The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Justin Doubleday reports: The Cybersecurity and Infrastructure Security Agency is continuing to offer cyber pay incentives to retain skilled technical staff, b…
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…
A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.
A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…
Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 o…
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere e…
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wedn…
A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). Both…
A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026,…
Linux kernel fuzzing service syzbot has reported an out-of-bounds array access in print_bpf_insn(), a routine used to turn BPF instructions into readable verif…
A Linux security tool can catch a system call and still record the wrong thing.
This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.
The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broade…
The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broade…
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch.Pu…
A large volume of Linux security updates and advisories this week across major distributions once again, but it wasn't just the volume that was the story. Wher…
Most Linux teams don't struggle to find vulnerabilities anymore. They struggle to decide which ones deserve attention first. Between daily scanner results, ven…
Before the week gets away from you, take a look at what's landed across the Linux ecosystem. The volume of security advisories hasn't slowed, and while not eve…
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda a…
A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration…
The recent Keystone advisory is unusual because the vulnerabilities are scattered across several features but keep affecting the same class of security control…