Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Breaches & leaks
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Pytho…

The Hacker News
The Hacker News
Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order

Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group.In addition, the tech giant said it's filing a f…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
IronWorm Supply Chain Threat from Linux Credential Theft

IronWorm steals credentials and uses them to spread beyond the original victim, turning developer access into a supply chain risk.

Linux

The Hacker News
The Hacker News
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign.The incident impacted…

Azure GitHub

The Hacker News
The Hacker News Breaches & leaks
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff.Recent re…

The Hacker News
The Hacker News Breaches & leaks
PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SM…

Azure AWS Google Cloud

The Hacker News
The Hacker News Vulnerabilities
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with noth…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
HTTP/2 Bomb: Why Linux Infrastructure is Vulnerable to a New Low-Bandwidth DoS Attack

A newly disclosed attack technique called HTTP/2 Bomb is drawing attention because it targets the software that sits at the front of much of the Linux internet…

Linux Apache Nginx

The Hacker News
The Hacker News
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell.Ac…

Palo Alto Apple

The Hacker News
The Hacker News
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traff…

The Hacker News
The Hacker News
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token."J…

GitHub

The Hacker News
The Hacker News
Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth Tokens

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token."J…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Compromised VS Code Extension Puts Linux Development Pipelines at Risk

The compromise of Nx Console shows how much infrastructure now sits behind a single developer account. GitHub repositories, CI/CD pipelines, container build sy…

Linux Docker Kubernetes

The Hacker News
The Hacker News
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

The Fragmented State of Modern Enterprise IdentityEnterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmen…

The Hacker News
The Hacker News Vulnerabilities
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker.Like in the cas…

Windows

The Hacker News
The Hacker News Vulnerabilities
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envo…

Apache Nginx

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Linux Persistence Hunting: The 5 Techniques Security Teams Miss Most

You remove the malware. You rotate the compromised credentials. You patch the original vulnerability and close the ticket. Two weeks later, the attacker is bac…

Linux

The Hacker News
The Hacker News Vulnerabilities
AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponi…

The Hacker News
The Hacker News
Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-fo…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Why Linux Rootkits Still Matter in Cloud and VMware Environments

Linux rootkits are old, but they never really disappeared. They just stopped attracting the same attention.

Linux VMware

The Hacker News
The Hacker News Breaches & leaks
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from dev…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Essential Cybersecurity Practices for Businesses to Protect Data

In this increasingly digital era, every business, no matter the size, has to be vigilant about its cybersecurity. Data breaches have become rampant over the pa…

The Hacker News
The Hacker News Alerts
The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the wor…

The Hacker News
The Hacker News Breaches & leaks
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-l…

GitHub Android