TL;DR A Linux kernel use-after-free in SCTP, tracked as CVE-2026-64564, allows local attackers to gain root. Researchers...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
TL;DR CVE-2026-63077 is a critical unauthenticated remote code execution flaw in JetBrains TeamCity. An attacker who reaches...
At a Glance Malware family API-driven XSS supply chain implant (Biggopti banner abuse) Threat actor Suspected; linked...
Lars Froder, the developer known as opa334, has released Dopamine 3.0, the first jailbreak to support iOS...
Google recently announced a groundbreaking new feature for the United States market. This innovative capability allows parents...
TL;DR Metabase disclosed a critical SQL injection zero-day rated CVSS 10. An unauthenticated remote attacker can gain...
TL;DR Cisco disclosed seven ClamAV vulnerabilities on August 7, 2026. Each lets an unauthenticated remote attacker crash...
TL;DR A weak random number generator inside CryptoJS produced predictable wallet seed phrases for over a decade....
TL;DR WSO2 disclosed four critical vulnerabilities across its API and identity products. Several are WSO2 account takeover...
The Tails project shipped Tails 7.10.1 as an emergency release on August 5, 2026. This update addresses...
In March of this year, Google introduced “Ask Maps,” a conversational AI, to completely revitalize the navigation...
Since the beginning of 2025, Google has been steadily deploying the Gemini Nano model to Chrome browser...
At a Glance Attribute Detail Actor / group Unattributed threat actor (tracked by Securonix as SMOKE#SCREEN) Activity...
OpenAI filed a motion to drop the Apple lawsuit and stop the ban. In recent court papers,...
For enterprises, operating system stability is paramount, whereas routine feature updates hold a significantly lower priority. Consequently,...
At a Glance Attribute Detail Malware family FDMTP implant (.NET, TouchSocket-based) Threat actor Suspected Twill Typhoon (not...
Recently, the “out-of-control” behavior of artificial intelligence during cybersecurity evaluations has triggered profound alarm across the technology...
At a glance Field Detail Actor Unidentified LATAM threat actor behind the Astaroth/Guildma botnet Activity WhatsApp Web...
Reports of AI-driven agents autonomously discovering vulnerabilities and escaping their evaluation environments have become increasingly frequent –...
TL;DR VulnCheck found a Zbtlink router backdoor in every published firmware build across the product line. Named...
TL;DR Security researcher Hyunwoo Kim (@v4bel) disclosed a KVM escape vulnerability named Zapscape. Tracked as CVE-2026-64561, it...
TL;DR WordPress 7.0.3 is out as a security release. This WordPress security update fixes about a dozen...