The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Cyberattacks cost retailers time, trust, and money''especially during peak seasons when disruption hits hardest. Despite heavy investments in cybersecurity, th…
Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to …
Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti…
At least six organizations in South Korea have been targeted by the prolific North Korea-linked Lazarus Group as part of a campaign dubbed Operation SyncHole.T…
The release of MITRE ATT&CK v17 , with the addition of a dedicated matrix for VMware ESXi hypervisors, reflects the growing threat surface in virtualized envir…
Securing the software supply chain has become a critical focus for us security professionals, especially in response to increasingly sophisticated attacks targ…
Vishing, or voice phishing, is when attackers use a phone call''not malware or email''to pull off a scam. They pretend to be someone trustworthy: tech support,…
Multiple threat activity clusters with ties to North Korea (aka Democratic People's Republic of Korea or DPRK) have been linked to attacks targeting organizati…
The Iran-nexus threat actor known as UNC2428 has been observed delivering a backdoor known as MURKYTOUR as part of a job-themed social engineering campaign aim…
Oracle Ksplice is an invaluable tool that fundamentally reshapes how we apply and monitor Linux security patches. Oracle Ksplice's Known Exploit Detection take…
The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed…
Cybersecurity researchers have detailed a malware campaign that's targeting Docker environments with a previously undocumented technique to mine cryptocurrency…
Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privile…
We, Linux security admins, are always on the lookout for kernel updates that enhance system stability and address critical bugs, and Linux 6.15-rc3 is no excep…
The recently released MX Linux 23.6 is a compelling option for us admins seeking a secure and efficient operating system based on Debian 12.10 "Bookworm." With…
Secure Sockets Layer (SSL) certificates are important for website security. Almost every list of website…The Role of SSL Certificates in Website Security and P…
The China-linked cyber espionage group tracked as Lotus Panda has been attributed to a campaign that compromised multiple organizations in an unnamed Southeast…
Cybersecurity researchers have flagged a new malicious campaign related to the North Korean state-sponsored threat actor known as Kimsuky that exploits a now-p…
A new Android malware-as-a-service (MaaS) platform named SuperCard X can facilitate near-field communication (NFC) relay attacks, enabling cybercriminals to co…
When malware like XorDDoS resurfaces with expanded capabilities, it's a wake-up call for us security professionals managing Linux-based systems. Initially disc…
When malware like XorDDoS resurfaces with expanded capabilities, it's a wake-up call for us security professionals managing Linux-based systems. Initially disc…
The GNOME Project recently rolled out GNOME 48.1 , the first maintenance update for the GNOME 48 ''Bengaluru'' desktop environment series. This update will soo…
The GNOME Project recently rolled out GNOME 48.1 , the first maintenance update for the GNOME 48 ''Bengaluru'' desktop environment series. This update will soo…
We Linux security administrators face a growing challenge with sophisticated supply chain attacks targeting popular development ecosystems, such as npm. The la…