Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

How Container Restore Can Reopen Privilege Escalation Paths

Privilege escalation in a container does not always begin with a new exploit.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

What CRIU Restores Beyond Application Memory in Linux Containers

Linux containers can be paused, checkpointed, and rebuilt later with CRIU.

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Why Container Security Needs a Separate Restore Boundary

A container normally starts under the security rules of the system receiving it.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CRI-O Restore Flaw Can Bypass Kubernetes Security Policies

Kubernetes groups one or more containers into a pod, the basic unit it deploys.

Docker Kubernetes

The Hacker News
The Hacker News Breaches & leaks

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers i…

The Hacker News
The Hacker News

DORA Year Two: Can Your SOC Actually See the Attack?

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financi…

The Hacker News
The Hacker News

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indi…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Researchers Show How Prompt Injection Could Expose AWS AgentCore Credentials

Security researchers have shown how hidden instructions in an AWS AgentCore support ticket could push an AI agent into running commands as root and exposing a …

AWS

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

crun Tightens GPU Security for Containers Running in MicroVMs

The crun container runtime has changed how GPU-enabled workloads launch a key graphics helper.

Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Fix SELinux Overlays Important Security Contexts 401610

Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.

Linux

The Hacker News
The Hacker News Breaches & leaks

Identity Visibility in 2026: The Foundation of Identity Security

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial acc…

The Hacker News
The Hacker News

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity ev…

The Hacker News
The Hacker News Breaches & leaks

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September…

GitHub

The Hacker News
The Hacker News Vulnerabilities

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Security Roundup: Patch BIND, Browsers, and Cloud Kernels First

Most administrators do not think about BIND, browser engines, or cloud kernels until one of them fails.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux eBPF Security Flaw Could Approve an Out-of-Bounds Memory Access

A Linux eBPF security flaw could cause the kernel to approve a program using an incorrect understanding of the values it would process.

Linux

The Hacker News
The Hacker News Breaches & leaks

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artifici…

Android

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Security Researcher Uses AI to Find Four Python Code-Execution Flaws

Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with auto…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CISA Warns of Active Attacks on a Critical Cisco ISE Flaw

Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 o…

Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Red Hat Quay Build Workflow Could Expose Registry Credentials

As of September 17, Red Hat had documented a flaw in a Red Hat Quay build workflow that could expose container registry credentials to code retrieved from a mu…

Linux Docker GitHub

The Hacker News
The Hacker News Vulnerabilities

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere e…

Docker Apple

The Hacker News
The Hacker News Breaches & leaks

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based ut…

The Hacker News
The Hacker News Vulnerabilities

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wedn…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Docker Sandboxes Flaw Lets a Guest Reach Host Unix Sockets

Docker has fixed a high-severity Docker Sandboxes vulnerability that allowed a malicious guest to redirect a host-side relay toward Unix sockets outside its au…

Docker