Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Breaches & leaks
Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim's KakaoTalk desktop application to distribut…

The Hacker News
The Hacker News Breaches & leaks
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Wing FTP to its Known Exploited Vuln…

The Hacker News
The Hacker News Breaches & leaks
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python reposi…

GitHub

The Hacker News
The Hacker News Breaches & leaks
INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime

INTERPOL on Friday announced the takedown of 45,000 malicious IP addresses and servers used in connection with phishing, malware, and ransomware campaigns, as …

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
SocksEscort Linux Router Malware Botnet Takedown Operation Lightning

Authorities have dismantled SocksEscort, a service that sold access to a large proxy network built from compromised residential routers. Investigators say much…

Linux

The Hacker News
The Hacker News Breaches & leaks
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks

Cybersecurity researchers have disclosed details of a suspected artificial intelligence (AI)-generated malware codenamed Slopoly put to use by a financially mo…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Intrusion Detection Systems vs Prevention Systems Snort Overview

Intrusion detection and prevention systems are often treated as interchangeable. IPS is often described as IDS with blocking turned on. That sounds simple, but…

The Hacker News
The Hacker News Breaches & leaks
Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets

Cybersecurity researchers have discovered half-a-dozen new Android malware families that come with capabilities to steal data from compromised devices and cond…

Android

The Hacker News
The Hacker News Breaches & leaks
UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim's clo…

AWS GitHub

The Hacker News
The Hacker News Breaches & leaks
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal se…

Apple

The Hacker News
The Hacker News Breaches & leaks
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft

Two Google Chrome extensions have turned malicious after what appears to be a case of ownership transfer, offering attackers a way to push malware to downstrea…

Chrome

The Hacker News
The Hacker News Breaches & leaks
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor

Cybersecurity researchers have disclosed details of a malicious Go module that's designed to harvest passwords, create persistent access via SSH, and deliver a…

Linux GitHub

The Hacker News
The Hacker News Breaches & leaks
ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks

The North Korean threat actor known as ScarCruft has been attributed to a fresh set of tools, including a backdoor that uses Zoho WorkDrive for command-and-con…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Linux Security in 2026 Hardening Monitoring and Defense Strategies

Linux runs an enormous share of the modern internet - cloud workloads, web backends, containers, routers, IoT devices, and the quiet infrastructure nobody noti…

Linux Docker

The Hacker News
The Hacker News Breaches & leaks
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware

A "coordinated developer-targeting campaign" is using malicious repositories disguised as legitimate Next.js projects and technical assessments to trick victim…

The Hacker News
The Hacker News Breaches & leaks
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware

Cybersecurity researchers have discovered four malicious NuGet packages that are designed to target ASP.NET web application developers to steal sensitive data.…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
What Is Fail2Ban? Using Log-Based Intrusion Prevention to Secure Linux Servers

Open any internet-facing Linux server and check /var/log/auth.log or run journalctl -u ssh. If it has been up for more than a few minutes, you will see it. Rep…

Linux

The Hacker News
The Hacker News Breaches & leaks
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks

The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the…

The Hacker News
The Hacker News Breaches & leaks
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems

In yet another software supply chain attack, the open-source, artificial intelligence (AI)-powered coding assistant Cline CLI was updated to stealthily install…

The Hacker News
The Hacker News Breaches & leaks
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware

Cybersecurity researchers have disclosed details of a new ClickFix campaign that abuses compromised legitimate sites to deliver a previously undocumented remot…

The Hacker News
The Hacker News Breaches & leaks
Identity Cyber Scores: The New Metric Shaping Cyber Insurance in 2026

With one in three cyber-attacks now involving compromised employee accounts, insurers and regulators are placing far greater emphasis on identity posture when …

The Hacker News
The Hacker News Breaches & leaks
Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster

Cloud attacks move fast — faster than most incident response teams.In data centers, investigations had time. Teams could collect disk images, review logs, and …

The Hacker News
The Hacker News Breaches & leaks
Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers

A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks un…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Maintaining DKIM Integrity for Linux-Based Email Servers in Operation

If you run Postfix, Exim, or OpenSMTPD on Linux, DKIM is already your problem. The private key lives on your box. If that key leaks or signing stops, your doma…

Linux