Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
How the Bing Images RCE Flaws Actually Worked, and How to Check Your Own Pipeline

A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain and a checklist for anyone running a…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
How the Fastjson RCE Vulnerability Actually Works, and How to Check You’re Exposed

A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Email Spoofing Techniques That Bypass Human Detection

You've probably trained your team to look for red flags. Odd sender names, urgent language, mismatched links. But a well-crafted spoofed email won't trip any o…

The Hacker News
The Hacker News
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base…

Windows

The Hacker News
The Hacker News Vulnerabilities
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applica…

The Hacker News
The Hacker News Breaches & leaks
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an acti…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Kubernetes Storage Flaws Expose a Dangerous Security Blind Spot

Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts …

Kubernetes

The Hacker News
The Hacker News
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that …

The Hacker News
The Hacker News
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operator…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Logging Strategies for Maximizing Security Visibility

A Linux server can be fully patched, hardened, and compliant, yet still leave investigators unable to explain how an attacker got in. Without reliable Linux lo…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Alerts
Mak’s Weekly Security Roundup: Linux Security Updates, Priorities, and Risk

A large volume of Linux security updates and advisories this week across major distributions once again, but it wasn't just the volume that was the story. Wher…

Linux

The Hacker News
The Hacker News Breaches & leaks
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, f…

Windows Cisco Chrome

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
CISA KEV vs. NVD: How Linux Teams Should Prioritize Vulnerabilities That Actually Matter

Most Linux teams don't struggle to find vulnerabilities anymore. They struggle to decide which ones deserve attention first. Between daily scanner results, ven…

Linux

The Hacker News
The Hacker News Vulnerabilities
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, wh…

Chrome

The Hacker News
The Hacker News
The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives secu…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
GNOME Cuts Vulnerability Disclosure Window to 30 Days

GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Lin…

Linux

The Hacker News
The Hacker News Vulnerabilities
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's desi…

The Hacker News
The Hacker News Breaches & leaks
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) …

Palo Alto

The Hacker News
The Hacker News Vulnerabilities
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) m…

The Hacker News
The Hacker News Vulnerabilities
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no explo…

The Hacker News
The Hacker News Breaches & leaks
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this mont…

The Hacker News
The Hacker News
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or…

GitHub

The Hacker News
The Hacker News
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, …

Windows

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Gitea 1.27 Delivers 45 Security Fixes for Self-Hosted Git Servers

For organizations that run a self-hosted Git platform, it’s no longer just about hosting static code repositories. Today, Git servers are responsible for deplo…