The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The latest iteration of Kali Linux is here, and while it won't shout for attention, it will make you lean in. Kali 2025.2 quietly reinforces its position as a …
Email security doesn't just happen''it's engineered, tweaked, and refined with every lurking threat on the horizon. Rspamd has long been a trusted tool for Lin…
Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that's capable of harvesting sensitive developer-re…
Cybersecurity researchers from SafeDep and Veracode detailed a number of malware-laced npm packages that are designed to execute remote code and download addit…
When people talk about open-source software, it often comes with a certain level of trust''trust in the community, trust in transparent development, and trust …
Cybersecurity researchers are calling attention to a "large-scale campaign" that has been observed compromising legitimate websites with malicious JavaScript i…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday disclosed that ransomware actors are targeting unpatched SimpleHelp Remote Monitor…
Fingerprint scanners aren't new, but let's be honest''Linux's experience with biometric authentication has historically been a mixed bag. Between a tangled web…
If you've spent any time dealing with Linux in Kubernetes clusters, you know that simplicity is hard to achieve without compromises. Managing nodes in distribu…
Cybersecurity researchers have discovered a novel attack technique called TokenBreak that can be used to bypass a large language model's (LLM) safety and conte…
A novel attack technique named EchoLeak has been characterized as a "zero-click" artificial intelligence (AI) vulnerability that allows bad actors to exfiltrat…
Human identities management and control is pretty well done with its set of dedicated tools, frameworks, and best practices. This is a very different world whe…
ConnectWise has disclosed that it's planning to rotate the digital code signing certificates used to sign ScreenConnect, ConnectWise Automate, and ConnectWise …
Linux. It's the silent backbone of modern cloud infrastructure''a workhorse running the vast majority of compute instances across enterprises. Depending on the…
For years, macOS has been more of a bystander in the containerization world''a useful client tool for developers but rarely the platform of choice for running …
As the world becomes more dependent on open-source software, it's critical to ensure that Linux systems stay secure. These systems run everything from enterpri…
Threat intelligence firm GreyNoise has warned of a "coordinated brute-force activity" targeting Apache Tomcat Manager interfaces.The company said it observed a…
The boundary between cyber and physical security is effectively gone. Attacks that once exploited software vulnerabilities now frequently begin with a compromi…
INTERPOL on Wednesday announced the dismantling of more than 20,000 malicious IP addresses or domains that have been linked to 69 information-stealing malware …
In today’s cybersecurity landscape, much of the focus is placed on firewalls, antivirus software, and endpoint detection. While these tools are essential, one …
In today’s security landscape, budgets are tight, attack surfaces are sprawling, and new threats emerge daily. Maintaining a strong security posture under thes…
Microsoft has released patches to fix 67 security flaws, including one zero-day bug in Web Distributed Authoring and Versioning (WebDAV) that it said has come …
Adobe on Tuesday pushed security updates to address a total of 254 security flaws impacting its software products, a majority of which affect Experience Manage…
Cybersecurity researchers have uncovered over 20 configuration-related risks affecting Salesforce Industry Cloud (aka Salesforce Industries), exposing sensitiv…