Preinstalled smartphone applications frequently operate with high system privileges. Security researchers recently uncovered a severe OnePlus session...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
Gift card fraud remains a rampant issue for corporations like Apple in the United States. Consequently, criminal...
Google is actively modifying the trash retention policy within its widely used Photos application. According to the...
Microsoft is developing an age-awareness API for Windows 11 to satisfy the age-rating verification mandates emerging across...
Brave, the independent browser and search engine developer, recently sent a mass email announcing a change to...
At a glance Actor or group Suspected DPRK APTs (APT37 links, medium confidence) Activity type Linux backdoor,...
At a glance Field Details Actor or Group Unattributed cybercrime operators Activity Type Email filter evasion, credential...
At a glance Field Details Actor or Group Kimsuky (North Korean state-sponsored threat group) Activity Type Spearphishing,...
NVIDIA patched two high-severity security flaws in its AI inferencing platform on September 10, 2026. These critical...
Five important-severity Apache Artemis vulnerabilities affect protocol handling and core authentication mechanisms. These ActiveMQ Artemis flaws allow...
At a glance Microsoft threat analysts reported active cloud intrusions utilizing passkey social engineering to breach enterprise...
Arista Networks published four security advisories on September 9, 2026, resolving multiple critical security flaws. These critical...
Security researchers discovered a critical Secure Boot bypass vulnerability impacting multiple major hardware vendors today. This flaw...
TL;DR MongoDB fixed 24 MongoDB Server vulnerabilities in recent releases. One critical flaw can leave authorization disabled...
Okta published security advisories resolving six vulnerabilities across several enterprise identity products on September 9, 2026. These...
Researchers recently published the LSPromise exploit chain, demonstrating a complete path from a local untrusted app to...
Threat actors are actively compromising executive accounts using highly targeted Microsoft 365 vishing attacks. The PREY-0058 extortion...
Palo Alto Networks disclosed a high-severity PAN-OS buffer overflow flaw today. This vulnerability allows unauthenticated remote attackers...
Website speed is vital for the success of an online store, as customers want product pages to...
Threat researchers at Cisco Talos are tracking the active exploitation of two critical Cisco FMC vulnerabilities. Malicious...
At a glance Truffle Security researchers found a critical GnuTLS token leak on June 17, 2026. This...
Streaming is now part of everyday web use, which also makes it useful cover for attackers. A...