Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through…

Windows Chrome

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Why Seccomp Must Be Rechecked After Container Restore

Seccomp limits which Linux system calls a process can make.

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
How Container Restore Can Reopen Privilege Escalation Paths

Privilege escalation in a container does not always begin with a new exploit.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
What CRIU Restores Beyond Application Memory in Linux Containers

Linux containers can be paused, checkpointed, and rebuilt later with CRIU.

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Why Container Security Needs a Separate Restore Boundary

A container normally starts under the security rules of the system receiving it.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CRI-O Restore Flaw Can Bypass Kubernetes Security Policies

Kubernetes groups one or more containers into a pod, the basic unit it deploys.

Docker Kubernetes

The Hacker News
The Hacker News Breaches & leaks
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers i…

The Hacker News
The Hacker News
DORA Year Two: Can Your SOC Actually See the Attack?

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financi…

The Hacker News
The Hacker News
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indi…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Researchers Show How Prompt Injection Could Expose AWS AgentCore Credentials

Security researchers have shown how hidden instructions in an AWS AgentCore support ticket could push an AI agent into running commands as root and exposing a …

AWS

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
crun Tightens GPU Security for Containers Running in MicroVMs

The crun container runtime has changed how GPU-enabled workloads launch a key graphics helper.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Fix SELinux Overlays Important Security Contexts 401610

Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.

Linux

The Hacker News
The Hacker News Breaches & leaks
Identity Visibility in 2026: The Foundation of Identity Security

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial acc…

The Hacker News
The Hacker News
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity ev…

The Hacker News
The Hacker News Breaches & leaks
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September…

GitHub

The Hacker News
The Hacker News Vulnerabilities
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Security Roundup: Patch BIND, Browsers, and Cloud Kernels First

Most administrators do not think about BIND, browser engines, or cloud kernels until one of them fails.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux eBPF Security Flaw Could Approve an Out-of-Bounds Memory Access

A Linux eBPF security flaw could cause the kernel to approve a program using an incorrect understanding of the values it would process.

Linux

The Hacker News
The Hacker News Breaches & leaks
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artifici…

Android

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws

Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with auto…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISA Warns of Active Attacks on a Critical Cisco ISE Flaw

Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 o…

Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Red Hat Quay Build Workflow Could Expose Registry Credentials

As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mu…

Linux Docker GitHub

The Hacker News
The Hacker News Vulnerabilities
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere e…

Docker Apple

The Hacker News
The Hacker News Breaches & leaks
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based ut…