Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Breaches & leaks

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers

Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to …

The Hacker News
The Hacker News Vulnerabilities

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks

Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti…

Ivanti

The Hacker News
The Hacker News Breaches & leaks

Lazarus Hits 6 South Korean Firms via Cross EX, Innorix Flaws and ThreatNeedle Malware

At least six organizations in South Korea have been targeted by the prolific North Korea-linked Lazarus Group as part of a campaign dubbed Operation SyncHole.T…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Securing Virtualized Linux Environments with MITRE ATT&CK v17

The release of MITRE ATT&CK v17 , with the addition of a dedicated matrix for VMware ESXi hypervisors, reflects the growing threat surface in virtualized envir…

Linux VMware

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

Finding & Fixing Security Bugs with Oracle Ksplice's Known Exploit Detection

Oracle Ksplice is an invaluable tool that fundamentally reshapes how we apply and monitor Linux security patches. Oracle Ksplice's Known Exploit Detection take…

Linux

The Hacker News
The Hacker News Vulnerabilities

Docker Malware Exploits Teneo Web3 Node to Earn Crypto via Fake Heartbeat Signals

Cybersecurity researchers have detailed a malware campaign that's targeting Docker environments with a previously undocumented technique to mine cryptocurrency…

Docker

The Hacker News
The Hacker News Vulnerabilities

GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages

Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privile…

Google Cloud Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

MX Linux 23.6: Improved Security and Admin Tools for Efficient Management

The recently released MX Linux 23.6 is a compelling option for us admins seeking a secure and efficient operating system based on Debian 12.10 "Bookworm." With…

Linux

The Hacker News
The Hacker News Breaches & leaks

Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan

Cybersecurity researchers have flagged a new malicious campaign related to the North Korean state-sponsored threat actor known as Kimsuky that exploits a now-p…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

New Supply Chain Attack Targets Telegram Bots

We Linux security administrators face a growing challenge with sophisticated supply chain attacks targeting popular development ecosystems, such as npm. The la…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

New Supply Chain Attack: Protect Linux Systems from Typosquatting Threats

In a sneaky new supply-chain attack , threat actors have been discovered exploiting package naming conventions to trick unsuspecting developers into installing…

Linux

The Hacker News
The Hacker News Vulnerabilities

Hackers Abuse Russian Bulletproof Host Proton66 for Global Attacks and Malware Delivery

Cybersecurity researchers have disclosed a surge in "mass scanning, credential brute-forcing, and exploitation attempts" originating from IP addresses associat…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

Linux 6.15-rc2 Security Advisory: x86 Patches for Spectre RSB

The latest round of x86 fixes was recently implemented in Linux 6.15-rc2 as several critical patches to increase mitigation against the Spectre Return Stack Bu…

Linux

The Hacker News
The Hacker News Vulnerabilities

CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a medium-severity security flaw impacting Microsoft Windows to its Known Exp…

Windows

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Expired US Funding Threatened to Disrupt Security Flaw Tracking

This past weekend, the globally recognized Common Vulnerabilities and Exposures (CVE) database, essential for tracking security flaws in software and systems, …

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CVE Database Funding Crisis: Urgent Need for Better Support

This past weekend, the globally recognized Common Vulnerabilities and Exposures (CVE) database, essential for tracking security flaws in software and systems, …

Linux

The Hacker News
The Hacker News Vulnerabilities

Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution

A critical security vulnerability has been disclosed in the Erlang/Open Telecom Platform (OTP) SSH implementation that could permit an attacker to execute arbi…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Google Fixed An Old Chrome Flaw That Exposed Browsing History

Google Chrome receives a significant security update as the tech giant addresses a major security…Google Fixed An Old Chrome Flaw That Exposed Browsing History…

Chrome

The Hacker News
The Hacker News Vulnerabilities

CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a security flaw impacting SonicWall Secure Mobile Access (SMA) 100 Series g…

The Hacker News
The Hacker News Vulnerabilities

From Third-Party Vendors to U.S. Tariffs: The New Cyber Risks Facing Supply Chains

IntroductionCyber threats targeting supply chains have become a growing concern for businesses across industries. As companies continue to expand their relianc…

The Hacker News
The Hacker News Vulnerabilities

U.S. Govt. Funding for MITRE's CVE Ends April 16, Cybersecurity Community on Alert

The U.S. government funding for non-profit research giant MITRE to operate and maintain its Common Vulnerabilities and Exposures (CVE) program will expire Wedn…

The Hacker News
The Hacker News Vulnerabilities

Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence

A critical security vulnerability has been disclosed in the Apache Roller open-source, Java-based blogging server software that could allow malicious actors to…

Apache

The Hacker News
The Hacker News Breaches & leaks

Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability

A recently disclosed security flaw in Gladinet CentreStack also impacts its Triofox remote access and collaboration solution, according to Huntress, with seven…

The Hacker News
The Hacker News Vulnerabilities

Cybersecurity in the AI Era: Evolve Faster Than the Threats or Get Left Behind

AI is changing cybersecurity faster than many defenders realize. Attackers are already using AI to automate reconnaissance, generate sophisticated phishing lur…