Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Misuse of Cron Jobs for Long-Term Access in Linux Environments

Cron has existed in Unix and Linux environments for decades, handling backups, cleanup scripts, patching jobs, log rotation, monitoring tasks, and other mainte…

Linux

The Hacker News
The Hacker News Breaches & leaks
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure t…

VPN

The Hacker News
The Hacker News Breaches & leaks
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151) has been observed using lures related to Prometheus, a Ukrainian online learni…

The Hacker News
The Hacker News Breaches & leaks
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositor…

GitHub

The Hacker News
The Hacker News Breaches & leaks
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malici…

The Hacker News
The Hacker News Breaches & leaks
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platfor…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised.It…

GitHub

The Hacker News
The Hacker News Breaches & leaks
GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious c…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious c…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv eco…

Apache

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks
Why Credential and Session Exposure Monitoring Should Be a Baseline Security Practice

Data breaches and ransomware incidents are often discussed as if they begin with a sophisticated…Why Credential and Session Exposure Monitoring Should Be a Bas…

The Hacker News
The Hacker News Breaches & leaks
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but n…

Apple

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Linux Security Monitoring Challenges and EDR Visibility Gaps

An attacker compromises a Linux container, launches a cryptominer, sets up a way to stay in the system through a background task, and disappears before the inv…

Linux Docker

The Hacker News
The Hacker News Breaches & leaks
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace."If you are using Checkmarx Jenkins AST plug…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Why Linux Servers Get Hacked More Often Than People Think

Linux runs a massive part of the internet. Cloud platforms, databases, containers, web hosting, APIs, and internal business infrastructure all depend heavily o…

Linux Docker

The Hacker News
The Hacker News Breaches & leaks
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated att…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Linux Attackers Abuse Admin Tools For Stealthy Intrusions

A lot of Linux attacks now look like normal admin activity. Attackers use SSH , cron , curl , systemd , cloud scripts, and other trusted tools that defenders a…

Linux

The Hacker News
The Hacker News Breaches & leaks
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems

Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any art…

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
CrackArmor AppArmor Flaws Put Linux Containers and Snap Sandboxes at Risk

Linux administrators rely on AppArmor to contain compromised applications. If a browser, container, or Snap package is exploited, the profile is supposed to li…

Linux Docker

The Hacker News
The Hacker News Breaches & leaks
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in …

The Hacker News
The Hacker News Breaches & leaks
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware

A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from …

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Your Linux Logs Probably Arent Catching Attacks: 2026 Detection Gaps

When a Linux system is compromised, the logs should tell you what happened. In a lot of cases, they don't.

Linux

The Hacker News
The Hacker News Breaches & leaks
ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

The North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing …

Windows Android