Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer

A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months …

Windows

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region

A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums r…

AWS

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins

WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution.wp2shell: Wor…

WordPress

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021

A heap-based buffer overflow in 7-Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five year…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks
ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit

An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an …

Docker

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft Patches It

A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the configuration changes to make right now.Azur…

Azure

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
How the Bing Images RCE Flaws Actually Worked, and How to Check Your Own Pipeline

A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain and a checklist for anyone running a…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
How the Fastjson RCE Vulnerability Actually Works, and How to Check You’re Exposed

A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate…

The Hacker News
The Hacker News Vulnerabilities
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applica…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot

Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts …

Kubernetes

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Logging Strategies for Maximizing Security Visibility

A Linux server can be fully patched, hardened, and compliant, yet still leave investigators unable to explain how an attacker got in. Without reliable Linux lo…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISA KEV vs. NVD: How Linux Teams Should Prioritize Vulnerabilities That Actually Matter

Most Linux teams don't struggle to find vulnerabilities anymore. They struggle to decide which ones deserve attention first. Between daily scanner results, ven…

Linux

The Hacker News
The Hacker News Vulnerabilities
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, wh…

Chrome

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
GNOME Cuts Vulnerability Disclosure Window to 30 Days

GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Lin…

Linux

The Hacker News
The Hacker News Vulnerabilities
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's desi…

The Hacker News
The Hacker News Breaches & leaks
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) …

Palo Alto

The Hacker News
The Hacker News Vulnerabilities
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) m…

The Hacker News
The Hacker News Vulnerabilities
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no explo…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Gitea 1.27 Delivers 45 Security Fixes for Self-Hosted Git Servers

For organizations that run a self-hosted Git platform, it’s no longer just about hosting static code repositories. Today, Git servers are responsible for deplo…

The Hacker News
The Hacker News Vulnerabilities
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archi…

The Hacker News
The Hacker News Vulnerabilities
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted H…

Nginx

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux UEFI Shim Vulnerability Severe Exploitation of Obsolete Bootloaders

ESET researchers identified 11 old and forgotten Linux UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Mak’s Weekly Security Roundup: Linux Updates You Shouldn't Ignore This Week

Before the week gets away from you, take a look at what's landed across the Linux ecosystem. The volume of security advisories hasn't slowed, and while not eve…

Linux VPN Docker

The Hacker News
The Hacker News Vulnerabilities
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.The vulnerabilities are listed b…

VMware Chrome