The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A GitHub Enterprise Server security fix addresses a way to turn the appliance's notebook viewer into a route to its own internal services.
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are …
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on Septembe…
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is …
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through…
Seccomp limits which Linux system calls a process can make.
Privilege escalation in a container does not always begin with a new exploit.
Linux containers can be paused, checkpointed, and rebuilt later with CRIU.
A container normally starts under the security rules of the system receiving it.
Kubernetes groups one or more containers into a pod, the basic unit it deploys.
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers i…
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financi…
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indi…
Security researchers have shown how hidden instructions in an AWS AgentCore support ticket could push an AI agent into running commands as root and exposing a …
The crun container runtime has changed how GPU-enabled workloads launch a key graphics helper.
Linux developers have fixed an SELinux flaw that could allow a program to make a mapped file executable after SELinux had blocked direct execution.
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial acc…
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity ev…
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnera…
Most administrators do not think about BIND, browser engines, or cloud kernels until one of them fails.
A Linux eBPF security flaw could cause the kernel to approve a program using an incorrect understanding of the values it would process.
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artifici…
Security researcher Sai Teja Erukude disclosed four alarming Python security flaws between June and August 2026 after combining specialized AI models with auto…