חדשות האבטחה החשובות, בהסבר הצוות שלנו — עם הצעדים המעשיים שיש לנקוט.
נאספים כל שעתיים מפרסומים מקצועיים — כל קישור מוביל למאמר המקורי.
עדיין אין חדשות בשפתכם — הנה הסיקור שלנו באנגלית:
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks…
Lee Hyo-jin reports: President Lee Jae Myung on Sunday ordered a thorough investigation into a string of recent data breaches at financial institutions, as art…
The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3. On October 2, Kairos threat acto…
The following is a machine translation of a press release by Italy’s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The…
Jana Winter, Raphael Satter, and A.J. Vicens report: A key member of the ShinyHunters hacking group, which claims to have stolen data on every FBI employee, w…
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in att…
Justin Doubleday reports: The Department of Homeland Security is preparing this year to award a major cloud, cybersecurity and network services contract aimed …
Featuring:Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As …
LiteLLM has patched a privilege-escalation flaw that can let an authenticated internal user forge an administrative session and reach command-execution feature…
Apache released HTTP Server 2.4.69 on October 1, 2026, to fix security faults ranging from unwanted code execution to mishandled web responses.
Apache detailed two Apache APISIX vulnerabilities in notices issued on October 1, 2026.
Apache disclosed CVE-2026-94250 on October 1, 2026, warning that public access to a batch-request endpoint can let an attacker exhaust a gateway worker's memor…
Apache's September 30, 2026 advisory, CVE-2026-88789, warns that an XML document can make an affected Camel Quarkus application read files or contact internal …
LightLLM, software used to serve AI models, can expose Linux AI servers to remote code execution when operators enable its profiling mode, a tool for measuring…
ModSecurity has released fixes for a group of web application firewall (WAF) weaknesses that can let dangerous input reach Linux-hosted applications without be…
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organi…
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cybe…
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure."We are actively addressi…
Flatpak 1.18.4 fixes three vulnerabilities that could let a malicious sandboxed app affect files or processes on its Linux host.
The maintainers of shell-quote, a JavaScript library for building shell commands, released version 1.11.0 on September 29, 2026, to fix CVE-2026-102422.
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browse…
A Linux patch series addresses how file truncation or hole punching could discard valid data beyond the range an application asked to remove.
A proposed Linux tracing patch addresses a race that could free a function probe while its return callback is still using it.
A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.