Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS SSL VPN in the wild under certain configurations.The vulnerab…

Fortinet VPN

The Hacker News
The Hacker News Vulnerabilities
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Kno…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISSP: Bridging Linux Security and Organizational Compliance Needs

Linux security professionals spend most of their time on concrete problems. Hardening SSH. Configuring SELinux or AppArmor. Building secure CI/CD pipelines. Ma…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
SNMP: CACTI Command Execution Risk Advisory for Linux Administrators

A recent command-execution flaw in the CACTI monitoring framework underscores a broader risk that keeps repeating. SNMP is routinely treated as passive plumbin…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
When Monitoring Turns Risky: SNMP Exposure in Linux Infrastructure

A recent command-execution flaw in the CACTI monitoring framework underscores a broader risk that keeps repeating. SNMP is routinely treated as passive plumbin…

Linux

The Hacker News
The Hacker News Vulnerabilities
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

WatchGuard has released fixes to address a critical security flaw in Fireware OS that it said has been exploited in real-world attacks.Tracked as CVE-2025-1473…

VPN

The Hacker News
The Hacker News Breaches & leaks
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances

Cisco has alerted users to a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent thr…

Cisco

The Hacker News
The Hacker News Breaches & leaks
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

Threat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public disclosure.Cybersecurity co…

Fortinet

The Hacker News
The Hacker News Vulnerabilities
React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

The security vulnerability known as React2Shell is being exploited by threat actors to deliver malware families like KSwapDoor and ZnDoor, according to finding…

Linux Palo Alto

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
React2Shell RCE: Critical Host Compromise Vulnerability Exploit 2025-55182

React2Shell is a server-side vulnerability that turns a normal web request into code execution. It allows unauthenticated remote code execution, without creden…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
React2Shell: How a Framework Bug Drives Full Linux Compromise

React2Shell is a server-side vulnerability that turns a normal web request into code execution. It allows unauthenticated remote code execution, without creden…

Linux

The Hacker News
The Hacker News Vulnerabilities
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that it sai…

Apple Chrome

The Hacker News
The Hacker News Vulnerabilities
New React RSC Vulnerabilities Enable DoS and Source Code Exposure

The React team has released fixes for two new types of flaws in React Server Components (RSC) that, if successfully exploited, could result in denial-of-servic…

The Hacker News
The Hacker News Vulnerabilities
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliv…

Linux

The Hacker News
The Hacker News Vulnerabilities
Webinar: How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes

Cloud security is changing. Attackers are no longer just breaking down the door; they are finding unlocked windows in your configurations, your identities, and…

Windows AWS Palo Alto

The Hacker News
The Hacker News Vulnerabilities
Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a security flaw impacting the WinRAR file archiver and compression utility to…

The Hacker News
The Hacker News Vulnerabilities
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two Zero-Days

Microsoft closed out 2025 with patches for 56 security flaws in various products across the Windows platform, including one vulnerability that has been activel…

Windows

The Hacker News
The Hacker News Vulnerabilities
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware

Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical React2Shell security flaw in React Server Compo…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
AIs Quiet Move Into the Linux Kernel Raises New Linux Kernel Security Questions

AI-written patches are starting to land in kernel discussions, and the timing has people watching closely. The code looks ordinary at first glance, yet the rev…

Linux

The Hacker News
The Hacker News Breaches & leaks
⚡ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More

It’s been a week of chaos in code and calm in headlines. A bug that broke the internet’s favorite framework, hackers chasing AI tools, fake apps stealing cash,…

The Hacker News
The Hacker News Vulnerabilities
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year?

The holiday season compresses risk into a short, high-stakes window. Systems run hot, teams run lean, and attackers time automated campaigns to get maximum ret…

The Hacker News
The Hacker News Vulnerabilities
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it beco…

The Hacker News
The Hacker News Vulnerabilities
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories

Think your Wi-Fi is safe? Your coding tools? Or even your favorite financial apps? This week proves again how hackers, companies, and governments are all locke…

The Hacker News
The Hacker News Vulnerabilities
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts

A critical security flaw impacting a WordPress plugin known as King Addons for Elementor has come under active exploitation in the wild.The vulnerability, CVE-…

WordPress