The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with auto…
Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 o…
As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mu…
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere e…
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wedn…
Docker has fixed a high-severity Docker Sandboxes vulnerability that allowed a malicious guest to redirect a host-side relay toward Unix sockets outside its au…
Acronis has fixed a high-severity vulnerability in its Linux hosting backup integrations after detecting exploitation in limited, targeted attacks. The Acronis…
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.The…
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.The first is an automated…
On September 10, 2026, Wiz Research reported that multiple attackers had chained two Artifactory vulnerabilities against self-hosted repositories. One flaw gav…
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining wh…
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewa…
Adobe has released an emergency fix for a Magento vulnerability that attackers are already using against online stores. Someone exploiting the flaw can make an…
Listing network routes should tell administrators where traffic will go. An IPv6 security report instead shows Linux accessing a freed record used to keep trac…
Chrome release notes can be a blur of version numbers. This one deserves a closer look. In the Linux build published on September 3, 2026, Google fixed CVE-202…
A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). Both…
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, eve…
Linux maintainers are testing a patch for a page-cache bug after KASAN reproduced a use-after-free in filemap_map_pages(). On Sep 3, 2026, Andrew Morton said h…
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.The fixes are avai…
A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026,…
A kernel crash tells defenders that something went wrong. It does not show whether an attacker can turn that failure into a useful capability, combine several …
A Linux kernel patch series submitted on Sep 1, 2026, stops an out-of-service Logical Link Control socket from indexing below two connection-state tables. The …
A patched Linux server can still fail a penetration test because patch status cannot show whether an attack path remains open.
A version 2 Linux kernel patch posted on August 31 fixes a stack overflow in the SA2UL hardware crypto driver. The Kernel Address Sanitizer, or KASAN, detected…