Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
How to Review Linux Security Boundaries: Three Kernel Examples

A Linux security review can find a check, a lock, or a safe-looking range and still miss the failure.

Linux

The Hacker News
The Hacker News Breaches & leaks
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems

San Francisco, USA, 29th September 2026, CyberNewswireSalmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Syste…

The Hacker News
The Hacker News
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed Phant…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
GitLab Patches Critical CI/CD Flaws That Can Run Code on Servers

Two critical GitLab flaws can turn authenticated continuous integration and delivery (CI/CD) configuration into code execution on self-managed servers.

GitLab

The Hacker News
The Hacker News Vulnerabilities
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real serv…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Linux eBPF Security Fixes Stop Interpreter Paths From Changing During Program Launch

Two Linux fixes show how extended Berkeley Packet Filter (eBPF) security can fail when mutable map data crosses into the exec path, where Linux starts a progra…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Linux GPU Security Fix Prevents Stale Mappings Across Containers

A Linux GPU security fix changes how AMD’s Kernel Fusion Driver (KFD) tracks shared mappings when several containers use one device.

Linux Docker

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Linux KVM Security Fixes Close Memory Isolation Gaps in Protected Virtual Machines

A new arm64 Kernel-based Virtual Machine (KVM) merge tightens two ordinary-looking mechanisms with major security weight: page mappings for protected-hyperviso…

Linux

The Hacker News
The Hacker News Vulnerabilities
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the e…

The Hacker News
The Hacker News
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy ha…

Android

The Hacker News
The Hacker News Vulnerabilities
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is th…

Citrix

The Hacker News
The Hacker News Breaches & leaks
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-a…

The Hacker News
The Hacker News
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received thre…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Linux Patch Management For Enterprises: A Complete Guide

Linux is not a standard environment. An enterprise can run many different flavors of Linux on its servers, desktops and specialized systems, each with its own …

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
A Linux eBPF Trampoline Can Outlive the Program It Calls

A Linux eBPF security race can leave generated kernel code pointing at a BPF program after that program’s memory has been released.

Linux

The Hacker News
The Hacker News Breaches & leaks
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised dur…

GitHub

The Hacker News
The Hacker News
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chai…

Apple

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Kubernetes Security Fix Blocks Cross-Namespace Pod Creation

Kubernetes released fixes on Sep 23, 2026 for a control-plane flaw that could create a pod outside the namespace where a user's permissions applied. CVE-2026-2…

Kubernetes

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles
Linux Console Font Bug Could Read Past Its Memory Buffer

A Linux console font change could leave the framebuffer console with a buffer sized for 256 characters even after a 512-character font was installed.

Linux

The Hacker News
The Hacker News
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a …

Windows

The Hacker News
The Hacker News Vulnerabilities
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new gl…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
MCP Toolbox Flaw Could Expose Google Service Tokens

A September 23 advisory describes a flaw in the Python SDK used with MCP Toolbox: a shared cache could send a Google ID token to a service it was not meant for.

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Emacs Security Flaw Could Run Code From an Untrusted File

A September 22 advisory on an Emacs vulnerability says opening a crafted file could run code on the reader's computer, even with the editor's default settings.