Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

How CVE-2026-20253 Turns Splunk’s PostgreSQL Sidecar Into an Open Door

CVE-2026-20253 is a CVSS 9.8 pre-auth flaw in Splunk Enterprise's PostgreSQL sidecar service. An unauthenticated attacker can write files and chain the primiti…

Databases

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

SimpleHelp Authentication Bypass Exposes Remote Access Security Risk

Remote support platforms sit close to the systems attackers want most: administrator workflows, technician accounts, and managed endpoints. That is why the Sim…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Cisco SD-WAN Vulnerability: Why Security Starts With the Management Plane

For those of us who live and breathe Linux and open-source infrastructure, the "management plane" is usually just a collection of familiar tools—SSH, APIs, and…

Linux Cisco

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

LiteLLM Vulnerability Chain: What Security Teams Running AI Gateways Need to Do Now

A three-CVE chain lets any default LiteLLM user escalate to admin and get a shell on the gateway server. A separate RCE is already in CISA's KEV. Here's what t…

The Hacker News
The Hacker News Vulnerabilities

Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.The vuln…

Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Does Linux Give Users a False Sense of Security? What This Year's Biggest Linux Security Incidents Actually Reveal

If more than 12 million enterprise systems can be exposed by flaws in a security control designed to harden Linux, it's probably worth asking whether Linux giv…

Linux

The Hacker News
The Hacker News Vulnerabilities

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidia…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Palo Alto’s GlobalProtect Authentication Bypass Was Exploited Four Days After Disclosure

CVE-2026-0257's GlobalProtect authentication bypass went from advisory to active exploitation in four days. The recurring pattern of perimeter device failures …

Palo Alto

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks

Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate

A CVSS 9.3 flaw in Check Point Remote Access VPN let unauthenticated attackers bypass certificate validation by supplying a crafted IKEv1 VendorID payload — ex…

VPN

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Langflow 1.9.0 Advisory CVE-2026-5027 High File Write Threat

Attackers are actively exploiting a high-severity vulnerability in Langflow, an open-source platform used to build and run AI workflows.

The Hacker News
The Hacker News Vulnerabilities

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponiz…

The Hacker News
The Hacker News Vulnerabilities

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution an…

Fortinet Ivanti

The Hacker News
The Hacker News Vulnerabilities

Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE

A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitat…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Actively Exploited Chromium V8 Zero-Day: What Linux Admins Need to Know

CISA added CVE-2026-11645 to its Known Exploited Vulnerabilities catalog after Google confirmed active exploitation of the flaw. The bug sits in V8, the JavaSc…

Linux Chrome

The Hacker News
The Hacker News Vulnerabilities

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), …

The Hacker News
The Hacker News Vulnerabilities

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with noth…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

HTTP/2 Bomb: Why Linux Infrastructure is Vulnerable to a New Low-Bandwidth DoS Attack

A newly disclosed attack technique called HTTP/2 Bomb is drawing attention because it targets the software that sits at the front of much of the Linux internet…

Linux Apache Nginx

The Hacker News
The Hacker News Vulnerabilities

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker.Like in the cas…

Windows

The Hacker News
The Hacker News Vulnerabilities

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envo…

Apache Nginx

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

Linux Persistence Hunting: The 5 Techniques Security Teams Miss Most

You remove the malware. You rotate the compromised credentials. You patch the original vulnerability and close the ticket. Two weeks later, the attacker is bac…

Linux

The Hacker News
The Hacker News Vulnerabilities

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponi…

The Hacker News
The Hacker News Vulnerabilities

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trus…

The Hacker News
The Hacker News Vulnerabilities

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbit…

The Hacker News
The Hacker News Vulnerabilities

Gitea Vulnerability Exposes Private Container Images without Authentication

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote…

Docker