TL;DR Splunk released patches on July 15, 2026 for three Splunk Enterprise vulnerabilities. The most serious, CVE-2026-20296,...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
TL;DR F5 has patched three memory safety flaws in NGINX Plus and NGINX Open Source. The most...
At a Glance Malware family Braintree.Net typosquat, a multi-stage .NET implant with a companion harvester (DependencyInjector.Core) Threat...
TL;DR Zoom has patched four flaws across its Windows products. The most severe Zoom vulnerability, CVE-2026-53412 (CVSS...
At a glance Actor / group Clubfoot Wolf (cluster tracked by BI.ZONE) Activity type Phishing that deploys...
TL;DR JetBrains has patched six JetBrains vulnerabilities across YouTrack, IntelliJ IDEA, and TeamCity. The most severe, CVE-2026-62422...
TL;DR Four critical Coolify vulnerabilities now have patches. Three score CVSS 9.9, and they let low-privileged members...
Introduction The increasing adoption of AI-enabled creative tools is a trend currently observed playing out in the...
The renowned cybersecurity firm Mindgard recently published an expose detailing a high-severity zero-day vulnerability harboring within Cursor,...
Google Images, born in July 2001, has officially reached its 25th anniversary. To celebrate the milestone, Google...
Malware family CrySome RAT, a .NET remote access trojan Threat actor Not named; no confirmed attribution Target...
Malware family RedWing (Android spyware/RAT; suspected new variant of Oblivion) Threat actor Unnamed operators; suspected Russian-nexus, not...
TL;DR A maximum-severity Rockwell Automation vulnerability, CVE-2026-10577, affects the 1715 Redundant I/O EtherNet/IP adapter (1715-AENTR). The access...
Actor / group Unnamed actor tracked as “Operation Muck and Load”; overlaps with the ischhfd83 cluster Activity...
At a Glance Malware family GodDamn ransomware (rebrand of Beast, formerly Monster) Threat actor Hyadina, a ransomware-as-a-service...
TL;DR Notepad++ v8.9.7 fixes five security flaws in the popular Windows editor. Technical details and proof-of-concept exploit...
TL;DR Google has shipped a Chrome security update that raises the Stable channel to 150.0.7871.124/.125 on Windows...
At a Glance Actor O-UNC-066 (Okta); tracked as CL-CRI-1147 / “Pink” by Palo Alto Unit 42; linked...
TL;DR CISA has confirmed active exploitation of three SharePoint vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. Threat actors chain...
At a glance Malware family Node.js backdoor (tracked as “TonRAT” by some researchers) Threat actor Unattributed; no...
TL;DR SonicWall has released hotfixes for two actively exploited flaws in SMA1000 secure access appliances. The SonicWall...