Stay Informed

Cybersecurity News

Home / News

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities

Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers

A newly discovered critical security flaw in legacy D-Link DSL gateway routers has come under active exploitation in the wild.The vulnerability, tracked as CVE…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities

Red Team Blue Team Insights for Linux Admins: Key Security Roles Explained

If you manage Linux systems long enough, you start to notice that most security conversations are not really about attackers or tools. They are about pressure.…

Linux Windows

The Hacker News
The Hacker News Vulnerabilities

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

A new critical security vulnerability has been disclosed in n8n, an open-source workflow automation platform, that could enable an authenticated attacker to ex…

The Hacker News
The Hacker News

The State of Cybersecurity in 2025:Key Segments, Insights, and Innovations

Featuring:Cybersecurity is being reshaped by forces that extend beyond individual threats or tools. As organizations operate across cloud infrastructure, distr…

The Hacker News
The Hacker News

Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act

Ilya Lichtenstein, who was sentenced to prison last year for money laundering charges in connection with his role in the massive hack of cryptocurrency exchang…

The Hacker News
The Hacker News

New VVS Stealer Malware Targets Discord Accounts via Obfuscated Python Code

Cybersecurity researchers have disclosed details of a new Python-based information stealer called VVS Stealer (also styled as VVS $tealer) that's capable of ha…

Palo Alto

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Open Source vs Commercial Email Security: Operational Choices and Risks

Email still looks like plumbing until it becomes the incident timeline, which is why the enterprise email security decision tends to surface only after somethi…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Cloud Security: Addressing Email Issues in Postfix Environments

Perimeter-based email security assumes mail reliably passes a single inspection point. That's how most Linux mail stacks were designed to operate: one choke po…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

MongoDB 8.2: Memory Leak Risk CVE-2025-14847 Critical Exploit

MongoBleed, tracked as CVE-2025-14847, is a high-severity flaw in MongoDB that allows unauthenticated attackers to read small pieces of a server's memory. In s…

Databases

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks

MongoBleed MongoDB Memory Leak Under Active Exploitation Distros Lag on Updates

MongoBleed, tracked as CVE-2025-14847, is a high-severity flaw in MongoDB that allows unauthenticated attackers to read small pieces of a server's memory. In s…

Databases

The Hacker News
The Hacker News

The ROI Problem in Attack Surface Management

Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, a…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

UFW: Efficient Logging Strategies for Enhanced Network Security Monitoring

UFW logging is useful, but the output is easy to misread if you're not used to kernel log lines. Where those logs show up depends on the distro and logging sta…

The Hacker News
The Hacker News

Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign

Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate Google-generated messages by abusi…

Google Cloud

The Hacker News
The Hacker News Breaches & leaks

ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories

The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defende…

Apple

The Hacker News
The Hacker News

Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack

Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for…

GitHub Chrome

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

UFW: Important Hardening Patterns for Long-Lived Linux Servers

UFW rules on long-lived hosts don't fail because the policy is wrong. They fail because changes get applied out of sequence, old rules survive longer than expe…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

NSA: Managing Secure Boot for Linux Against Bootchain Attacks

The NSA's recent guidance on UEFI Secure Boot reflects a shift that's been building for years. Attackers have moved earlier in the boot process, while most def…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Guide to Auditing UFW Firewall Rules on Long-Term Linux Environments

Over time, it's common for the same service to be allowed by more than one rule. An older broad rule may still match traffic first, while newer, more restricti…

Linux

The Hacker News
The Hacker News

Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware

The threat actor known as Silver Fox has turned its focus to India, using income tax-themed lures in phishing campaigns to distribute a modular remote access t…

The Hacker News
The Hacker News Breaches & leaks

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances ident…

Databases

The Hacker News
The Hacker News

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

Cybersecurity researchers have disclosed details of what has been described as a "sustained and targeted" spear-phishing campaign that has published over two d…

The Hacker News
The Hacker News Breaches & leaks

Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In Au…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles

Exploring AI Agents' Influence on Linux Security Threats and Administration

AI didn't invent hacking, and it didn't make attackers smarter. It removed friction. Tasks that once required patience, focus, and a fair amount of context now…

Linux

The Hacker News
The Hacker News Breaches & leaks

Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code

Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a "security incident" that led to the l…

Chrome