The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without be…
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organi…
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cybe…
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure."We are actively addressi…
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.
The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browse…
A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.
A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.
A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT…
San Francisco, USA, 29th September 2026, CyberNewswireSalmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Syste…
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed Phant…
Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…
Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a progra…
A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.
A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for protected-hyperviso…