel Macs
  • Technology

Siri’s New Soul: Why iOS 27 is the “Snow Leopard” Moment Your iPhone Desperately Needs

Do Son February 9, 2026 0
Reports suggest that Apple’s software stratagem for the current year will be characterized by notable restraint. iOS...
Read More Read more about Siri’s New Soul: Why iOS 27 is the “Snow Leopard” Moment Your iPhone Desperately Needs
Don’t Trash Your Printer: Microsoft Clarifies “End of Support” for V3 and V4 Drivers in Windows 11 Windows 11 app updates Windows Insider preview build, Calculator app update, built-in Windows apps Windows 11 KB5089549 network lag Windows 11 Home to Pro Education upgrade Windows 11 Start menu update Windows 11 update KB5079391 Windows 11 KB5085516 OOB update Windows 11 C drive permission error Windows 11 C drive access denied Windows native NVMe driver UEFI Secure Boot certificate rotation Windows 11 printer driver policy Windows 11 printer driver deprecation Windows 11 Build 26300 Sysmon Windows 11 Storage settings restriction Windows 11 Build 26300.7674, Windows Insider channel migration 2026 Windows 11 Update Fix KB5073455 shutdown bug, Secure Launch restart loop Windows 11 File Explorer search performance, Search Indexer RAM usage fix Windows 11 Gaming PC Specs, NVMe DirectStorage Windows 10 End of Support Windows 11 Slow Adoption Windows 11 Crash Loop KB5062553 Bug Update and Shut Down, KB5067036 Windows authentication, Kerberos bug Windows 11 fix, localhost bug Windows 11 Update Restart, Update and Shut Down Windows SMBv1 Windows 11 Arm, Easy Anti-Cheat Windows 11 error, Pluton Windows 11 24H2, Easy Anti-Cheat Windows Firewall Bug, Microsoft Update Error Windows 11, JScript9Legacy Windows Activation, TSforge Windows 11 Update, Firewall Error Windows 11 25H2, Annual Update Windows Resiliency Initiative, Kernel Security Windows 11 Upgrade, ESU Program Windows 11 Recall, Data Export Windows 11 Easy Anti-Cheat Windows 11 Update, Cumulative Update Windows Update, ACPI.sys Windows Updates, Enterprise Software Windows 11 Start Data Encryption Standard Printing Problems Windows 11 updates Estimated installation time Smart App Control, Windows 11 security
  • Windows

Don’t Trash Your Printer: Microsoft Clarifies “End of Support” for V3 and V4 Drivers in Windows 11

Do Son February 9, 2026 0
Microsoft previously indicated that, commencing with the optional updates in January 2026, it would formally deprecate legacy...
Read More Read more about Don’t Trash Your Printer: Microsoft Clarifies “End of Support” for V3 and V4 Drivers in Windows 11
Verified or Vanished: Google Voice Now Requires Government ID to Stop “Gray Market” Scammers Google Voice identity verification
  • Technology

Verified or Vanished: Google Voice Now Requires Government ID to Stop “Gray Market” Scammers

Do Son February 9, 2026 0
Google provides users with complimentary United States mobile numbers via Google Voice for VOIP teleconferencing and messaging...
Read More Read more about Verified or Vanished: Google Voice Now Requires Government ID to Stop “Gray Market” Scammers
Endpoint Exposed: Critical FortiClient EMS Flaw (CVSS 9.1) Allows Unauthenticated RCE FortiSandbox Vulnerability Unauthenticated RCE FortiClient EMS Vulnerability CVE-2026-21643 FortiClient EMS Vulnerability CVE-2026-21643 CVE-2023-34992 - CVE-2023-37936 Fortinet Vulnerabilities CVE-2025-64155
  • Vulnerability Report

Endpoint Exposed: Critical FortiClient EMS Flaw (CVSS 9.1) Allows Unauthenticated RCE

