The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The threat actors behind the DragonForce ransomware gained access to an unnamed Managed Service Provider's (MSP) SimpleHelp remote monitoring and management (R…
Google on Wednesday disclosed that the Chinese state-sponsored threat actor known as APT41 leveraged a malware called TOUGHPROGRESS that uses Google Calendar f…
Cybersecurity researchers have disclosed a critical unpatched security flaw impacting TI WooCommerce Wishlist plugin for WordPress that could be exploited by u…
Cybersecurity researchers have discovered a security flaw in Microsoft's OneDrive File Picker that, if successfully exploited, could allow websites to access a…
With May Patch Tuesday updates, Microsoft addressed dozens of security vulnerabilities important for customers’ systems.…May Patch Tuesday From Microsoft Fixed…
Zero-day vulnerabilities are a nightmare for any Linux admin, and here's the latest one that demands your attention: CVE-2025-4664 . If you're running Chrome o…
Picture this: you're staring at your trusted Linux system, a network of processes handling everything from file sharing to user requests. It's smooth, reliable…
From zero-day exploits to large-scale bot attacks — the demand for a powerful, self-hosted, and user-friendly web application security solution has never been …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday revealed that Commvault is monitoring cyber threat activity targeting applications…
Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant Duo that could have allowed atta…
A privilege escalation flaw has been demonstrated in Windows Server 2025 that makes it possible for attackers to compromise any user in Active Directory (AD)."…
Tails version 6.15.1 has landed, and this isn't just a routine update''it's an emergency release. If you're working with Tails, this release demands your immed…
Russian cyber threat actors have been attributed to a state-sponsored campaign targeting Western logistics entities and technology companies since 2022.The act…
A threat actor known as Hazy Hawk has been observed hijacking abandoned cloud resources of high-profile organizations, including Amazon S3 buckets and Microsof…
Debian 12.11 isn't a new chapter in the lineup of Debian releases but rather an important update to fine-tune and patch the existing Debian 12 ''Bookworm'' ser…
High-level government institutions in Sri Lanka, Bangladesh, and Pakistan have emerged as the target of a new campaign orchestrated by a threat actor known as …
Cybersecurity researchers are calling attention to a new Linux cryptojacking campaign that's targeting publicly accessible Redis servers.The malicious activity…
Cybersecurity researchers have uncovered malicious packages uploaded to the Python Package Index (PyPI) repository that act as checker tools to validate stolen…
Several ransomware actors are using a malware called Skitnet as part of their post-exploitation efforts to steal sensitive data and establish remote control ov…
Imagine you're sitting down at your desk, coffee in hand, ready to tackle the day, and you're met with this: a new campaign, slyly dubbed ''ClickFix,'' is burr…
Modern apps move fast—faster than most security teams can keep up. As businesses rush to build in the cloud, security often lags behind. Teams scan code in iso…
Red Hat Enterprise Linux got hacked during the Pwn2Own Berlin 2025 competition . Let that sink in for a moment. This is one of the go-to systems for businesses…
Imagine this: you're neck-deep in code, deploying a Python app you've poured hours into. Your dependencies''those trusty libraries''are the silent workhorses i…
Google on Wednesday released updates to address four security issues in its Chrome web browser, including one for which it said there exists an exploit in the …