TL;DR FreeRDP 3.31.0 patches five server-role flaws reported by Bynario, plus 17 other issues. Researchers chained three...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
Developer JPRX recently released the open-source Darwin-VM project, a modified QEMU virtualization scheme that boots genuine iOS...
The trade secret lawsuit between Apple and OpenAI recently escalated. According to a recent Reuters report, Apple...
TL;DR Hewlett Packard Enterprise disclosed dozens of critical HPE Fabric Composer vulnerabilities. These flaws allow unauthenticated attackers...
TL;DR SonicWall published advisory SNWLID-2026-0016 on September 1, 2026. It confirms active exploitation of two SMA1000 flaws....
TL;DR Proxmox published advisory PSA-2026-00043-1 on September 1, 2026. It warns of a critical Proxmox VE authentication...
TL;DR Honeypot sensors recorded thousands of unauthorized requests targeting a severe LiteLLM vulnerability tracked as CVE-2026-35029. This...
Google had previously announced that it would remove all extensions built on the Manifest V2 protocol from...
The veteran VPS server management panel Virtualizor has confirmed a serious supply-chain attack. Between 28 and 30...
Anthropic recently published a detailed blog post outlining their security remediation plans. These plans follow several alarming...
TL;DR Attackers are exploiting CVE-2026-9586 in the wild. This critical Sangoma Switchvox vulnerability turns an unauthenticated SQL...
TL;DR A critical Redis vulnerability, tracked as CVE-2026-81934, allows remote code execution on TLS-enabled servers. It carries...
At a Glance Malware Family: Miraak Threat Actor: Unknown (Discovered via adversary operational security failure) Targets: Broad...
TL;DR CERT@VDE published full details of CVE-2026-78319 on September 1, 2026. This SAUTER building controller vulnerability lets...
At a Glance Category Details Threat Actor Dark Caracal (suspected connection to Lebanese GDGS) Activity Type Cyberespionage,...
TL;DR A critical Artifactory authentication bypass vulnerability allows unauthenticated threat actors to obtain administrative privileges. Security researchers...
At a Glance Actor/Group Unattributed cluster; low-confidence overlap with SilverFox-associated activity Activity Multi-stage malware campaign delivering SparkRAT...
At a Glance Actor or group: BREEZE COMET (formerly UNC5669, Plump Spider, SHADOW-AETHER-064) Activity type: Banking fraud,...
Research organizations METR and Redwood Research recently published a detailed, independent investigation. This investigation meticulously examined the...
The Codex project recently merged multiple changes. These updates indicate that Codex is redesigning the context mechanism....
A single, devastating error within the balance accounting mechanism of Cosmos EVM directly precipitated a coordinated series...
The infamous NightmareEclipse public vulnerability series recently expanded its scope significantly. It rapidly transcended its initial Windows...