TL;DR A researcher has published a public PoC called ShieldBreak. It bypasses Microsoft’s July patch for the...
Do Son
Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.
TL;DR Google shipped a new Chrome security update on the Stable channel. It fixes five high-severity use-after-free...
What happened at a glance Actor or group Lazarus (DPRK-linked), per Check Point Research Activity type Spear-phishing,...
TL;DR Microsoft August 2026 Patch Tuesday fixes 421 vulnerabilities, with 62 rated critical. One flaw, CVE-2026-68820, is...
TL;DR Zoom released four security bulletins on August 11, 2026. Two of the flaws allow remote code...
TL;DR A Linux kernel CPU timer flaw lets a local user reach root. Tracked as CVE-2026-64560, it...
TL;DR SonicWall disclosed critical flaws in its GMS and Email Security products on August 11, 2026. The...
TL;DR Cisco disclosed a Cisco ASA and FTD VPN vulnerability on August 11, 2026. Tracked as CVE-2026-20349...
TL;DR Progress released an August 2026 bulletin for MarkLogic Server. It fixes ten MarkLogic Server vulnerabilities, several...
TL;DR Researchers published full details and a proof-of-concept tool for CVE-2026-27912, called ResetNightmare. The flaw sits in...
TL;DR SAP released its August 2026 Patch Day on August 11, with 28 new security notes. The...
TL;DR Two Accenture researchers showed that plugging a USB device into Windows can hand an attacker SYSTEM....
At a glance Malware family MaaS infostealer delivered via SmartLoader (NodeJS strain among final payloads) Threat actor...
At a Glance Attribute Detail Malware family DOUBLECUP (Loader-as-a-Service); payloads CountLoader 4.5p and DeviceManager RAT Threat actor...
TL;DR Three critical Wazuh manager vulnerabilities now have public advisories and proof-of-concept exploit code. Each scores CVSS...
TL;DR A critical flaw lets a low-privileged Rancher user seize full control of the platform. Tracked as...
TL;DR Red Hat disclosed a critical privilege escalation flaw in Advanced Cluster Management (ACM) for Kubernetes. Tracked...
TL;DR A high-severity authentication bypass affects the Neo4j GraphQL Library before versions 7.5.6 and 5.12.14. Tracked as...
TL;DR A Linux kernel eventpoll flaw lets a local user climb to root. Tracked as CVE-2026-43074, it...
At a Glance Attribute Detail Malware family Interlock ransomware (double extortion) Threat actor Interlock, tracked by Sophos...
At a glance Actor or group Operators of the Greatness kit, also tracked as HoneyStorm Activity type...
Security teams tracked 1,877 new vulnerabilities between August 3 and August 9, 2026. This weekly CVE report,...