The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The maintainers of the nx build system have alerted users to a supply chain attack that allowed attackers to publish malicious versions of the popular npm pack…
Imagine this scenario: you're managing Linux servers that host critical applications, where uptime is everything and security is non-negotiable. You're diligen…
The financially motivated threat actor known as Storm-0501 has been observed refining its tactics to conduct data exfiltration and extortion attacks targeting …
Cybersecurity company ESET has disclosed that it discovered an artificial intelligence (AI)-powered ransomware variant codenamed PromptLock.Written in Golang, …
Cybersecurity company ESET has disclosed that it discovered an artificial intelligence (AI)-powered ransomware variant codenamed PromptLock.Written in Golang, …
Anthropic on Wednesday revealed that it disrupted a sophisticated operation that weaponized its artificial intelligence (AI)-powered chatbot Claude to conduct …
Docker containers are supposed to provide a safe boundary''a virtual sandbox separating workloads from the host machine. When that boundary gets breached, we'r…
Containers were never just a convenience''they were a promise. A promise of isolation, security, and the ability to run workloads in confined, controlled envir…
Small and medium-sized businesses (SMBs) can’t afford to take a hit when it comes to security. And many SMBs rely on Linux to keep their servers and other appl…
A team of academics has devised a novel attack that can be used to downgrade a 5G connection to a lower generation without relying on a rogue base station (gNB…
Cybersecurity researchers are calling attention to a sophisticated social engineering campaign that's targeting supply chain-critical manufacturing companies w…
A new large-scale campaign has been observed exploiting over 100 compromised WordPress sites to direct site visitors to fake CAPTCHA verification pages that em…
Cybersecurity researchers have discovered a new variant of an Android banking trojan called HOOK that features ransomware-style overlay screens to display exto…
Google has announced plans to begin verifying the identity of all developers who distribute apps on Android, even for those who distribute their software outsi…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws impacting Citrix Session Recording and Git to its Known E…
Docker has released fixes to address a critical security flaw affecting the Docker Desktop app for Windows and macOS that could potentially allow an attacker t…
If you've tried pulling files from Arch's main site, hit the AUR, or popped into their forums recently, then you've probably noticed things are off. Maybe you …
Security Information and Event Management (SIEM) systems act as the primary tools for detecting suspicious activity in enterprise networks, helping organizatio…
Cybersecurity researchers have discovered a malicious Go module that presents itself as a brute-force tool for SSH but actually contains functionality to discr…
There's a new tool of mischief in the Linux cybersecurity world, and it's not just a cause for concern''it's quite the wake-up call. ''RingReaper'' isn't your …
There's a new tool of mischief in the Linux cybersecurity world, and it's not just a cause for concern''it's quite the wake-up call. ''RingReaper'' isn't your …
If you've worked with Tails OS before, you already know it's not just another privacy-focused Linux distro ''it's the go-to for anonymous computing. Now, with …
Cybersecurity researchers have shed light on a novel attack chain that employs phishing emails to deliver an open-source backdoor called VShell.The "Linux-spec…
Cybersecurity researchers are calling attention to malicious activity orchestrated by a China-nexus cyber espionage group known as Murky Panda that involves ab…