Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
LightLLM Profiling Flaw Allows Code Execution Without a Login

LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Command Injection Flaw in shell-quote Can Execute Linux Commands

The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux File Truncation Patch Targets Data Loss Beyond the Requested Range

A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Tracing Patch Addresses a Probe Use-After-Free Race

A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.

Linux

The Hacker News
The Hacker News Breaches & leaks
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers

Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.

GitLab

The Hacker News
The Hacker News Vulnerabilities
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…

The Hacker News
The Hacker News Vulnerabilities
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the e…

The Hacker News
The Hacker News Vulnerabilities
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is th…

Citrix

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Patch Management For Enterprises: A Complete Guide

Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own …

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Kubernetes Security Fix Blocks Cross-Namespace Pod Creation

Kubernetes released fixes on Sep 23, 2026 for a control-plane flaw that could create a pod outside the namespace where a user's permissions applied. CVE-2026-2…

Kubernetes

The Hacker News
The Hacker News Vulnerabilities
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new gl…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
MCP Toolbox Flaw Could Expose Google Service Tokens

A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Emacs Security Flaw Could Run Code From an Untrusted File

A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
GitHub Enterprise Server Flaw Could Let Attackers Run Code

A GitHub Enterprise Server security fix addresses a way to turn the appliance's notebook viewer into a route to its own internal services.

GitHub

The Hacker News
The Hacker News Vulnerabilities
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through…

Windows Chrome

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
How Container Restore Can Reopen Privilege Escalation Paths

Privilege escalation in a container does not always begin with a new exploit.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CRI-O Restore Flaw Can Bypass Kubernetes Security Policies

Kubernetes groups one or more containers into a pod, the basic unit it deploys.

Docker Kubernetes

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Fix SELinux Overlays Important Security Contexts 401610

Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.

Linux

The Hacker News
The Hacker News Vulnerabilities
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Security Roundup: Patch BIND, Browsers, and Cloud Kernels First

Most administrators do not think about BIND, browser engines, or cloud kernels until one of them fails.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux eBPF Security Flaw Could Approve an Out-of-Bounds Memory Access

A Linux eBPF security flaw could cause the kernel to approve a program using an incorrect understanding of the values it would process.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws

Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with auto…

Linux