Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Security Roundup: Prioritizing This Week's Critical Updates

Before you close out the week, check what still needs to be patched.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Mak's Security Roundup: Prioritizing This Week's Critical Updates

Before you close out the week, check what still needs to be patched.

The Hacker News
The Hacker News Breaches & leaks
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial …

Citrix

The Hacker News
The Hacker News Breaches & leaks
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

This week’s security news is mostly about weak spots.Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everyt…

Apple

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Cursor IDE Vulnerabilities Let Prompt Injection Escape the Sandbox

Two critical Cursor IDE vulnerabilities, dubbed DuneSlide, let prompt injection break the editor's command sandbox with no click required. Both are fixed in Cu…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
NetScaler Memory Overread Flaw Revives CitrixBleed Fears

Citrix has patched a pre-auth NetScaler memory overread bug, CVE-2026-8451, that echoes the 2023 CitrixBleed flaw and was found while researchers dissected an …

Citrix

The Hacker News
The Hacker News Breaches & leaks
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.Its Threat Research Team calls t…

The Hacker News
The Hacker News Vulnerabilities
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in P…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Network Security Monitoring: Common Linux Monitoring Gaps That Hide Threats

If you’re relying on standard network logs to protect your Linux infrastructure, you’re flying blind. Most organizations believe they have network security mon…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
libssh2 CVE-2026-55200 Shows Why Outbound SSH Is an Attack Surface

The critical libssh2 CVE-2026-55200 flaw inverts SSH security: the remote server attacks the connecting client, no credentials needed. A public PoC is out and …

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Amazon Q’s MCP Flaw Is an Industry Warning: AI Tools Still Lack Workspace Trust Standards

CVE-2026-12957 in Amazon Q is the third MCP auto-execution vulnerability in three AI coding tools. The pattern reveals a shared design failure, not just a sing…

AWS

The Hacker News
The Hacker News Vulnerabilities
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Foundation Launches Akrites to Strengthen Software Supply Chain Security

The Linux Foundation has officially launched Akrites, a coordinated industry initiative designed to improve how critical open source vulnerabilities are valida…

Linux AWS GitHub

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Programming Languages for Cyber Security: What the Tools Actually Use

Security tooling is not written in a single language. Python powers most automation. C sits at the exploit layer. PowerShell dominates Windows incident respons…

Windows

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
DirtyClone Is the Fourth ‘Dirty’ Linux Kernel Exploit in Six Weeks

CVE-2026-43503 DirtyClone is the fourth DirtyFrag-family privilege escalation in six weeks. JFrog's public PoC raises the urgency. More variants may still be i…

Linux

The Hacker News
The Hacker News Vulnerabilities
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer o…

AWS

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Dark Moon: Can AI Actually Automate Penetration Testing on Linux?

AI is beginning to reshape how penetration testing workflows are organized. For years, the penetration tester’s workflow has been a labor-intensive ritual: sca…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
How AI Is Changing Open Source Penetration Testing

AI is beginning to reshape how penetration testing workflows are organized. For years, the penetration tester’s workflow has been a labor-intensive ritual: sca…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Cisco Unified CM SSRF Flaw Is Being Exploited to Drop Webshells

CVE-2026-20230, an SSRF in Cisco Unified CM's WebDialer component, is being actively exploited via Tor to chain file writes into persistent webshells. Patches …

Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
The New Rules for AI-Assisted Contributions: Ownership is Not Optional

AI-assisted patches are already showing up across open source. Small GitHub projects, package updates, kernel-adjacent tools, system libraries. It’s not a futu…

GitHub

The Hacker News
The Hacker News Vulnerabilities
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pu…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
FFmpeg PixelSmash Vulnerability Exposes Linux Media Servers to Remote Code Execution Risk

A newly disclosed FFmpeg vulnerability, known as PixelSmash (CVE-2026-8461), affects the MagicYUV decoder and can be triggered by specially crafted video files.

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks
SonicWall CVE-2024-40766 Proves Patching Is Not Remediation

A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never …

The Hacker News
The Hacker News Vulnerabilities
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial inte…