The eSentire Threat Response Unit (TRU) has uncovered a new malware campaign leveraging a tool called MintsLoader...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
The U.S. Department of State has announced sanctions against two Chinese entities, Yin Kecheng and Sichuan Juxinhe...
A sophisticated cyber-espionage campaign targeting organizations across China, Hong Kong, and Taiwan has been uncovered by Intezer’s...
Microsoft recently unveiled a new experimental feature for participants in the Windows 11 Insider Program, enabling users...
Oracle has released its Critical Patch Update Pre-Release Announcement for January 2025, providing advance notice of the...
The behavior of ChatGPT’s web crawler can be exploited through a discovered vulnerability: under specific query conditions,...
OpenAI CEO Sam Altman has revealed plans to launch the o3-mini artificial intelligence model within the coming...
After ByteDance voluntarily ceased TikTok’s operations within the United States, it issued a statement within less than...
Security researcher MrAle_98 recently published a proof-of-concept (PoC) exploit for a zero-day vulnerability, CVE-2024-49138. This flaw, which...
Microsoft Threat Intelligence has uncovered a new spear-phishing campaign orchestrated by the Russian threat actor known as...
9.0 CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection
9.0 CVE-2025-2306 (CVSS 9.0): Mongoose Flaw Leaves Millions of Downloads Exposed to Search Injection
A newly discovered vulnerability in Mongoose, a popular MongoDB object modeling tool, could leave millions of users...
The Socket research team has identified a malicious Python package on PyPI named pycord-self, targeting developers working...
SEKOIA’s Threat Detection & Research (TDR) team has exposed a new Adversary-in-the-Middle (AiTM) phishing kit, dubbed “Sneaky...
NVISO Labs has uncovered a sophisticated phishing campaign attributed to the ransomware group Black Basta, leveraging Microsoft...
BlackBerry’s QNX Software Development Platform (SDP), a widely used real-time operating system in safety-critical industries, is the...
Truth Social, the social media platform launched by Trump Media & Technology Group in 2022, has become...
A newly discovered IoT botnet has been linked to a series of large-scale distributed denial-of-service (DDoS) attacks...
As the digital revolution advances, so do cyber threats to new levels. As companies adopt new digital...
Moxa has issued a security advisory detailing CVE-2024-12297 (CVSS 9.2), a critical vulnerability in its EDS-508A Series...
North Korea’s notorious Lazarus APT group has been observed employing advanced social engineering tactics in a campaign...