The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Cybersecurity researchers have lifted the veil on a widespread malicious campaign that's targeting TikTok Shop users globally with an aim to steal credentials …
Malware isn’t just trying to hide anymore—it’s trying to belong. We’re seeing code that talks like us, logs like us, even documents itself like a helpful teamm…
WordPress admins need to update their websites with the latest Post SMTP plugin release, as…Post SMTP Plugin Flaw Risked 400K+ WordPress Sites To Hijacking on …
Canadian telecommunication giant Mitel Networks patched serious vulnerabilities across different products. One of these includes…Mitel Fixed Multiple Vulnerabi…
Some of the most devastating cyberattacks don’t rely on brute force, but instead succeed through stealth. These quiet intrusions often go unnoticed until long …
A serious code execution vulnerability threatened the security of Gemini CLI users. Upon detecting the…Google Patched A Code Execution Vulnerability In Gemini …
SonicWall SSL VPN devices have become the target of Akira ransomware attacks as part of a newfound surge in activity observed in late July 2025."In the intrusi…
If you're running servers, maintaining web apps, or just spending a lot of time thinking about the integrity of systems, cross-site scripting (or XSS) probably…
Cybersecurity researchers have flagged a malicious npm package that was generated using artificial intelligence (AI) and concealed a cryptocurrency wallet drai…
The days of straightforward Linux security threats''malware you could spot with a cursory glance at the logs''are fading fast. Meet "Koske," a new breed of mal…
The threat actor linked to the exploitation of the recently disclosed security flaws in Microsoft SharePoint Server is using a bespoke command-and-control (C2)…
Imagine this: you're midway through deploying critical patches on your Linux servers when you notice something strange. Traffic to one of your services spikes …
If you're an admin managing Linux machines, you've got a couple of things on your radar right now. One is CVE-2025-31324, a vulnerability that's got the potent…
Apple on Tuesday released security updates for its entire software portfolio, including a fix for a vulnerability that Google said was exploited as a zero-day …
Threat actors have been observed exploiting a now-patched critical SAP NetWeaver flaw to deliver the Auto-Color backdoor in an attack targeting a U.S.-based ch…
Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:Compromise an endpoint via softw…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperCutNG/MF print managemen…
The notorious cybercrime group known as Scattered Spider is targeting VMware ESXi hypervisors in attacks targeting retail, airline, and transportation sectors …
The threat actor known as Patchwork has been attributed to a new spear-phishing campaign targeting Turkish defense contractors with the goal of gathering strat…
Threat hunters have disclosed two different malware campaigns that have targeted vulnerabilities and misconfigurations across cloud environments to deliver cry…
Microsoft has revealed that one of the threat actors behind the active exploitation of SharePoint flaws is deploying Warlock ransomware on targeted systems.The…
The Windows banking trojan known as Coyote has become the first known malware strain to exploit the Windows accessibility framework called UI Automation (UIA) …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two security flaws impacting SysAid IT support software to its Known Exploited Vulnerabi…
Let's talk straight: if you're running Apache HTTP Server and you haven't checked your version in a while, you might have a problem. An issue that's now pretty…