First spotted in 2022 and actively developed ever since, DarkCloud Stealer has reemerged with a sophisticated new...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
Apache IoTDB, a system designed for managing industrial IoT time-series data, faces a series of security vulnerabilities...
Fortinet has released patches for a critical vulnerability (CVE-2025-22252, CVSS 9.0) affecting multiple products, including FortiOS, FortiProxy,...
A sophisticated ransomware campaign targeting National Defense Corporation (NDC) and its subsidiaries affected the defense supply chain,...
Security researchers at ETH Zürich have unveiled a novel speculative execution attack—Branch Privilege Injection (CVE-2024-45332)—that subverts Intel’s...
Malware authors have begun exploiting Google Calendar invites and Unicode Private Use Area (PUA) characters to deliver...
A pair of critical-severity vulnerabilities in the OpenPubkey authentication protocol and its companion tool, OPKSSH, could allow...
On May 12, 2025, Xerox published Security Bulletin XRX25-009, announcing the release of its April 2025 Security...
The ReversingLabs research team has uncovered yet another software supply chain attack targeting the cryptocurrency ecosystem, this...
Microsoft recently announced a strategic organizational restructuring, which will result in a workforce reduction of approximately 3%,...
Before the official commencement of Google I/O 2025, Google unveiled several upcoming innovations through “The Android Show:...
The Australian Human Rights Commission (AHRC) has disclosed a significant data breach involving the unintended public exposure...
A sophisticated phishing campaign has exploited compromised Indiana state government accounts to distribute fraudulent toll collection messages...
Siemens has released a critical security advisory (SSA-047424) addressing two severe vulnerabilities—CVE-2025-26389 and CVE-2025-26390—affecting its OZW672 and...
Ivanti has released a critical security patch for its on-premises Neurons for ITSM platform, addressing a severe...
Varnish Software has disclosed a client-side desynchronization vulnerability, tracked as CVE-2025-47905, in both Varnish Cache and Varnish...
Zoom has released a security bulletin addressing multiple vulnerabilities across its Workplace Apps suite. The bulletin details...
A critical security vulnerability has been identified in the Bitnami Pgpool-II Docker image and the bitnami/postgres-ha Kubernetes...
In a recently disclosed campaign, TA406, a North Korean state-aligned threat actor, has expanded its cyber-espionage efforts...
Siemens ProductCERT released an urgent security advisory (SSA-301229) detailing multiple command injection vulnerabilities in its RUGGEDCOM ROX...
In the ever-expanding ecosystem of information stealers, a new and unusually sophisticated malware has entered the scene:...
rend Micro researchers have uncovered the full extent of an elaborate, multi-phase cyber-espionage operation attributed to Earth...