The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that al…
A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remot…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA…
Threat actors have been observed uploading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node that have racked up thousa…
In recent months, Linux security administrators and WordPress site owners have encountered a formidable adversary: MUT-1244 . This threat actor has been unleas…
Attention Linux administrators and Python developers! A crucial security alert regarding a high-severity vulnerability, CVE-2024-12254 , has just been issued, …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 25-01, ordering federal civilian agencies to se…
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed that a threat actor it tracks as UAC-0125 is leveraging Cloudflare Workers service to t…
We Linux security admins have a new challenge on our hands: it was recently discovered that Qualcomm Snapdragon X Plus and Elite processors - found in laptops,…
Keeping WordPress secure can be challenging, especially when considering Linux security concerns in a typical LAMP stack setup. Most WordPress security issues …
If you're an admin responsible for managing and securing one or more Linux systems, you already know the importance of having top-notch tools at your disposal.…
BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to…
Did you know that 43.1% of websites on the Internet run on WordPress, according to W3Techs? Most WordPress websites run on Linux servers, which makes them prim…
A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate."An attacker used soci…
Wordfence security researchers recently shed light on an infamous supply chain attack that may have affected as many as 36,000 WordPress websites. Five widely …
We Linux security admins have a new challenge on our hands: several Qualcomm processors/SoCs are still vulnerable to Spectre-related attacks . Despite its prom…
Streaming on Linux can be an exhilarating experience, but it also comes with its own set of cybersecurity challenges. The risks are real, from DDoS attacks tha…
A suspected South Asian cyber espionage threat group known as Bitter targeted a Turkish defense sector organization in November 2024 to deliver two C++-malware…
Addressing cyber threats before they have a chance to strike or inflict serious damage is by far the best security approach any company can embrace. Achieving …
Bogus software update lures are being used by threat actors to deliver a new stealer malware called CoinLurker."Written in Go, CoinLurker employs cutting-edge …
A little-known cyber espionage actor known as The Mask has been linked to a new set of attacks targeting an unnamed organization in Latin America twice in 2019…
As attackers threaten key utility facilities, CISA warns water and waste facilities to protect online…Water Facilities Must Secure Exposed HMIs – Warns CISA on…
This month marked the release of Microsoft’s last scheduled updates. With the December 2024 Patch…Microsoft December Patch Tuesday Arrived With 70+ Bug Fixes o…
We Linux security admins have a new challenge on our hands: several Qualcomm processors/SoCs are still vulnerable to Spectre-related attacks . Despite its prom…