The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that pr…
The North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing …
Linux security usually comes down to access controls and permissions, but those controls only work if the platform enforcing them holds up. What happens when t…
AI coding tools have allowed engineering teams to double their output, and 64% of organizations…AI Coding Agents Are Redefining Cyber Risk — Is Your Exposure S…
The China-based cybercrime group known as Silver Fox (aka Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne) has been linked to a new…
A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed servic…
Most Linux hardening work stays focused on access. Flip on a control, lock things down, move on. Doesn't mean you're actually covered.
Most Linux hardening focuses on access. This vulnerability bypasses that entirely.
The managed security services market is projected to grow from $38.31 billion in 2025 to $69.16 billion by 2030[1], with cybersecurity being the fastest-growin…
The U.S. Department of Justice (DoJ) on Thursday announced the sentencing of two cybersecurity professionals to four years each in prison for their role in fac…
In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to co…
Most information security best practices are built on a single, comfortable assumption: that we have control over what software is running on our hardware, and…
Cybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR that comes with capabilities to establish persi…
Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root.Th…
Most information security best practices are built on a single, comfortable assumption: that if we find a bug, we can patch it, and once it's patched, the syst…
Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware.A…
Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic's Claude Opus …
cPanel has released security updates to address a security issue impacting various authentication paths that could allow an attacker to obtain access to the co…
Think about Linux security like the structural integrity of a building. Most information security best practices focus on the front door''locks, cameras, and I…
Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its encryption…
A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited to the U.S. from Italy. Xu Zewei, 34, was arrested in July 2…
Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data relate…
Most information security best practices are built on a single, comfortable assumption: that the "root" gate is locked and only the administrator holds the key…
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help …