The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Tails OS is changing the speed of its entire Linux distribution because one of its most security-sensitive applications is tied to the system image. Tails 7.12…
The Linux security news from August 27 through September 3 brought serious fixes for remote access software, PostgreSQL, sandboxing tools, local system service…
A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026,…
A kernel crash tells defenders that something went wrong. It does not show whether an attacker can turn that failure into a useful capability, combine several …
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplac…
Virtualizor has confirmed that a BGP hijack redirected traffic for part of its update infrastructure and allowed an attacker-controlled server to deliver a mal…
A Linux host intrusion prevention system can fail even when the protected server still has spare CPU. If its logging path cannot record and move events as quic…
A Linux kernel patch series submitted on Sep 1, 2026, stops an out-of-service Logical Link Control socket from indexing below two connection-state tables. The …
A Linux server can be carefully hardened before it reaches production and still become less secure over time. Hardening means reducing unnecessary services, ac…
A patched Linux server can still fail a penetration test because patch status cannot show whether an attack path remains open.
Using a proxy on Linux changes how web traffic reaches its destination, but it does not automatically protect every part of the connection. DNS requests may st…
A version 2 Linux kernel patch posted on August 31 fixes a stack overflow in the SA2UL hardware crypto driver. The Kernel Address Sanitizer, or KASAN, detected…
A version 2 Linux kernel patch series posted on August 31 proposes a new eBPF security interface for applying Landlock policy during program execution. The 15-…
An eBPF security system can produce precise Linux telemetry while leaving a harder question unanswered: what happens if the eBPF layer itself is misconfigured,…
Linux interrupt maintainer Thomas Gleixner traced a Kernel Address Sanitizer report to incomplete regmap IRQ cleanup on Aug 30, 2026. The crash appeared while …
Jonghyuk Kim submitted a Linux Direct Rendering Manager scheduler patch series on Aug 28, 2026 that targets a use-after-free read shared by several GPU drivers…
Bnei Brak, Israel, 31st August 2026, CyberNewswireLunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials on Latest …
A Linux service may need broad system-call access while it starts, then only a smaller set while it handles requests. A single policy loaded before startup oft…
Linux kernel vulnerability news dominated the security updates published from August 20 through August 27. Ubuntu, Debian, Fedora, Mageia, Oracle Linux, Rocky …
A Linux security hook should be able to check a task without invalidating the identity data that surrounding kernel code is still using. AppArmor broke that ex…
Linus Torvalds merged a Linux NFS client update on Aug 26, 2026, that includes a fix for rpc_pipefs files left attached to an RPC client after the client objec…
The Linux IPMI maintainer accepted a patch on Aug 26, 2026 that restores an RCU grace period before command-receiver objects are freed. The one-line change add…
A Linux system can be hardened, monitored, and carefully administered while still receiving untrusted code through a package, dependency, container image, buil…
A Linux dm-integrity patch posted on Aug 24, 2026 targets a writeback race that can leave stored data with the wrong integrity tag after a crash. Chen Cheng pr…