The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Researchers have devised a new attack strategy “Cookie-Bite” demonstrating cookie theft via malicious browser extensions.…Cookie-Bite Attack Demoes Extension E…
Linux's case-sensitive filesystems have long been seen as essential to the reliability and security of our much-loved OS. Still, recent discussions , led by Li…
VulnCon 2025 , recently held in Raleigh, NC, created a dynamic stage for security professionals and open-source advocates to connect, share, and collaborate on…
ASUS recently patched a vulnerability in routers enabled with AiCloud that could allow executing unauthorized…ASUS Fixed Critical Auth Bypass Vulnerability In …
Cybersecurity researchers have detailed the activities of an initial access broker (IAB) dubbed ToyMaker that has been observed handing over access to double e…
One of the most important responsibilities of any organization's IT team is to make sure that its digital assets are kept secure. Data breaches can result in m…
As security-minded Linux admins, we take pride in the reliability, flexibility, and security of our systems. The recent emergence of the Curing rootkit has bro…
Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to …
Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti…
At least six organizations in South Korea have been targeted by the prolific North Korea-linked Lazarus Group as part of a campaign dubbed Operation SyncHole.T…
The release of MITRE ATT&CK v17 , with the addition of a dedicated matrix for VMware ESXi hypervisors, reflects the growing threat surface in virtualized envir…
Oracle Ksplice is an invaluable tool that fundamentally reshapes how we apply and monitor Linux security patches. Oracle Ksplice's Known Exploit Detection take…
Cybersecurity researchers have detailed a malware campaign that's targeting Docker environments with a previously undocumented technique to mine cryptocurrency…
Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate their privile…
The recently released MX Linux 23.6 is a compelling option for us admins seeking a secure and efficient operating system based on Debian 12.10 "Bookworm." With…
Cybersecurity researchers have flagged a new malicious campaign related to the North Korean state-sponsored threat actor known as Kimsuky that exploits a now-p…
We Linux security administrators face a growing challenge with sophisticated supply chain attacks targeting popular development ecosystems, such as npm. The la…
In a sneaky new supply-chain attack , threat actors have been discovered exploiting package naming conventions to trick unsuspecting developers into installing…
Cybersecurity researchers have disclosed a surge in "mass scanning, credential brute-forcing, and exploitation attempts" originating from IP addresses associat…
The latest round of x86 fixes was recently implemented in Linux 6.15-rc2 as several critical patches to increase mitigation against the Spectre Return Stack Bu…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a medium-severity security flaw impacting Microsoft Windows to its Known Exp…
This past weekend, the globally recognized Common Vulnerabilities and Exposures (CVE) database, essential for tracking security flaws in software and systems, …
This past weekend, the globally recognized Common Vulnerabilities and Exposures (CVE) database, essential for tracking security flaws in software and systems, …
A critical security vulnerability has been disclosed in the Erlang/Open Telecom Platform (OTP) SSH implementation that could permit an attacker to execute arbi…