Do Son February 9, 2026 0
Fortinet has issued a high-priority security advisory for its FortiClient Enterprise Management Server (EMS), warning of a...
Read More Read more about Endpoint Exposed: Critical FortiClient EMS Flaw (CVSS 9.1) Allows Unauthenticated RCE
Speed of Truth: X Trials “Collaborative Notes” to Supercharge Fact-Checking with Grok AI X Collaborative Notes pilot
  • Technology

Speed of Truth: X Trials “Collaborative Notes” to Supercharge Fact-Checking with Grok AI

Do Son February 9, 2026 0
Since the acquisition of Twitter by Elon Musk and its subsequent transformation into X, Community Notes has...
Read More Read more about Speed of Truth: X Trials “Collaborative Notes” to Supercharge Fact-Checking with Grok AI
Co-Pilots of the Future: Apple Opens CarPlay to ChatGPT and Google Gemini for Smarter Road Trips Apple HomePad delay Tesla CarPlay integration 2026 Apple CarPlay AI integration 2026 Apple 2026 product roadmap rumors, foldable iPhone release date Apple Vision Pro sales slump, Vision Pro production cut Russia FaceTime Ban Network Blockade Apple Apple 2026 Roadmap, iPhone Foldable, Apple Intelligence Apple Maps ads, iOS monetization Apple, Digital Markets Act FCC Leak, iPhone 16e Schematics iPhone Fold Apple Made in India Apple US Investment, Indian Tariffs Apple Leadership, Tim Cook Tenure Siri Redesign, Apple AI Apple App Store Apple EU, Digital Markets Act CVE-2022-32898 Third-Party iOS Apps Apple Antitrust, DOJ Lawsuit
  • Technology

Co-Pilots of the Future: Apple Opens CarPlay to ChatGPT and Google Gemini for Smarter Road Trips

Do Son February 9, 2026 0
According to reports from Bloomberg, Apple intends to facilitate the integration of third-party voice-controlled artificial intelligence applications—such...
Read More Read more about Co-Pilots of the Future: Apple Opens CarPlay to ChatGPT and Google Gemini for Smarter Road Trips
Fortune Favors the AI: Crypto.com CEO Drops $70M on AI.com to Launch “Synthetic Secretaries” at Super Bowl LX Kris Marszalek AI.com launch
  • Technology

Fortune Favors the AI: Crypto.com CEO Drops $70M on AI.com to Launch “Synthetic Secretaries” at Super Bowl LX

Do Son February 9, 2026 0
Recalling the 2021 global phenomenon where the Singaporean cryptocurrency exchange Crypto.com debuted its ubiquitous “Fortune Favors the...
Read More Read more about Fortune Favors the AI: Crypto.com CEO Drops $70M on AI.com to Launch “Synthetic Secretaries” at Super Bowl LX
Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover shell-quote command injection AI-Driven Vulnerabilities Q1 2026 Cyber Threats vm2 Sandbox Escape Node.js RCE upKeeper Privilege Escalation CVE-2026-2449 Pharos Controls Vulnerability Root Access Exploit Cybersecurity Vulnerability Roundup CVSS 10.0 Flaws Shadow Archives CVE-2026-0866 MS-Agent Prompt Injection CVE-2026-2256 basic-ftp Path Traversal CVE-2026-27699 telnetd Root Vulnerability CVE-1999-0073 Regression USR-W610 Vulnerabilities End-of-Life IoT Security IceWarp Security Update IceWarp Vulnerabilities Airleader Master Vulnerability CVE-2026-1358 ZLAN5143D Vulnerability CISA ICS Advisory Acronis Cyber Protect Vulnerability CVE-2025-30411 WAGO 852 Vulnerability OT Network Security SandboxJS Vulnerability Sandbox Escape (CVSS 10.0) Kubernetes Local Path Provisioner CVE-2025-62878 CISA Unresponsive Vendors Avation & RISS Vulnerabilities KiloView Vulnerability CVE-2026-1453 OpenClaw RCE vulnerability Johnson Controls Vulnerability CVE-2025-26385 SandboxJS Vulnerability CVE-2026-23830 ibaPDA Vulnerability CVE-2025-14988 Protobuf Vulnerability CVE-2026-0994 AVEVA Process Optimization Vulnerability CVE-2025-61937 ConnectWise PSA Vulnerability CVE-2026-0695 Aruba VIA Vulnerability CVE-2025-37186 aiohttp v3.13.3, Denial of Service (DoS) SmarterMail RCE, CVE-2025-52691 Airoha RACE, Headphone Jacking HPE OneView RCE CVE-2025-37164 FreePBX Auth Bypass, PBX Takeover ScreenConnect Config Flaw, Untrusted Extensions Ruby SAML Auth Bypass, XML Parser Differential Devolutions SQL Injection, Password Manager Flaw Vivotek Unauthenticated RCE, EOL IP Camera Flaw Lynx+ Critical Flaw, Unauthenticated Reset Firebox Default Credentials, CVE-2025-59396 Veeder-Root RCE, Critical ATG Flaw ArcGIS Server SQLi Watchdoc RCE, CVE-2025-58384 Delta DIALink Daikin Security Gateway, authentication bypass Frostbyte10, industrial controller security SunPower, vulnerability Ubiquiti UniFi Connect, EV Station Vulnerabilities Adobe Experience Manager, RCE Vulnerability UniFi Access, Command Injection LDAPNightmare - CVE-2025-1316
  • Vulnerability Report

Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover

Do Son February 9, 2026 0
A quartet of critical vulnerabilities has been discovered in SandboxJS, a library designed to isolate and secure...
Read More Read more about Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover
Digital Detox Mandate: EU Charges TikTok Over “Autopilot” Design and Minor Safety Failures TikTok addictive design breach TikTok, ByteDance TikTok Zero-Day - TikTok Play Store Trump Extends TikTok
  • Technology

Digital Detox Mandate: EU Charges TikTok Over “Autopilot” Design and Minor Safety Failures

Do Son February 9, 2026 0
The European Commission has promulgated its preliminary investigative findings, adjudging that TikTok’s structural architecture contravenes the European...
Read More Read more about Digital Detox Mandate: EU Charges TikTok Over “Autopilot” Design and Minor Safety Failures
The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC OSX/Amos Stealer Electron ASAR Trojan MioLab Malware macOS Security MacSync Stealer macOS Malware ambar-src npm Malware Supply Chain Typosquatting Matryoshka Mac Malware ClickFix Crypto Scam Infostealer Evolution macOS Malware Predator Spyware Intellexa Anti-Analysis XCSSET macOS Malware, Xcode Supply Chain
  • Malware

The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC

Do Son February 9, 2026 0
Mac users, often confident in the “walled garden” security of their devices, are facing a new threat...
Read More Read more about The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC
Tearing Down the Walled Garden: How Google Quick Share Finally Bridged the AirDrop Chasm Google Quick Share AirDrop Google Quick Share AirDrop interoperability, Pixel 9 AirDrop support 2026 Snapdragon AirDrop Quick Share Interoperability Quick Share AirDrop Cross-Platform File Transfer
  • Android

Tearing Down the Walled Garden: How Google Quick Share Finally Bridged the AirDrop Chasm

Do Son February 9, 2026 0
In addition to elucidating the dawn of the AI Agent era for Pixel devices and the pivotal...
Read More Read more about Tearing Down the Walled Garden: How Google Quick Share Finally Bridged the AirDrop Chasm
❮ Prev Page
Next Page ❯

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-54419CVSS 9.8
    claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5)...
  • CVE-2026-8024CVSS 9.8
    A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability...
  • CVE-2026-55742CVSS 9.6
    Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery...
  • CVE-2026-55740CVSS 9.8
    Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL...
  • CVE-2026-48768CVSS 9.3
    TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST...
  • CVE-2026-54388CVSS 9.1
    Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing...
  • CVE-2026-54387CVSS 9.1
    Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length...
  • CVE-2026-48814CVSS 9.1
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the...
  • CVE-2026-55518CVSS 9.6
    ## Summary A critical missing authorization flaw exists in Avo's association attach...
  • CVE-2026-55471
    ### Summary `org.hl7.fhir.utilities.XsltUtilities` exposes two parallel families of XSLT transform helpers. The...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.