Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive file…

The Hacker News
The Hacker News Vulnerabilities

What Is Agentic Pentesting? What It Proves, and Where It Stops.

If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, val…

BleepingComputer
BleepingComputer Vulnerabilities

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.…

BleepingComputer
BleepingComputer Breaches & leaks

Advantest confirms personal information stolen in ransomware attack

Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data.…

The Hacker News
The Hacker News Vulnerabilities

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with…

The Hacker News
The Hacker News Breaches & leaks

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript t…

DataBreaches.net
DataBreaches.net Breaches & leaks

Engineer sentenced for locking over 3,000 devices on employer’s network

Sergiu Gatlan has an update on a case previously noted on this site. A former core infrastructure engineer at an industrial company headquartered in New Jersey…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Security Configuration Management: Build a Linux Baseline Your Team Can Maintain

“Which settings are we supposed to use?” is a reasonable question from an administrator building a server.

Linux

BleepingComputer
BleepingComputer Vulnerabilities

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerc…

WordPress

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache Struts Fixes Four Flaws Including Possible Remote Code Execution

Apache published four Struts security notices on October 5, 2026. The fixes are in the new 6.12.0 and 7.4.0 releases.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

SubQuery Supply Chain Attack Targeted Cloud and CI Credentials

An npm package used throughout the SubQuery project was poisoned.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

SELinux NFS Security Update Fixes File Labeling Problems Effectively

On an affected host, a second mount of the same NFSv4 share could alter SELinux label handling on the first.

Linux

BleepingComputer
BleepingComputer Breaches & leaks

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero…

The Hacker News
The Hacker News

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI…

The Hacker News
The Hacker News

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimat…

Linux

BleepingComputer
BleepingComputer Vulnerabilities

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted …

BleepingComputer
BleepingComputer Breaches & leaks

ASOS confirms data breach after “HACKED” in-app notifications

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stole…

The Record
The Record

Alleged ATM malware creator appears in Nebraska court after arrest

Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.

The Record
The Record Breaches & leaks

South Korean officials believe AI agents were used to hack several banks

The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a C…

DataBreaches.net
DataBreaches.net Breaches & leaks

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reute…

BleepingComputer
BleepingComputer

Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authenticati…

The Record
The Record Breaches & leaks

Osaka Metropolitan University cancels classes after suspected ransomware attack

Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.

BleepingComputer
BleepingComputer Vulnerabilities

How to secure RMM software: 8 controls MSPs should test

RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight contro…

The Record
The Record Breaches & leaks

ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infoste…