Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications.…

The Hacker News
The Hacker News Vulnerabilities

Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cach…

BleepingComputer
BleepingComputer Breaches & leaks

PoeLLM malware infects exposed AI servers in cryptomining attacks

A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.…

BleepingComputer
BleepingComputer Vulnerabilities

Hackers exploit critical Atlassian flaw after public PoC release

A critical vulnerability (CVE-2026-21589) affecting multiple Atlassian product families, including Jira, Confluence, and Bitbucket, is being exploited in attac…

The Hacker News
The Hacker News Breaches & leaks

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active…

Fortinet VPN

The Hacker News
The Hacker News Vulnerabilities

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive file…

The Hacker News
The Hacker News Vulnerabilities

What Is Agentic Pentesting? What It Proves, and Where It Stops.

If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, val…

BleepingComputer
BleepingComputer Vulnerabilities

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.…

The Hacker News
The Hacker News Vulnerabilities

Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with…

BleepingComputer
BleepingComputer Vulnerabilities

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerc…

WordPress

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache Struts Fixes Four Flaws Including Possible Remote Code Execution

Apache published four Struts security notices on October 5, 2026. The fixes are in the new 6.12.0 and 7.4.0 releases.

Apache

BleepingComputer
BleepingComputer Breaches & leaks

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero…

BleepingComputer
BleepingComputer Vulnerabilities

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted …

DataBreaches.net
DataBreaches.net Breaches & leaks

FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reute…

BleepingComputer
BleepingComputer Vulnerabilities

How to secure RMM software: 8 controls MSPs should test

RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight contro…

DataBreaches.net
DataBreaches.net Breaches & leaks

Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million

Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation: On October 5, 2026, Danish authorities publicly …

The Hacker News
The Hacker News Vulnerabilities

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There…

Apache

The Hacker News
The Hacker News Breaches & leaks

Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful …

The Hacker News
The Hacker News Vulnerabilities

Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

In 2024, MCP (Model Context Protocol) set out to become the USB-C of AI: one standard for connecting models, agents, and IDEs to tools and data. The protocol d…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Kernel Vulnerability Fixed in Binder Device Creation

Linux developers have merged a fix for a Linux kernel vulnerability that can leave Binder device creation writing to memory the kernel has already released.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Citrix NetScaler Vulnerability Is Being Exploited: Check SAML Systems

Citrix has confirmed targeted attacks involving a Citrix NetScaler vulnerability and urged affected customers to update.

Citrix

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

OpenOffice Vulnerability Can Run Code From Malicious Documents

Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Apache Directory LDAP API 2.1.9 Security Update for CVE-2026-103877

Apache’s release notice on Oct 3, 2026 lists six Apache Directory LDAP API vulnerabilities.

Apache

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

OpenSSL Vulnerability Can Leak Server Memory Through DTLS

OpenSSL issued fixes on Sep 29, 2026 for an OpenSSL vulnerability that can send unrelated program memory to another party during secure connection setup.

OpenSSL