The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to…
A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate."An attacker used soci…
We Linux security admins have a new challenge on our hands: several Qualcomm processors/SoCs are still vulnerable to Spectre-related attacks . Despite its prom…
Bogus software update lures are being used by threat actors to deliver a new stealer malware called CoinLurker."Written in Go, CoinLurker employs cutting-edge …
This month marked the release of Microsoft’s last scheduled updates. With the December 2024 Patch…Microsoft December Patch Tuesday Arrived With 70+ Bug Fixes o…
We Linux security admins have a new challenge on our hands: several Qualcomm processors/SoCs are still vulnerable to Spectre-related attacks . Despite its prom…
Cybersecurity researchers have discovered a new PHP-based backdoor called Glutton that has been put to use in cyber attacks targeting China, the United States,…
A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled th…
Game hacking has become a pervasive issue in the gaming industry, testing notions of fairness and redefining how gamers engage with their favorite titles. Desp…
A security flaw has been disclosed in OpenWrt's Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicio…
Attention Linux administrators and Python developers! A crucial security alert regarding a high-severity vulnerability, CVE-2024-12254 , has just been issued, …
A newly devised technique leverages a Windows accessibility framework called UI Automation (UIA) to perform a wide range of malicious activities without tippin…
IBM recently disclosed a critical security vulnerability affecting their Db2 database software on Linux and UNIX platforms, identified as CVE-2024-37071 . This…
Microsoft closed out its Patch Tuesday updates for 2024 with fixes for a total of 72 security flaws spanning its software portfolio, including one that it said…
Ivanti has released security updates to address multiple critical flaws in its Cloud Services Application (CSA) and Connect Secure products that could lead to …
Users of Cleo-managed file transfer software are being urged to ensure that their instances are not exposed to the internet following reports of mass exploitat…
Recently discovered vulnerabilities in OpenWrt , an open-source firmware for routers and embedded devices, have cast light on new network security flaws that a…
Cyber attackers never stop inventing new ways to compromise their targets. That's why organizations must stay updated on the latest threats. Here's a quick run…
A type confusion vulnerability within the Linux Kernel's nftables subsystem - CVE-2024-42070 - was recently discovered, requiring urgent mitigation through ker…
Details have emerged about a now-patched security flaw in the DeepSeek artificial intelligence (AI) chatbot that, if successfully exploited, could permit a bad…
The Linux kernel community recently issued an EOL announcement regarding the 6.11 kernel series, urging sysadmins to upgrade quickly to 6.12 . This announcemen…
As 2025 approaches, we Linux admins are facing new and often unseen cloud-native security obstacles. While skilled at mitigating known risks, emerging vulnerab…
Vulnerability Management (VM) has long been a cornerstone of organizational cybersecurity. Nearly as old as the discipline of cybersecurity itself, it aims to …
Google recently unveiled a critical security update to their popular web browser, Google Chrome, addressing over a dozen significant security vulnerabilities. …