The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Cybersecurity researchers have flagged a malicious package on the Python Package Index (PyPI) repository that claims to offer the ability to create a SOCKS5 pr…
Cybersecurity researchers have discovered two new malicious packages in the Python Package Index (PyPI) repository that are designed to deliver a remote access…
The threat actor known as Silver Fox has been attributed to abuse of a previously unknown vulnerable driver associated with WatchDog Anti-malware as part of a …
Cybersecurity researchers have discovered a malicious npm package that comes with stealthy features to inject malicious code into desktop apps for cryptocurren…
Docker has released fixes to address a critical security flaw affecting the Docker Desktop app for Windows and macOS that could potentially allow an attacker t…
The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads.Trustwave S…
Zoom and Xerox have addressed critical security flaws in Zoom Clients for Windows and FreeFlow Core that could allow privilege escalation and remote code execu…
Cybersecurity researchers have uncovered multiple security flaws in Dell's ControlVault3 firmware and its associated Windows APIs that could have been abused b…
Cybersecurity researchers have discovered a set of 11 malicious Go packages that are designed to download additional payloads from remote servers and execute t…
Threat hunters have disclosed two different malware campaigns that have targeted vulnerabilities and misconfigurations across cloud environments to deliver cry…
Let's face it: threat actors are getting smarter, and malware isn't just for your typical Windows clickbait anymore. In recent years, the H2Miner botnet has go…
For a long time, Linux carried an aura of impenetrable security. It was the backbone of choice for enterprise workloads, revered for its reliability, open-sour…
Governmental organizations in Southeast Asia are the target of a new campaign that aims to collect sensitive information by means of a previously undocumented …
Cryptocurrency users are the target of an ongoing social engineering campaign that employs fake startup companies to trick users into downloading malware that …
Ransomware is nothing new to us as Linux admins and infosec folks''it's pretty much part of the modern threat landscape now. But when I say "BERT ransomware," …
You know how it goes''Linux admins have long prided themselves on running systems that ransomware gangs mostly ignored. Sure, the occasional attack would trick…
Enterprise environments power everything from development machines and servers to kiosks and IoT devices. However, managing these endpoints, especially across …
Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory inter…
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information. CVE-2025-4673. os: inconsiste…
Disallowing use of the arcfour-hmac(-md5) encryption type for session keys Add support for the PKINIT paChecksum2 sequence, required for Active Directory inter…
Ransomware has been making life miserable for IT folks for years now, and you've probably heard plenty about how it hits Windows systems . But Linux? Yeah, tha…
If you've been staring at an aging Windows 10 PC that's slowed to a crawl, you might be feeling a little stuck. Do you give in and replace your perfectly funct…
A sprawling operation undertaken by global law enforcement agencies and a consortium of private sector firms has disrupted the online infrastructure associated…
For years, Windows Subsystem for Linux (WSL) has closed the gap between Windows and Linux ecosystems. It's used by developers, engineers, and system administra…