Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

LiteLLM Key Reuse Lets Internal Users Forge Admin Tokens

LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache HTTP Server Vulnerability Update Fixes Code Execution and Memory Flaws

Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache APISIX Vulnerabilities Let Attackers Impersonate Users and Bypass Protected Routes

Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache APISIX Denial of Service Flaw Can Disrupt Web Traffic

Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache Camel Vulnerability Can Expose Files and Internal Services

Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

LightLLM Profiling Flaw Allows Code Execution Without a Login

LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

ModSecurity Updates Fix WAF Bypasses on Linux Web Servers

ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without be…

Linux

The Hacker News
The Hacker News Breaches & leaks

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organi…

The Hacker News
The Hacker News

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cybe…

The Hacker News
The Hacker News

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure."We are actively addressi…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Flatpak Vulnerability Fixes Protect Linux Host Files and Processes

Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Command Injection Flaw in shell-quote Can Execute Linux Commands

The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.

Linux

The Hacker News
The Hacker News Breaches & leaks

Know Your Enemy: Browser-Based Attack Techniques in 2026

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browse…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux File Truncation Patch Targets Data Loss Beyond the Requested Range

A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Tracing Patch Addresses a Probe Use-After-Free Race

A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

How to Review Linux Security Boundaries: Three Kernel Examples

A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.

Linux

The Hacker News
The Hacker News Breaches & leaks

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses

Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems

San Francisco, USA, 29th September 2026, CyberNewswireSalmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Syste…

The Hacker News
The Hacker News

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed Phant…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers

Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.

GitLab

The Hacker News
The Hacker News Vulnerabilities

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Linux eBPF Security Fixes Stop Interpreter Paths From Changing During Program Launch

Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a progra…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Linux GPU Security Fix Prevents Stale Mappings Across Containers

A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Linux KVM Security Fixes Close Memory Isolation Gaps in Protected Virtual Machines

A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for protected-hyperviso…

Linux