Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities

Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers

A newly discovered critical security flaw in legacy D-Link DSL gateway routers has come under active exploitation in the wild.The vulnerability, tracked as CVE…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Red Team Blue Team Insights for Linux Admins: Key Security Roles Explained

If you manage Linux systems long enough, you start to notice that most security conversations are not really about attackers or tools. They are about pressure.…

Linux Windows

The Hacker News
The Hacker News Vulnerabilities

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to ex…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

MongoDB 8.2: Memory Leak Risk CVE-2025-14847 Critical Exploit

MongoBleed, tracked as CVE-2025-14847, is a high-severity flaw in MongoDB that allows unauthenticated attackers to read small pieces of a server's memory. In s…

Databases

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

MongoBleed MongoDB Memory Leak Under Active Exploitation Distros Lag on Updates

MongoBleed, tracked as CVE-2025-14847, is a high-severity flaw in MongoDB that allows unauthenticated attackers to read small pieces of a server's memory. In s…

Databases

The Hacker News
The Hacker News Breaches & leaks

ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories

The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defende…

Apple

The Hacker News
The Hacker News Breaches & leaks

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances ident…

Databases

The Hacker News
The Hacker News Breaches & leaks

Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In Au…

GitHub

The Hacker News
The Hacker News Vulnerabilities

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large langua…

The Hacker News
The Hacker News Vulnerabilities

ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories

It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking every…

Docker

The Hacker News
The Hacker News Vulnerabilities

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS SSL VPN in the wild under certain configurations.The vulnerab…

Fortinet VPN

The Hacker News
The Hacker News Vulnerabilities

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Kno…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

CISSP: Bridging Linux Security and Organizational Compliance Needs

Linux security professionals spend most of their time on concrete problems. Hardening SSH. Configuring SELinux or AppArmor. Building secure CI/CD pipelines. Ma…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

SNMP: CACTI Command Execution Risk Advisory for Linux Administrators

A recent command-execution flaw in the CACTI monitoring framework underscores a broader risk that keeps repeating. SNMP is routinely treated as passive plumbin…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

When Monitoring Turns Risky: SNMP Exposure in Linux Infrastructure

A recent command-execution flaw in the CACTI monitoring framework underscores a broader risk that keeps repeating. SNMP is routinely treated as passive plumbin…

Linux

The Hacker News
The Hacker News Vulnerabilities

WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

WatchGuard has released fixes to address a critical security flaw in Fireware OS that it said has been exploited in real-world attacks.Tracked as CVE-2025-1473…

VPN

The Hacker News
The Hacker News Breaches & leaks

Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances

Cisco has alerted users to a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent thr…

Cisco

The Hacker News
The Hacker News Breaches & leaks

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

Threat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public disclosure.Cybersecurity co…

Fortinet

The Hacker News
The Hacker News Vulnerabilities

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

The security vulnerability known as React2Shell is being exploited by threat actors to deliver malware families like KSwapDoor and ZnDoor, according to finding…

Linux Palo Alto

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

React2Shell RCE: Critical Host Compromise Vulnerability Exploit 2025-55182

React2Shell is a server-side vulnerability that turns a normal web request into code execution. It allows unauthenticated remote code execution, without creden…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

React2Shell: How a Framework Bug Drives Full Linux Compromise

React2Shell is a server-side vulnerability that turns a normal web request into code execution. It allows unauthenticated remote code execution, without creden…

Linux

The Hacker News
The Hacker News Vulnerabilities

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that it sai…

Apple Chrome

The Hacker News
The Hacker News Vulnerabilities

New React RSC Vulnerabilities Enable DoS and Source Code Exposure

The React team has released fixes for two new types of flaws in React Server Components (RSC) that, if successfully exploited, could result in denial-of-servic…

The Hacker News
The Hacker News Vulnerabilities

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliv…

Linux