Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CUPS Exploit Chain Still Reaches Root Access, Despite 2024 Fixes

The Common Unix Printing System (CUPS) still sits on millions of Linux systems, usually in the background, rarely monitored, and often trusted more than it sho…

Linux

The Hacker News
The Hacker News Breaches & leaks

New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips

New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that could be exploited to escalate p…

The Hacker News
The Hacker News Breaches & leaks

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware

A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to…

The Hacker News
The Hacker News Vulnerabilities

⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More

This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort…

Fortinet Chrome

The Hacker News
The Hacker News Breaches & leaks

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silenc…

Cisco

The Hacker News
The Hacker News Vulnerabilities

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads t…

Databases

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

The npm Supply Chain Problem: Why Installing Packages Executes Untrusted Code

Running npm install is a reflex at this point. You see a progress bar, a few hundred dependencies fly by, and the lockfile updates. You move on to the next tas…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CI/CD Pipelines Vulnerabilities in Trusted Execution Paths March 2026

Time and time again, Linux systems execute attacker-controlled code during normal operation, and nothing in the system reports it as a failure.Security models …

Linux

The Hacker News
The Hacker News Breaches & leaks

Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

Cybersecurity researchers have disclosed a security "blind spot" in Google Cloud's Vertex AI platform that could allow artificial intelligence (AI) agents to b…

Google Cloud Palo Alto

The Hacker News
The Hacker News Breaches & leaks

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new …

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

FortiClient EMS SQL Injection Risk on Linux Systems CVE-2026-21643

One unauthenticated HTTP request is all it takes. From there, attackers can move from the edge straight into your internal network, operating from a system you…

Linux Fortinet

The Hacker News
The Hacker News Vulnerabilities

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks

Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX's pre-publish scanning pipeline to cause the tool to allow a malicious…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

This RCE Flaw Can Expose Your Internal Network Through a Single Linux Server

A single unpatched server opens a path into systems that were never meant to be exposed, and because nothing appears broken, that access can remain in place fo…

Linux

The Hacker News
The Hacker News Vulnerabilities

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR

A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve r…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Linux Vulnerability Could Let Attackers Take Control of Systems and Disrupt Services

There's a Linux vulnerability in systemd affecting several Ubuntu LTS releases.

Linux

The Hacker News
The Hacker News Breaches & leaks

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware cap…

Docker GitHub

The Hacker News
The Hacker News Breaches & leaks

54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security

A new analysis of endpoint detection and response (EDR) killers has revealed that 54 of them leverage a technique known as bring your own vulnerable driver (BY…

The Hacker News
The Hacker News Breaches & leaks

54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security

A new analysis of endpoint detection and response (EDR) killers has revealed that 54 of them leverage a technique known as bring your own vulnerable driver (BY…

The Hacker News
The Hacker News Breaches & leaks

CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra…

Microsoft 365 Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

n8n 1.122.0 Critical RCE Auth Bypass Exploit CVE-2025-68613

n8n (CVE-2025-68613) is an open-source automation tool used to connect APIs, databases, and SaaS apps into workflows. It is commonly used to move data between …

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

The Ni8mare Chain: How n8n RCE Turns Auth Bypass Into Linux Host Compromise

n8n (CVE-2025-68613) is an open-source automation tool used to connect APIs, databases, and SaaS apps into workflows. It is commonly used to move data between …

Linux

The Hacker News
The Hacker News Breaches & leaks

Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access

Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that's exploiting a recently disclosed critical security flaw in Cisco Secure …

AWS Cisco

The Hacker News
The Hacker News Vulnerabilities

Product Walkthrough: How Mesh CSMA Reveals and Breaks Attack Paths to Crown Jewels

Security teams today are not short on tools or data. They are overwhelmed by both. Yet within the terabytes of alerts, exposures, and misconfigurations – secur…

The Hacker News
The Hacker News Vulnerabilities

Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS

Apple on Tuesday released its first round of Background Security Improvements to address a security flaw in WebKit that affects iOS, iPadOS, and macOS.The vuln…

Apple