At a glance Actor / group DPRK-aligned group behind the Contagious Interview campaign (Elastic tracks it as...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
At a glance Malware family ACR Stealer (infostealer; linked to a rebrand of Amatera Stealer) Threat actor...
Unsanctioned Desktop Advertising Sparks Outrage Netizens recently observed an unsettling phenomenon: upon connecting newly acquired LG monitors,...
TL;DR ManageEngine patched a critical ADAudit Plus vulnerability tracked as CVE-2026-6516. Two weaknesses in the product’s Agent...
TL;DR A researcher published full technical details and working proof-of-concept exploit code for a Knot Resolver RCE...
TL;DR CERT/CC published vulnerability note VU#492466 on 23 July 2026, covering six flaws in the Logto identity...
At a glance Actor Jinbin Ren, 38, a Chinese national who lived in Lynnfield, Massachusetts; co-conspirators unnamed...
TL;DR Google pushed Chrome 150.0.7871.186/.187 to the Stable channel on 23 July 2026. This Chrome security update...
We live in an age thoroughly dependent on digital accounts. How, then, does one prove one is...
A newly disclosed HTTP/2 DoS vulnerability affects several server implementations at once. A remote, unauthenticated attacker can...
At a Glance Actor or group TA488 (Void Blizzard, Laundry Bear) and TA458 (Operation RoundPress), both Russia-aligned...
TL;DR JetBrains fixed 18 vulnerabilities across GoLand, IntelliJ IDEA, PhpStorm, PyCharm, TeamCity, and WebStorm. Two IntelliJ IDEA...
The Apache Syncope project has patched two security flaws in its identity management platform. Both Apache Syncope...
TL;DR A security researcher has published full details and proof-of-concept code for a Foxit PDF Reader vulnerability....
TL;DR Vercel fixed three Next.js vulnerabilities, each rated CVSS 8.3. Two of them allow Server-Side Request Forgery,...
TL;DR CERT/CC published vulnerability note VU#326070 on July 16, 2026. It details an SGLang vulnerability, CVE-2026-14890, rated...
Revolutionizing Secure Enterprise Software Distribution Canonical recently unveiled its new enterprise application hub built on the Ubuntu...
Raspberry Pi has introduced a new touchscreen to its official display range. Seven-inch and five-inch models arrived...
At a Glance Actor or group A vendor using the alias “Kontraktnik”; no real identity published Activity...
The transatlantic submarine cable Nuvem, financed and controlled by Google, is approaching full service. It principally joins...
The Microsoft-owned code repository, GitHub, recently published a blog post announcing a sweeping overhaul of its security...