Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

DataBreaches.net
DataBreaches.net Alerts
CISA to keep cyber pay incentives, but less staff will qualify

Justin Doubleday reports: The Cybersecurity and Infrastructure Security Agency is continuing to offer cyber pay incentives to retain skilled technical staff, b…

The Record
The Record Vulnerabilities
US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…

Citrix

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Apache Camel Vulnerability Can Expose Files and Internal Services

Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …

Apache

The Hacker News
The Hacker News Vulnerabilities
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
MCP Toolbox Flaw Could Expose Google Service Tokens

A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Emacs Security Flaw Could Run Code From an Untrusted File

A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.

The Hacker News
The Hacker News Vulnerabilities
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISA Warns of Active Attacks on a Critical Cisco ISE Flaw

Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 o…

Cisco

The Hacker News
The Hacker News Vulnerabilities
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere e…

Docker Apple

The Hacker News
The Hacker News Vulnerabilities
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wedn…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Advisory Timer Vulnerabilities Leading to Use-After-Free Issues

A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). Both…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISA Flags Exploited Kestra Flaw That Lets Attackers Run Commands in Linux Containers

A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026,…

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Linux Kernel BPF Disassembler Out-of-Bounds Access Advisory Alert

Linux kernel fuzzing service syzbot has reported an out-of-bounds array access in print_bpf_insn(), a routine used to turn BPF instructions into readable verif…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
eBPF Security Logs May Show the Wrong File or Command, New Study Warns

A Linux security tool can catch a system call and still record the wrong thing.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Mak's Weekly Security Roundup: Critical Linux Security Updates Admins Should Know

This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Linux Kernel Updates Privilege Escalation Provisioning July 28 2026

The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broade…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Mak's Weekly Security Roundup: Linux Security Priorities This Week

The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broade…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511

A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch.Pu…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Mak’s Weekly Security Roundup: Linux Security Updates, Priorities, and Risk

A large volume of Linux security updates and advisories this week across major distributions once again, but it wasn't just the volume that was the story. Wher…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISA KEV vs. NVD: How Linux Teams Should Prioritize Vulnerabilities That Actually Matter

Most Linux teams don't struggle to find vulnerabilities anymore. They struggle to decide which ones deserve attention first. Between daily scanner results, ven…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Mak’s Weekly Security Roundup: Linux Updates You Shouldn't Ignore This Week

Before the week gets away from you, take a look at what's landed across the Linux ecosystem. The volume of security advisories hasn't slowed, and while not eve…

Linux VPN Docker

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed

CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda a…

The Hacker News
The Hacker News Breaches & leaks
INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific

A new report from INTERPOL has revealed a "dramatic increase" in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
OpenStack Keystone Flaws Expose Multiple Paths to Cloud Privilege Escalation

The recent Keystone advisory is unusual because the vulnerabilities are scattered across several features but keep affecting the same class of security control…