A critical security vulnerability, tracked as CVE-2024-58136 (CVSS 9.1), has been uncovered in the popular PHP web...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
The APT group GOFFEE has resurfaced with a revamped arsenal, launching targeted cyberattacks across Russia’s strategic sectors....
In a recent cybersecurity analysis, ClearSky’s team uncovered a persistent influence campaign originating from Yemen/Houthi, targeting Israel...
Perl, a versatile programming language widely used for various tasks like system administration and web development, has...
In a decisive move to protect U.S. national security and personal data from foreign threats, the U.S....
The cybersecurity landscape has witnessed significant activity over the past week (April 7th – April 13th), with...
A newly disclosed vulnerability, CVE-2025-32896, in Apache SeaTunnel—a widely used distributed data integration platform—could allow unauthenticated attackers...
In a world where images are meant to inform or entertain, a new breed of phishing attack...
A recent report by Trend Research has uncovered that NVIDIA’s September 2024 security update for a critical...
AhnLab Security intelligence Center (ASEC) has revealed a cyberattack campaign where Arabic-speaking attackers are distributing ViperSoftX malware,...
A critical security vulnerability has been discovered in the Everest Forms WordPress plugin, putting over 100,000 websites...
A recent report by Cofense Intelligence reveals a game-changing phishing technique called Precision-Validated Phishing—a surgical approach to...
Spammers are constantly adapting their tactics to exploit new digital communication channels. A recent report by SentinelLABS...
A newly discovered vulnerability in Langflow, a popular tool for building agentic AI workflows, poses a significant...
A severe security vulnerability has been identified in the InstaWP Connect WordPress plugin, posing a significant risk...
OpenAI CEO Sam Altman recently announced via his personal X account the introduction of the “Memory” feature...
Researchers at Rapid7 published technical details and proof-of-concept exploit code for a critical zero-day vulnerability in Ivanti...
In the ever-evolving world of DevOps automation, Jenkins is a cornerstone tool powering countless build pipelines across...
In a technical deep-dive, IBM’s X-Force Red has revealed a stealthy new lateral movement and credential access...
Yesterday, we reported that the April 2025 cumulative security update KB5002700 for Microsoft Office 2016 has triggered...