The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A newly discovered critical security flaw in legacy D-Link DSL gateway routers has come under active exploitation in the wild.The vulnerability, tracked as CVE…
If you manage Linux systems long enough, you start to notice that most security conversations are not really about attackers or tools. They are about pressure.…
A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to ex…
Featuring:Cybersecurity is being reshaped by forces that extend beyond individual threats or tools. As organizations operate across cloud infrastructure, distr…
Ilya Lichtenstein, who was sentenced to prison last year for money laundering charges in connection with his role in the massive hack of cryptocurrency exchang…
Cybersecurity researchers have disclosed details of a new Python-based information stealer called VVS Stealer (also styled as VVS $tealer) that's capable of ha…
Email still looks like plumbing until it becomes the incident timeline, which is why the enterprise email security decision tends to surface only after somethi…
Perimeter-based email security assumes mail reliably passes a single inspection point. That's how most Linux mail stacks were designed to operate: one choke po…
MongoBleed, tracked as CVE-2025-14847, is a high-severity flaw in MongoDB that allows unauthenticated attackers to read small pieces of a server's memory. In s…
MongoBleed, tracked as CVE-2025-14847, is a high-severity flaw in MongoDB that allows unauthenticated attackers to read small pieces of a server's memory. In s…
Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, a…
UFW logging is useful, but the output is easy to misread if you're not used to kernel log lines. Where those logs show up depends on the distro and logging sta…
Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate Google-generated messages by abusi…
The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defende…
Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for…
UFW rules on long-lived hosts don't fail because the policy is wrong. They fail because changes get applied out of sequence, old rules survive longer than expe…
The NSA's recent guidance on UEFI Secure Boot reflects a shift that's been building for years. Attackers have moved earlier in the boot process, while most def…
Over time, it's common for the same service to be allowed by more than one rule. An older broad rule may still match traffic first, while newer, more restricti…
The threat actor known as Silver Fox has turned its focus to India, using income tax-themed lures in phishing campaigns to distribute a modular remote access t…
A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances ident…
Cybersecurity researchers have disclosed details of what has been described as a "sustained and targeted" spear-phishing campaign that has published over two d…
In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In Au…
AI didn't invent hacking, and it didn't make attackers smarter. It removed friction. Tasks that once required patience, focus, and a fair amount of context now…
Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a "security incident" that led to the l…