Six Apart Ltd. has issued an urgent security advisory for Movable Type, a long-standing content management system...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
Welcome to this week’s vulnerability digest. As we close out the first full week of April, security...
The Lat61 Threat Intelligence Team has pulled back the curtain on DesckVB RAT, a highly active and...
Apache Tomcat, the open-source backbone for millions of Java-based web applications, has been hit by a wave...
In a sophisticated campaign codenamed FrostArmada, the threat research team at Black Lotus Labs (Lumen Technologies) has...
A critical security vulnerability in Axios, the ubiquitous promise-based HTTP client for Node.js and the browser, has...
Credential leaks have shifted from isolated security events to a continuous operational risk that organizations must actively...
A severe security vulnerability has been identified in the Nix package manager, a tool celebrated by the...
A critical-severity security vulnerability has been identified in the Checkmk monitoring platform, potentially allowing local users to...
In a sophisticated shift in tactics, cybercriminals are increasingly weaponizing the trusted notification pipelines of major collaboration...
Microsoft Defender Security Research has uncovered a sophisticated, wide-scale phishing campaign that weaponizes the Device Code Authentication...
Netskope Threat Labs has uncovered a sophisticated new ClickFix campaign targeting Windows users with a high-quality, custom-built...
North Korea’s cyber program has moved past the era of accidental growth into a period of “mature...
HPE Aruba Networking has issued an important software update to address a high-severity security flaw in its...
In a calculated move that signals a new frontier in cyber espionage, North Korean threat actors have...
TP-Link has issued an urgent security advisory regarding its Archer AX53 v1.0 router, detailing five distinct vulnerabilities...
A sophisticated, financially motivated threat campaign is currently sweeping across professional networks, specifically targeting job seekers on...
Amazon Web Services (AWS) has released urgent security updates for its Research and Engineering Studio (RES), an...
Security researchers have unmasked three critical vulnerabilities in goshs, a popular high-performance replacement for Python’s SimpleHTTPServer. The...
In a critical security alert, Juniper Networks has warned of a severe vulnerability in its Support Insights...
Everest Forms, a popular WordPress plugin trusted by over 100,000 websites for building everything from simple contact...
Vite has become the “speed demon” of modern frontend development, prized for its lightning-fast Hot Module Replacement...