Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

DataBreaches.net
DataBreaches.net Breaches & leaks
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reute…

BleepingComputer
BleepingComputer Vulnerabilities
How to secure RMM software: 8 controls MSPs should test

RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight contro…

DataBreaches.net
DataBreaches.net Breaches & leaks
Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million

Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation: On October 5, 2026, Danish authorities publicly …

The Hacker News
The Hacker News Vulnerabilities
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There…

Apache

The Hacker News
The Hacker News Breaches & leaks
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful …

The Hacker News
The Hacker News Vulnerabilities
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol d…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Kernel Vulnerability Fixed in Binder Device Creation

Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems

Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.

Citrix

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
OpenOffice Vulnerability Can Run Code From Malicious Documents

Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877

Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
OpenSSL Vulnerability Can Leak Server Memory Through DTLS

OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.

OpenSSL

BleepingComputer
BleepingComputer Vulnerabilities
Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and r…

The Record
The Record Vulnerabilities
US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…

Citrix

BleepingComputer
BleepingComputer Vulnerabilities
New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.…

The Hacker News
The Hacker News Breaches & leaks
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep fi…

Citrix Fortinet

BleepingComputer
BleepingComputer Vulnerabilities
Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.…

BleepingComputer
BleepingComputer Vulnerabilities
Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks…

Citrix

The Hacker News
The Hacker News Breaches & leaks
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in att…

Microsoft 365

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Apache Camel Vulnerability Can Expose Files and Internal Services

Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
LightLLM Profiling Flaw Allows Code Execution Without a Login

LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…

Linux