The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to tou…
AI coding assistants have become a staple in many Linux developers' daily workflows. Whether you're generating boilerplate, refactoring code, or updating confi…
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of…
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead.That is the finding in a p…
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The …
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules …
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that…
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps t…
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.The …
Linux runs a huge portion of today's infrastructure because it gives administrators an unusual amount of control over the system. That control extends to netwo…
Linux runs a huge portion of today's infrastructure because it gives administrators an unusual amount of control over the system. That control extends to netwo…
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet…
Adobe frames the fast exploitation of its ColdFusion vulnerabilities as an attacker speed problem. The real issue is a connector that never should have trusted…
A critical flaw in Gitea's official Docker image let anyone impersonate an admin with one forged header. Sysdig spotted the first exploitation attempts 13 days…
One of the easiest mistakes to make in detection engineering is assuming a rule keeps working simply because nobody has touched it. Most of the time, nobody re…
We often view OpenSSH security updates through the lens of standard patch management. When a new CVE hits, we scramble to update, check our versions, and retur…
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritat…
Google has replaced Android's 1,800-guess lockscreen limit with a 20-attempt hard cap. Here is how the new rate limiter works and what it means for anyone test…
Toronto, Canada, 6th July 2026, CyberNewswireInsignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk on Latest Hacking News | Cyber Se…
Linux security teams are drowning. Patches, kernel updates, new CVEs every week. SSH exposed here, an old web service there, and a forgotten cron job running a…
Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, twe…
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use i…
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new…
A practitioner's breakdown of the CSRF attack: how the forged request works, two documented exploits, a manual test, and the fixes that hold up.CSRF Attack Exp…