Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and in…

The Hacker News
The Hacker News
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, …

The Hacker News
The Hacker News Breaches & leaks
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without eve…

The Hacker News
The Hacker News Breaches & leaks
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organiza…

Fortinet

The Hacker News
The Hacker News Breaches & leaks
Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organiza…

Fortinet

The Hacker News
The Hacker News Breaches & leaks
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) p…

WordPress

The Hacker News
The Hacker News Breaches & leaks
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called …

The Hacker News
The Hacker News
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Vulnerability Prioritization with Threat Intelligence Insight

A Linux vulnerability scan can create almost as many questions as it answers. The scan may identify dozens of affected packages, several CVEs marked High or Cr…

Linux

The Hacker News
The Hacker News
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation …

The Hacker News
The Hacker News
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targetin…

Linux Windows

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Detecting Persistence on Linux Hosts: A Security Playbook for Cron and systemd

If you manage Linux boxes long enough, you hit this exact wall. You spot a weird process eating CPU, kill it, wipe the script, and reset the user password. You…

Linux

The Hacker News
The Hacker News
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for B…

Windows Microsoft 365

The Hacker News
The Hacker News
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Mak's Weekly Security Roundup: Critical Linux Security Updates Admins Should Know

This week’s most important Linux security updates arrived through vendor advisories rather than major headline-making disclosures.

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Kubernetes Maintainers Expand CSI Path Traversal Fixes Beyond Original Vulnerabilities

Kubernetes maintainers patched two path-traversal vulnerabilities in the NFS and SMB CSI drivers earlier this year. But repository histories show that the secu…

Kubernetes

The Hacker News
The Hacker News Breaches & leaks
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Ninete…

The Hacker News
The Hacker News Breaches & leaks
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Strengthening Linux Cybersecurity in Enterprise Infrastructure

Linux runs cloud platforms, containerized applications, and business-critical servers. It is the engine that powers much of today’s business infrastructure. St…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Choosing the Right Secrets Detection Platform

Not every security incident begins with sophisticated malware or a compromised server. Sometimes it is nothing more than a developer pushing code before the en…

The Hacker News
The Hacker News
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Mic…

Apple

The Hacker News
The Hacker News Vulnerabilities
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane f…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Reducing Attack Surface Without Breaking Production

When people talk about Linux hardening, the conversation often quickly turns to enterprise security platforms, EDR agents, and complex monitoring stacks.

Linux

The Hacker News
The Hacker News Breaches & leaks
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the system…