The notorious Kimsuky threat group is refining its arsenal, shifting toward more complex, multi-stage execution chains to...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
In a major joint advisory released on April 7, 2026, a coalition of U.S. federal agencies—including the...
In its most recent iteration, the instant messaging platform Telegram has granted bots the faculty of inter-bot...
Since last week, users have observed that the 2025 Microsoft Copilot Terms of Service emphasize that the...
According to Microsoft’s announcement in the Microsoft 365 Admin Center (MC1269861), commencing in May 2026, files deleted...
As generative AI technologies proliferate, global anxieties regarding their potential misuse—particularly as instruments for cyber warfare and...
A sophisticated, high-severity social engineering campaign is currently targeting the open source developer community. The attack, which...
OpenSSL has released a comprehensive security advisory detailing seven vulnerabilities ranging from Moderate to Low severity. The...
In a major technical disclosure, the UK National Cyber Security Centre (NCSC) has detailed a sophisticated campaign...
A new Malware-as-a-Service (MaaS) platform is making waves in the cybercrime underground, promising operators an automated pipeline...
Researchers at Socket have identified a massive new cluster of malicious packages linked to North Korea’s notorious...
Security researchers at StepSecurity have sounded the alarm on a compromised version of the @velora-dex/sdk package. On...
A new intelligence report from Proofpoint reveals that TA416, a sophisticated threat actor aligned with Chinese state...
Budibase, the popular open-source low-code platform used by engineers to rapidly build internal tools, has released urgent...
A critical security vulnerability has been unmasked in Kestra, the popular open-source, event-driven orchestration platform. The flaw,...
A critical security vulnerability has been unmasked in Convoy, the modern KVM server management panel used by...
The Electron framework—the powerhouse behind heavyweights like Visual Studio Code and countless other cross-platform desktop applications —has...
In the world of cybercrime, malware is typically designed for one of two things: stealthy espionage or...
A researcher has publicly disclosed a functional zero-day exploit targeting the internal signature update mechanism of Windows...
Cisco Talos has revealed a major automated credential harvesting campaign, tracked as UAT-10608, that has already compromised...