The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The 2025 cybersecurity landscape is increasingly complex, driven by sophisticated cyber threats, increased regulation, and rapidly evolving technology. In 2025…
A dual Russian and Israeli national has been charged in the United States for allegedly being the developer of the now-defunct LockBit ransomware-as-a-service …
Linux security admins must be wary of an emerging and dangerous threat: the cShell DDoS bot malware. Recently discovered by researchers at ASEC, this sophistic…
Open-source data and intelligence availability have partly enabled legal and illegal actions. These resources leverage public data to address cyber threats whi…
In recent months, serious vulnerabilities have been discovered in widely used TP-Link routers including Archer and Deco models . These flaws, CVE-2024-21833 an…
The Lazarus Group, an infamous threat actor linked to the Democratic People's Republic of Korea (DPRK), has been observed leveraging a "complex infection chain…
The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that al…
A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remot…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA…
Threat actors have been observed uploading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node that have racked up thousa…
In recent months, Linux security administrators and WordPress site owners have encountered a formidable adversary: MUT-1244 . This threat actor has been unleas…
Attention Linux administrators and Python developers! A crucial security alert regarding a high-severity vulnerability, CVE-2024-12254 , has just been issued, …
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 25-01, ordering federal civilian agencies to se…
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed that a threat actor it tracks as UAC-0125 is leveraging Cloudflare Workers service to t…
We Linux security admins have a new challenge on our hands: it was recently discovered that Qualcomm Snapdragon X Plus and Elite processors - found in laptops,…
Keeping WordPress secure can be challenging, especially when considering Linux security concerns in a typical LAMP stack setup. Most WordPress security issues …
If you're an admin responsible for managing and securing one or more Linux systems, you already know the importance of having top-notch tools at your disposal.…
BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to…
Did you know that 43.1% of websites on the Internet run on WordPress, according to W3Techs? Most WordPress websites run on Linux servers, which makes them prim…
A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate."An attacker used soci…
Wordfence security researchers recently shed light on an infamous supply chain attack that may have affected as many as 36,000 WordPress websites. Five widely …
We Linux security admins have a new challenge on our hands: several Qualcomm processors/SoCs are still vulnerable to Spectre-related attacks . Despite its prom…
Streaming on Linux can be an exhilarating experience, but it also comes with its own set of cybersecurity challenges. The risks are real, from DDoS attacks tha…
A suspected South Asian cyber espionage threat group known as Bitter targeted a Turkish defense sector organization in November 2024 to deliver two C++-malware…