The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to ach…
Security researchers have disclosedFence2Pwn, a new Linux kernel exploitation technique that uses KFENCE’s alternate memory-allocation path to bypass protectio…
A disclosure posted to the oss-security mailing list on August 16, 2026, reports that OpenZFS on Linux accepts namespace-local CAP_SYS_ADMIN for several host-l…
Linux security problems rarely stay in one place. An authentication issue can lead to unexpected privilege. A container problem can reach the host. Missing log…
Linux security no longer lives on one server.
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced pers…
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.The vulnerability, tracked as CVE-2026-58231, …
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale.DNS threat inte…
Two fixes posted August 13 correct separate per-CPU map failures on Linux systems whose logical CPU IDs contain gaps.
A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow priv…
Border Gateway Protocol (BGP) is still trust-based. In the past, a router would announce it originated a block of address space, and its neighbors would take t…
A Linux security tool can catch a system call and still record the wrong thing.
Linux Audit can tell defenders that a system call ran while leaving out the setting that explains what the call did.
This week’s Linux security updates cover several areas administrators cannot afford to overlook. Debian, Ubuntu, Fedora, SUSE, openSUSE, and other distribution…
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access tr…
A step-by-step method for finding and proving CORS misconfiguration vulnerabilities: the header checks, the edge cases developers miss, and how to fix them.How…
A proposed Linux kernel patch addresses a private-futex race that a recent security fix left unresolved. Security researcher Hyunwoo Kim found that a rare sequ…
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.The vu…
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernet…
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.…
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.The bug sits in a core Windows kern…
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a b…
Public exploit code is now available for SCTPhantom, a Linux kernel flaw that researchers used to escape an unprivileged container and take control of the unde…
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and in…