Collected every two hours from specialised publications — each link leads to the original article.
bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes ---- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix iss…
bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes ---- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix iss…
It was discovered that the vhost PMD in DPDK, a set of libraries for fast packet processing, was affected by memory and file descriptor leaks which could resul…
LibVNC contained a memory leak (CWE-655) in VNC server code, which allowed an attacker to read stack memory and could be abused for information disclosure.
It was discovered that the Special:Redirect functionality of MediaWiki, a website engine for collaborative work, could expose suppressed user names, resulting …
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.
Exim may be the Internet's most popular email server, but the MTA's recent history with security vulnerabilities is concerning to say the least. This past Frid…
Gentoo Linux has issued a security advisory about multiple vulnerabilities in FreeType, urging users to upgrade to version 2.14.3 to mitigate risks including a…
A process with a stable workload shouldn't keep growing its resident memory. When it does, the first question isn't how much RAM is available. It's where the a…
An AUR supply chain attack compromised more than 400 Arch Linux packages from 11 June 2026, planting a Rust credential stealer and an eBPF rootkit that hides f…
Your attack surface no longer lives on one operating system, and neither do the campaigns targeting it. In enterprise environments, attackers move across Windo…
The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependen…
Cybersecurity researchers have disclosed details of a malicious Go module that's designed to harvest passwords, create persistent access via SSH, and deliver a…
React2Shell is a server-side vulnerability that turns a normal web request into code execution. It allows unauthenticated remote code execution, without creden…
Imagine this scenario: you're managing Linux servers that host critical applications, where uptime is everything and security is non-negotiable. You're diligen…
Docker containers are supposed to provide a safe boundary''a virtual sandbox separating workloads from the host machine. When that boundary gets breached, we'r…
As a Linux admin, you're no stranger to juggling servers, permissions, and late-night emergencies. Let me introduce you to Qilin ransomware ''a crafty, cross-p…
libpam vulnerable to leaking hashed passwords. (CVE-2024-10041) References: - https://bugs.mageia.org/show_bug.cgi?id=34219 - https://lists.opensuse.org/archiv…
Oracle Ksplice is an invaluable tool that fundamentally reshapes how we apply and monitor Linux security patches. Oracle Ksplice's Known Exploit Detection take…
We Linux security administrators face a growing challenge with sophisticated supply chain attacks targeting popular development ecosystems, such as npm. The la…
The Anubis ransomware group has emerged as a growing threat, targeting Linux environments, NAS devices, and ESXi systems. What sets Anubis apart is its novel r…
Qualys researchers have recently identified two significant vulnerabilities in OpenSSH that put Linux and FreeBSD systems at severe risk. These bugs enable man…
Recent reports have revealed a sophisticated intrusion campaign conducted by Salt Typhoon, targeting major U.S. telecommunications providers. To safeguard agai…