Apple has removed two strategically important Russian apps from its App Store. The two apps are VKontakte,...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
The European Commission has rendered a preliminary determination, designating Amazon Web Services (AWS) and Microsoft Azure as...
Security researcher Massimiliano Oldani has published IPV6_FRAG_ESCAPE, a working proof-of-concept for an IPv6 container escape on CentOS...
At a glance Field Detail Malware family SharkLoader (loader) delivering Cobalt Strike Beacon Threat actor StrikeShark; unattributed,...
TL;DR Synacktiv publicly disclosed a new NTLM reflection bypass tracked as CVE-2026-24294. The flaw gives a local...
At a glance Malware Family: macOS.Gaslight Threat Actor: High confidence DPRK-aligned (North Korea) Target or Victims: macOS...
At a glance Actor: Suspected unknown threat cluster (tracked by Seqrite Lab) Activity Type: Spear-phishing, credential theft,...
At a Glance Malware family Edgecution (malicious Microsoft Edge extension plus a Python backdoor) Threat actor Initial...
The rapid development of generative artificial intelligence currently faces an unprecedented physical barrier. Specifically, a severe computing...
Google has just rolled out a genuinely useful addition to Google Wallet: package tracking. Thanks to deep...
TL;DR Attackers are exploiting a Cisco Unified CM RCE flaw in live attacks. Tracked as CVE-2026-20230, it...
TL;DR This weekly CVE report covers 1,909 new vulnerabilities published between June 22 and 28, 2026. Critical...
TL;DR Dell released urgent security updates for its thin client management platform. Two critical Dell Wyse vulnerabilities...
A critical Gemini CLI vulnerability (CVE-2026-12537) exposes developer workflows to maximum severity attacks. Google disclosed this CVSS...
A critical Hoppscotch mass assignment vulnerability threatens self-hosted API deployments. The flaw, tracked as CVE-2026-50160, allows unauthenticated...
TL;DR DirtyClone is a Linux kernel privilege escalation flaw tracked as CVE-2026-43503. It scores 8.8 on the...
The evolution of generative AI technology is now officially intertwined with geopolitics and national security. Previewing GPT-5.6...
Anthropic recently suffered a complete network blackout under a stringent United States government ban. Fortunately, their formidable...
TL;DR Researchers publicly disclosed a libssh2 vulnerability tracked as CVE-2026-58050. The flaw lets a malicious SSH server...
TL;DR Security experts disclosed a high-severity flaw (CVE-2026-11940) in Python. A critical CPython tarfile vulnerability allows directory...
At a Glance Actor or Group: Unnamed digital piracy networks Activity Type: Copyright infringement Targets or Victims:...
At a Glance Actor / group UNC5792 (linked to FSB Border Guards); UNC4221 (Russian military) Activity Phishing...