TL;DR Google shipped a Chrome security update for the stable desktop channel. It fixes 41 vulnerabilities in...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
TL;DR Cisco disclosed two Cisco IMC vulnerabilities in the web-based management interface. The more serious one, CVE-2026-20200,...
At a glance Actor Connor Riley Moucka, 26, of Kitchener, Ontario Activity type Cloud account intrusion, data...
Most organizations discover the gaps in their DDoS defenses at the worst possible moment: during an actual...
TL;DR: Phoenix Contact CHARX vulnerabilities now number 20 across the SEC-3xxx EV charging controllers. Several rate critical,...
At a glance Actor Chinese-speaking operator (suspected, moderate confidence); one of 7-8 unrelated groups using the leaked...
TL;DR Apple has patched a serious macOS kernel vulnerability tracked as CVE-2026-39868. An unprivileged app can corrupt...
At a glance Malware family Powercat (Java-based stealer and RAT) Threat actor Not attributed to a named...
At a glance Malware family XCSSET (version 40) Threat actor Unattributed; tracked by Unit 42 since 2020,...
At a glance Actor or group Storm-2945, assessed as an operational sub-cluster of Midnight Blizzard Activity type...
Autonomous Agents Exchange Covert Intelligence Under standard testing protocols, human engineering teams deployed and evaluated distinct AI...
Google Assistant, the ubiquitous voice companion that has faithfully served Android users for nearly a decade, is...
Ransomware Intrusion Erases User Data When utilizing Virtual Private Server (VPS) infrastructure, performing routine data backups remains...
Understanding iCloud Private Relay Limits Apple includes iCloud Private Relay as a privacy feature within its paid...
Renowned virtualization platform Proxmox VE has officially launched its Arm64 edition, marking the first instance of PVE...
TL;DR CISA added the TeamCity vulnerability CVE-2026-63077 to its Known Exploited Vulnerabilities catalog. The flaw allows unauthenticated...
TL;DR Jenkins patched a critical Jenkins vulnerability, CVE-2026-70426, that bypasses the JEP-200 deserialization filter. Attackers with Agent/Connect...
TL;DR Cisco patched five Cisco SD-WAN vulnerability issues in Catalyst SD-WAN Software. Three are Critical, with two...
TL;DR A researcher found six SGLang vulnerabilities, and the worst allow unauthenticated remote code execution. SGLang serves...
TL;DR: TP-Link patched a TP-Link command injection flaw in the Archer AXE75 V1 router. Tracked as CVE-2026-9044,...
TL;DR IBM has disclosed three critical vulnerabilities across three products, each rated CVSS 9.8. The flaws affect...
TL;DR Security researchers have detailed a critical Linux suTrap local privilege escalation flaw. This interactive su TIOCSTI...