The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP…
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as wel…
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 p…
Adelaide, Australia, 19th August 2026, CyberNewswireAirlock Digital Completes Independent IRAP Assessment at the PROTECTED Level on Latest Hacking News | Cyber…
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Wor…
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malwar…
When an authentication platform goes down, downstream applications go with it. Employees can't sign in, customers get locked out, and scheduled jobs quietly fa…
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software b…
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from …
Researchers published a new Linux intrusion-detection architecture on Monday that handles network-flow analysis using XDP and eBPF. By shifting the workload cl…
A sustainable Linux security program depends on more than individual hardening settings, scanners, and monitoring tools. Those controls matter, but they only r…
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to ach…
Security researchers have disclosedFence2Pwn, a new Linux kernel exploitation technique that uses KFENCE’s alternate memory-allocation path to bypass protectio…
A disclosure posted to the oss-security mailing list on August 16, 2026, reports that OpenZFS on Linux accepts namespace-local CAP_SYS_ADMIN for several host-l…
Linux security problems rarely stay in one place. An authentication issue can lead to unexpected privilege. A container problem can reach the host. Missing log…
Linux security no longer lives on one server.
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced pers…
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.The vulnerability, tracked as CVE-2026-58231, …
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale.DNS threat inte…
Two fixes posted August 13 correct separate per-CPU map failures on Linux systems whose logical CPU IDs contain gaps.
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow priv…
Border Gateway Protocol (BGP) is still trust-based. In the past, a router would announce it originated a block of address space, and its neighbors would take t…
A Linux security tool can catch a system call and still record the wrong thing.
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.