The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reute…
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight contro…
Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation: On October 5, 2026, Danish authorities publicly …
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There…
The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful …
In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol d…
Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.
Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.
OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and r…
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.…
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep fi…
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.…
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks…
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in att…
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…