Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Record
The Record Alerts

Cyber experts call on CISA to create mandatory federal OT rules

The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, whi…

The Hacker News
The Hacker News Breaches & leaks

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active…

Fortinet VPN

BleepingComputer
BleepingComputer Vulnerabilities

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.…

BleepingComputer
BleepingComputer Vulnerabilities

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted …

DataBreaches.net
DataBreaches.net Alerts

CISA to keep cyber pay incentives, but less staff will qualify

Justin Doubleday reports: The Cybersecurity and Infrastructure Security Agency is continuing to offer cyber pay incentives to retain skilled technical staff, b…

The Record
The Record Vulnerabilities

US, Australia warn of latest Citrix vulnerability after NetScaler advisory

Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem wa…

Citrix

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache Camel Vulnerability Can Expose Files and Internal Services

Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …

Apache

The Hacker News
The Hacker News Vulnerabilities

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

MCP Toolbox Flaw Could Expose Google Service Tokens

A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Emacs Security Flaw Could Run Code From an Untrusted File

A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.

The Hacker News
The Hacker News Vulnerabilities

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CISA Warns of Active Attacks on a Critical Cisco ISE Flaw

Attackers are exploiting a critical Cisco ISE flaw that can open the product’s web management interface without a valid login. Cisco disclosed CVE-2026-76460 o…

Cisco

The Hacker News
The Hacker News Vulnerabilities

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere e…

Docker Apple

The Hacker News
The Hacker News Vulnerabilities

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wedn…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Advisory Timer Vulnerabilities Leading to Use-After-Free Issues

A proposed Linux repair addresses two timer bugs that can trigger use-after-free conditions while one program replaces itself with another through exec(). Both…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CISA Flags Exploited Kestra Flaw That Lets Attackers Run Commands in Linux Containers

A newly confirmed Kestra vulnerability is being exploited in the wild. CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on Sep 2, 2026,…

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts

Linux Kernel BPF Disassembler Out-of-Bounds Access Advisory Alert

Linux kernel fuzzing service syzbot has reported an out-of-bounds array access in print_bpf_insn(), a routine used to turn BPF instructions into readable verif…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts

eBPF Security Logs May Show the Wrong File or Command, New Study Warns

A Linux security tool can catch a system call and still record the wrong thing.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts

Mak's Weekly Security Roundup: Critical Linux Security Updates Admins Should Know

This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts

Linux Kernel Updates Privilege Escalation Provisioning July 28 2026

The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broade…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts

Mak's Weekly Security Roundup: Linux Security Priorities This Week

The volume of Linux security advisories remains high across enterprise distributions, but the more difficult task is determining which updates carry the broade…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities

Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511

A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch.Pu…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts

Mak’s Weekly Security Roundup: Linux Security Updates, Priorities, and Risk

A large volume of Linux security updates and advisories this week across major distributions once again, but it wasn't just the volume that was the story. Wher…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CISA KEV vs. NVD: How Linux Teams Should Prioritize Vulnerabilities That Actually Matter

Most Linux teams don't struggle to find vulnerabilities anymore. They struggle to decide which ones deserve attention first. Between daily scanner results, ven…

Linux