TL;DR A critical Kimai vulnerability, CVE-2026-52824 (CVSS 9.1), affects the open-source time-tracking app’s official Docker image. The...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
Most routing investigations still depend on someone else’s servers. When an engineer needs to know who originates...
TL;DR The Okta Red Team recently found a severe crash flaw in a core secure library. A...
At a glance Actor / group UTA0533 (Volexity tracking cluster); no nation or identity confirmed Activity type...
The United States Department of Justice recently announced a major policy shift. Federal workers can now legally...
At a glance Organization Hugging Face Data exposed A limited set of internal datasets and several service...
As the artificial intelligence arms race intensifies, computing power has emerged as the most coveted strategic resource....
Anthropic recently announced a major shift for its advanced AI models. Starting July 20, 2026, the company...
TL;DR A critical flaw in the ServiceNow AI platform allows unauthenticated users to run arbitrary commands. DefusedCyber...
Network provider Cloudflare recently published a blog post about emergency Web Application Firewall (WAF) rules. These new...
According to a recent announcement in the Microsoft 365 Admin Center, the company will gradually end support...
TL;DR Canonical shipped fixes for CVE-2026-11386 in USN-8555-1 on July 16, 2026. This Ubuntu Pro Client vulnerability...
TL;DR WordPress shipped 7.0.2 on July 17, 2026 to fix a critical flaw chain. The bug is...
At a glance Actor / group APT-C-60 (threat group) Activity Spear-phishing, LNK loader, SpyGlace backdoor Targets /...
As cyber threats continue to grow and SSL certificate lifecycles become shorter, businesses need a security provider...
In today’s digital world, protecting websites, applications, users, and sensitive data requires more than simply installing an...
At a glance Malware family GoldPickaxe (Android banking Trojan, GoldDigger suite) Threat actor GoldFactory (confirmed by Zimperium;...
At a glance Malware family RokRAT variant (x64) Threat actor Assessed highly likely APT37 (suspected, not confirmed)...
TL;DR A critical Kyverno vulnerability, CVE-2026-54523 (CVSS 9.6), has been publicly disclosed with full technical details and...
TL;DR Cloud Software Group published bulletin CTX696734 for two flaws in Citrix Windows clients. CVE-2026-53565, a Citrix...
At a glance Actor / group codemado, mail-argenta, saroula01 (online aliases) Activity AiTM phishing and OAuth Device...
At a Glance Malware family BoryptGrab-lineage in-memory infostealer Threat actor Unattributed; financially motivated, likely Russian-speaking Targets Opportunistic...