The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request. Here is how the attack works and how …
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC."The Drup…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, SQL injection…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, SQL injection…
The North Korea-linked persistent campaign known as Contagious Interview has spread its tentacles by publishing malicious packages targeting the Go, Rust, and …
Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS…
It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in server side request forgery or …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, ci…
Release 1.6.12 Support IPv6 in database DSN (#9937) Don't force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove …
Release 1.6.12 Support IPv6 in database DSN (#9937) Don't force specific error_reporting setting Fix compatibility with PHP 8.5 regarding array_first() Remove …
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service or memory disc…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service or server side…
This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: Fix Post-Auth RCE vi…
Alright, Linux admins and security pros, let's talk WordPress . I know''typically, "WordPress" doesn't top the list of thrilling topics in our corner of the te…
Kirill Firsov discovered that Roundcube, a skinnable AJAX based webmail solution for IMAP servers, was performing PHP Object deserialization on unvalidated inp…
Multiple security issues were discovered in TCPDF, a PHP class for generating PDF files on-the-fly, which may result in denial of service, cross-site scripting…
Security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lead to vali…
SQL injection in the PostgreSQL driver has been fixed in the ADOdb database access library for PHP. For Debian 11 bullseye, this problem has been fixed in vers…
Cybersecurity researchers have shed light on a new campaign targeting WordPress sites that disguises the malware as a security plugin.The plugin, which goes by…
Keeping WordPress secure can be challenging, especially when considering Linux security concerns in a typical LAMP stack setup. Most WordPress security issues …
A security vulnerability was discovered in Smarty, a template engine for PHP, which could result in PHP code injection. For the stable distribution (bookworm),…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorizatio…
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in denial of service, CLRF injectio…