הישאר מעודכן

חדשות סייבר

ראשי / חדשות

חיפושים מהירים: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

מה זה אומר עבור השרתים שלכם

חדשות האבטחה החשובות, בהסבר הצוות שלנו — עם הצעדים המעשיים שיש לנקוט.

הכותרות האחרונות מאתרי אבטחת מידע

נאספים כל שעתיים מפרסומים מקצועיים — כל קישור מוביל למאמר המקורי.

עדיין אין חדשות בשפתכם — הנה הסיקור שלנו באנגלית:

DataBreaches.net
DataBreaches.net פריצות ודליפות
ShinyHunters hacker “Rey,” allegedly involved in FBI data theft, detained in Jordan

Jana Winter, Raphael Satter, and A.J. Vicens report: A key member of the ShinyHunters hacking group, ‌which claims to have stolen data on every FBI employee, w…

The Hacker News
The Hacker News פריצות ודליפות
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in att…

Microsoft 365

DataBreaches.net
DataBreaches.net
DHS readies major cyber contract

Justin Doubleday reports: The Department of Homeland Security is preparing this year to award a major cloud, cybersecurity and network services contract aimed …

The Hacker News
The Hacker News
The State of Cybersecurity in 2026:Key Segments, Insights, and Innovations

Featuring:Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As …

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Apache Camel Vulnerability Can Expose Files and Internal Services

Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
LightLLM Profiling Flaw Allows Code Execution Without a Login

LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
ModSecurity Updates Fix WAF Bypasses on Linux Web Servers

ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without be…

Linux

The Hacker News
The Hacker News פריצות ודליפות
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organi…

The Hacker News
The Hacker News
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cybe…

The Hacker News
The Hacker News
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure."We are actively addressi…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Command Injection Flaw in shell-quote Can Execute Linux Commands

The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.

Linux

The Hacker News
The Hacker News פריצות ודליפות
Know Your Enemy: Browser-Based Attack Techniques in 2026

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browse…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Linux File Truncation Patch Targets Data Loss Beyond the Requested Range

A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
Linux Tracing Patch Addresses a Probe Use-After-Free Race

A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
How to Review Linux Security Boundaries: Three Kernel Examples

A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.

Linux

The Hacker News
The Hacker News פריצות ודליפות
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems

San Francisco, USA, 29th September 2026, CyberNewswireSalmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Syste…

The Hacker News
The Hacker News
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed Phant…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles חולשות
GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers

Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.

GitLab