The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
SonicWall SSL VPN devices have become the target of Akira ransomware attacks as part of a newfound surge in activity observed in late July 2025."In the intrusi…
If you're running servers, maintaining web apps, or just spending a lot of time thinking about the integrity of systems, cross-site scripting (or XSS) probably…
Cybersecurity researchers have flagged a malicious npm package that was generated using artificial intelligence (AI) and concealed a cryptocurrency wallet drai…
The days of straightforward Linux security threats''malware you could spot with a cursory glance at the logs''are fading fast. Meet "Koske," a new breed of mal…
The threat actor linked to the exploitation of the recently disclosed security flaws in Microsoft SharePoint Server is using a bespoke command-and-control (C2)…
Imagine this: you're midway through deploying critical patches on your Linux servers when you notice something strange. Traffic to one of your services spikes …
If you're an admin managing Linux machines, you've got a couple of things on your radar right now. One is CVE-2025-31324, a vulnerability that's got the potent…
Apple on Tuesday released security updates for its entire software portfolio, including a fix for a vulnerability that Google said was exploited as a zero-day …
Threat actors have been observed exploiting a now-patched critical SAP NetWeaver flaw to deliver the Auto-Color backdoor in an attack targeting a U.S.-based ch…
Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:Compromise an endpoint via softw…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperCutNG/MF print managemen…
The notorious cybercrime group known as Scattered Spider is targeting VMware ESXi hypervisors in attacks targeting retail, airline, and transportation sectors …
The threat actor known as Patchwork has been attributed to a new spear-phishing campaign targeting Turkish defense contractors with the goal of gathering strat…
Threat hunters have disclosed two different malware campaigns that have targeted vulnerabilities and misconfigurations across cloud environments to deliver cry…
Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws is deploying Warlock ransomware on targeted systems.The…
The Windows banking trojan known as Coyote has become the first known malware strain to exploit the Windows accessibility framework called UI Automation (UIA) …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two security flaws impacting SysAid IT support software to its Known Exploited Vulnerabi…
Let's talk straight: if you're running Apache HTTP Server and you haven't checked your version in a while, you might have a problem. An issue that's now pretty…
Google recently addressed a serious zero-day vulnerability in its Chrome browser that allowed sandbox escape.…Google Patched A Chrome Zero-Day That Allowed San…
Microsoft on Sunday released security patches for an actively exploited security flaw in SharePoint and also disclosed details of another vulnerability that it…
Let's face it: threat actors are getting smarter, and malware isn't just for your typical Windows clickbait anymore. In recent years, the H2Miner botnet has go…
Let's face it: threat actors are getting smarter, and malware isn't just for your typical Windows clickbait anymore. In recent years, the H2Miner botnet has go…
Cybersecurity researchers have disclosed a critical container escape vulnerability in the NVIDIA Container Toolkit that could pose a severe threat to managed A…
Let's talk about CVE-2025-6558 ''the latest zero-day vulnerability in Google Chrome. If you're managing Linux systems or handling infosec at any level, you sho…