Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning th…

Windows

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed

CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda a…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs

ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new exploit.11 Old Signed UEFI Shims …

The Hacker News
The Hacker News Vulnerabilities
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of …

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
GhostLock Exposes an Uncomfortable Truth About Open Source Security

When researchers announced GhostLock, many people focused on the exploit. What stood out to me wasn't just what the vulnerability could do, but how long it had…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
How Linux Security Teams Spot Vulnerabilities Before CVEs Are Published

Most of us don't hear about a kernel vulnerability until a CVE lands in our inbox or the vulnerability scanner starts complaining. By then, the patch isn't new…

Linux

The Hacker News
The Hacker News Breaches & leaks
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without expl…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Critical Gitea Docker Authentication Bypass: An Open Door to Your Infrastructure

If you’re running Gitea in a container, stop what you’re doing and check your versioning right now. We’re looking at a critical vulnerability—CVE-2026-20896—sh…

Docker

The Hacker News
The Hacker News Vulnerabilities
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code e…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Privilege Escalation from a Defensive Perspective: Sudoers and SUID Misconfigurations

Root access on a Linux system rarely arrives through a zero-day.

Linux

The Hacker News
The Hacker News Vulnerabilities
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart ca…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks
How the GodDamn Ransomware Driver Bypasses Your EDR

GodDamn ransomware's PoisonX driver is a textbook EDR bypass driver: a Microsoft-signed kernel driver that kills security tools instead of exploiting them.How …

The Hacker News
The Hacker News Vulnerabilities
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the…

The Hacker News
The Hacker News Vulnerabilities
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, co…

The Hacker News
The Hacker News Vulnerabilities
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software gene…

The Hacker News
The Hacker News Vulnerabilities
Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software gene…

The Hacker News
The Hacker News Vulnerabilities
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The …

AWS

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Adobe ColdFusion Vulnerabilities Are a Design Failure, Not Bad Luck

Adobe frames the fast exploitation of its ColdFusion vulnerabilities as an attacker speed problem. The real issue is a connector that never should have trusted…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Gitea Docker Vulnerability Now Under Active Probing, CVE-2026-20896

A critical flaw in Gitea's official Docker image let anyone impersonate an admin with one forged header. Sysdig spotted the first exploitation attempts 13 days…

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
The Hidden Cost of Enterprise SSH Authentication

We often view OpenSSH security updates through the lens of standard patch management. When a new CVE hits, we scramble to update, check our versions, and retur…

OpenSSH

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
How Linux Security Teams Can Prioritize Real-World Attack Paths and Reduce Alert Fatigue

Linux security teams are drowning. Patches, kernel updates, new CVEs every week. SSH exposed here, an old web service there, and a forgotten cron job running a…

Linux

The Hacker News
The Hacker News Vulnerabilities
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use i…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
CSRF Attack Explained: Mechanics, Real Exploits, and How to Test for It

A practitioner's breakdown of the CSRF attack: how the forged request works, two documented exploits, a manual test, and the fixes that hold up.CSRF Attack Exp…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
“Bad Epoll” Linux Kernel Bug Lets Any User Grab Root

A newly disclosed use-after-free in the Linux kernel's epoll code, CVE-2026-46242, lets an unprivileged user get root on affected Linux and Android systems. A …

Linux Android