Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities

⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Foundation Launches Akrites to Strengthen Software Supply Chain Security

The Linux Foundation has officially launched Akrites, a coordinated industry initiative designed to improve how critical open source vulnerabilities are valida…

Linux AWS GitHub

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Programming Languages for Cyber Security: What the Tools Actually Use

Security tooling is not written in a single language. Python powers most automation. C sits at the exploit layer. PowerShell dominates Windows incident respons…

Windows

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

DirtyClone Is the Fourth ‘Dirty’ Linux Kernel Exploit in Six Weeks

CVE-2026-43503 DirtyClone is the fourth DirtyFrag-family privilege escalation in six weeks. JFrog's public PoC raises the urgency. More variants may still be i…

Linux

The Hacker News
The Hacker News Vulnerabilities

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer o…

AWS

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Dark Moon: Can AI Actually Automate Penetration Testing on Linux?

AI is beginning to reshape how penetration testing workflows are organized. For years, the penetration tester’s workflow has been a labor-intensive ritual: sca…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

How AI Is Changing Open Source Penetration Testing

AI is beginning to reshape how penetration testing workflows are organized. For years, the penetration tester’s workflow has been a labor-intensive ritual: sca…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Cisco Unified CM SSRF Flaw Is Being Exploited to Drop Webshells

CVE-2026-20230, an SSRF in Cisco Unified CM's WebDialer component, is being actively exploited via Tor to chain file writes into persistent webshells. Patches …

Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

The New Rules for AI-Assisted Contributions: Ownership is Not Optional

AI-assisted patches are already showing up across open source. Small GitHub projects, package updates, kernel-adjacent tools, system libraries. It’s not a futu…

GitHub

The Hacker News
The Hacker News Vulnerabilities

GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns

GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pu…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

FFmpeg PixelSmash Vulnerability Exposes Linux Media Servers to Remote Code Execution Risk

A newly disclosed FFmpeg vulnerability, known as PixelSmash (CVE-2026-8461), affects the MagicYUV decoder and can be triggered by specially crafted video files.

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks

SonicWall CVE-2024-40766 Proves Patching Is Not Remediation

A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never …

The Hacker News
The Hacker News Vulnerabilities

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial inte…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

AryStinger: Why Thousands of Unpatched Linux Routers Are Being Weaponized

More than 4,300 internet-facing devices have been pulled into a newly documented router malware campaign called AryStinger. The infected systems are mostly not…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

SQL Injection: Why It Persists and How to Prevent It

SQL injection has been in every OWASP Top 10 list ever published, and it is still number five in 2025. Here is why the vulnerability persists and the defences …

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Virus vs Worm: Why the Propagation Difference Actually Matters

The difference between a virus and a worm is not semantic. A virus waits for a user to trigger it; a worm exploits vulnerabilities and spreads on its own. That…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

usbliter8 Exploit Achieves Code Execution in Apple’s Unpatchable SecureROM

Paradigm Shift has published a working exploit for Apple's A12 and A13 SecureROM. The flaw is in hardware, so no patch will ever exist. Here's the technical br…

Apple

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

OpenStack Keystone Flaws Expose Multiple Paths to Cloud Privilege Escalation

The recent Keystone advisory is unusual because the vulnerabilities are scattered across several features but keep affecting the same class of security control…

The Hacker News
The Hacker News Vulnerabilities

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution.Steer t…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

The ASLR Caveat on NGINX’s Critical HTTP/3 Flaw Changes Nothing About Urgency

CVE-2026-42530, the NGINX HTTP/3 vulnerability rated CVSS 9.2, is collecting dismissals because exploitation requires ASLR to be disabled or bypassed. Here is …

Nginx

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Fortinet FortiSandbox Critical Command Execution Risk Exploit 2026-39813

Fortinet has confirmed active exploitation of three FortiSandbox vulnerabilities. One allows attackers to bypass login controls, while the other two enable com…

Fortinet

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

CVE-2026-48907: How the Joomla JCE Exploit Works and What to Do About It

CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request. Here is how the attack works and how …

PHP

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers

The Joomla Content Editor (JCE), one of the most widely deployed editor extensions for Joomla websites, is currently under active attack due to a critical vuln…

Linux

The Hacker News
The Hacker News Breaches & leaks

The Top 10 Attack Surface Exposures in 2026

Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerabilit…