TL;DR Apache APISIX 3.16.0 shipped a JWT algorithm confusion bug in its jwt-auth plugin. The flaw, tracked...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
Recently, Anthropic reintroduced the Claude Fable 5 model. However, this iteration offers a brief complimentary window for...
Google’s virtual network operator service recently introduced two premium Google Voice personal paid plans tailored for United...
Cybersecurity firm Nebula recently unveiled a demonstration video exposing a critical kernel-level vulnerability and remote privilege escalation...
Elon Musk confirmed the upcoming arrival of the flagship Grok 4.5 model. Previously, this artificial intelligence system...
Consequently, OpenAI has officially unveiled the exquisite GPT-5.6 series. This new cohort includes models code-named Sol, Terra,...
At a glance Details Activity type Phantom squatting: registering AI hallucinated domains for phishing and malware Actors...
At a Glance Malware type Native Messaging backdoor with a malicious Chrome extension Threat actor Unattributed Targets...
The open-source operating system Ubuntu typically releases Long Term Support (LTS) and non-LTS versions at regular intervals....
The Biden administration originally instituted the Broadband Consumer Labels directive. They designed this framework to help citizens...
Malware family PureLog Stealer (delivered by the Veil#Drop framework) Threat actor Not attributed by Securonix Targets Windows...
Hundreds of WordPress sites remain easy targets year after year. The cause is rarely a rare zero-day...
TL;DR Researchers have published full details and proof-of-concept code for GhostLock. This Linux kernel bug, tracked as...
TL;DR The CISA KEV Catalog just gained four actively exploited flaws. Three of them carry a top...
TL;DR BMC disclosed a critical flaw in Control-M/Server tracked as CVE-2026-10539. The Control-M command injection bug scores...
TL;DR Researchers have published full technical details and proof-of-concept code for a SharePoint remote code execution flaw....
Ubiquiti released a UniFi security advisory, Bulletin 066. It fixes 25 flaws in UniFi products. One bug...
While quietly altering its artificial intelligence training data collection policies, Google has once again adjusted its cloud...
Five months after Elon Musk amalgamated his artificial intelligence and space enterprises, xAI formally announced its rebranding...
At a glance Details Actor or group ARToken operators; assessed as an EvilTokens affiliate panel Activity type...
TL;DR IBM disclosed a critical CVSS 9.8 flaw, tracked as CVE-2026-12943, in its Power Hardware Management Console...
At a Glance Malware family RustDuck Threat actor Unattributed Targets / victims IoT devices, web apps, and...