TL;DR Phoenix Contact disclosed three vulnerabilities in PLCnext firmware on August 12, 2026. One flaw, CVE-2025-41771, lets...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
At a glance Malware family Gunra ransomware (RaaS, Conti-derived) Threat actor Gunra operators and affiliates, also branded...
TL;DR CISA disclosed eight vulnerabilities in the Mira Hormone Monitor and its Android app. The worst, CVE-2026-68067,...
TL;DR TP-Link disclosed five vulnerabilities across its ISP-managed networking gear. The flaws hit mesh systems, routers, PON...
TL;DR A researcher published full technical details and working proof-of-concept exploit code for CVE-2026-64582. The flaw is...
TL;DR HPE Aruba Networking patched two critical flaws in its SD-WAN EdgeConnect Orchestrator. Both carry a CVSS...
TL;DR Apple patched a flaw that let a local app gain root privileges through the mediaremoted service....
TL;DR A researcher at ByteriaLab found a zero-click flaw in Xiaomi ShareMe, also shipped as MiDrop. An...
TL;DR WordPress released version 7.0.4 on August 12, 2026, as a security-only update. It fixes CVE-2026-65640, an...
At a glance Malware family ChainDrop (Shai-Hulud code lineage) Threat actor Unattributed; possible link to TeamPCP (not...
At a glance Malware family Overlord (open-source RAT framework) Threat actor Unattributed (suspected DPRK links noted, not...
TL;DR Researchers at V12 Security published a MariaDB remote code execution chain. It runs commands as the...
TL;DR GitLab shipped a new patch release on August 12, 2026. Versions 19.2.2, 19.1.4, and 19.0.6 fix...
TL;DR Dell patched two critical flaws in Virtual Storage Integrator (VSI) for VMware vSphere Client. The worst,...
TL;DR A critical Nuxt DevTools vulnerability lets an attacker run arbitrary commands on a developer’s machine. Tracked...
TL;DR Two critical Puwell IP Camera vulnerabilities now have public details and proof-of-concept exploit code. Both score...
TL;DR Siemens has disclosed CVE-2026-58115, a maximum-severity flaw in SIMATIC IoT2050 Advanced devices. The bug scores a...
At a glance Malware family Atomic Stealer (AMOS) and MacSync infostealers Threat actor Unnamed operator running a...
At a glance Actor or group UNC6671 (suspected single coordinated group) Activity type Vishing-led data theft and...
TL;DR Rapid7 has published a technical analysis and a working proof-of-concept for CVE-2026-55040. The flaw is a...
TL;DR A researcher has published a public PoC called ShieldBreak. It bypasses Microsoft’s July patch for the...
TL;DR Google shipped a new Chrome security update on the Stable channel. It fixes five high-severity use-after-free...