Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

OpenSSL Vulnerability Can Leak Server Memory Through DTLS

OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.

OpenSSL

BleepingComputer
BleepingComputer Vulnerabilities

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and r…

The Record
The Record Vulnerabilities

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…

Citrix

BleepingComputer
BleepingComputer Vulnerabilities

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.…

The Hacker News
The Hacker News Breaches & leaks

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep fi…

Citrix Fortinet

BleepingComputer
BleepingComputer Vulnerabilities

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.…

BleepingComputer
BleepingComputer Vulnerabilities

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks…

Citrix

The Hacker News
The Hacker News Breaches & leaks

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in att…

Microsoft 365

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache Camel Vulnerability Can Expose Files and Internal Services

Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

LightLLM Profiling Flaw Allows Code Execution Without a Login

LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Command Injection Flaw in shell-quote Can Execute Linux Commands

The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux File Truncation Patch Targets Data Loss Beyond the Requested Range

A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Tracing Patch Addresses a Probe Use-After-Free Race

A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.

Linux

The Hacker News
The Hacker News Breaches & leaks

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers

Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.

GitLab

The Hacker News
The Hacker News Vulnerabilities

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…

The Hacker News
The Hacker News Vulnerabilities

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the e…

The Hacker News
The Hacker News Vulnerabilities

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is th…

Citrix

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Patch Management For Enterprises: A Complete Guide

Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own …

Linux