Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Vulnerabilities
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial inte…

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
AryStinger: Why Thousands of Unpatched Linux Routers Are Being Weaponized

More than 4,300 internet-facing devices have been pulled into a newly documented router malware campaign called AryStinger. The infected systems are mostly not…

Linux

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
SQL Injection: Why It Persists and How to Prevent It

SQL injection has been in every OWASP Top 10 list ever published, and it is still number five in 2025. Here is why the vulnerability persists and the defences …

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Virus vs Worm: Why the Propagation Difference Actually Matters

The difference between a virus and a worm is not semantic. A virus waits for a user to trigger it; a worm exploits vulnerabilities and spreads on its own. That…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
usbliter8 Exploit Achieves Code Execution in Apple’s Unpatchable SecureROM

Paradigm Shift has published a working exploit for Apple's A12 and A13 SecureROM. The flaw is in hardware, so no patch will ever exist. Here's the technical br…

Apple

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
OpenStack Keystone Flaws Expose Multiple Paths to Cloud Privilege Escalation

The recent Keystone advisory is unusual because the vulnerabilities are scattered across several features but keep affecting the same class of security control…

The Hacker News
The Hacker News Vulnerabilities
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution.Steer t…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
The ASLR Caveat on NGINX’s Critical HTTP/3 Flaw Changes Nothing About Urgency

CVE-2026-42530, the NGINX HTTP/3 vulnerability rated CVSS 9.2, is collecting dismissals because exploitation requires ASLR to be disabled or bypassed. Here is …

Nginx

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Fortinet FortiSandbox Critical Command Execution Risk Exploit 2026-39813

Fortinet has confirmed active exploitation of three FortiSandbox vulnerabilities. One allows attackers to bypass login controls, while the other two enable com…

Fortinet

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
CVE-2026-48907: How the Joomla JCE Exploit Works and What to Do About It

CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request. Here is how the attack works and how …

PHP

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers

The Joomla Content Editor (JCE), one of the most widely deployed editor extensions for Joomla websites, is currently under active attack due to a critical vuln…

Linux

The Hacker News
The Hacker News Breaches & leaks
The Top 10 Attack Surface Exposures in 2026

Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerabilit…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
How CVE-2026-20253 Turns Splunk’s PostgreSQL Sidecar Into an Open Door

CVE-2026-20253 is a CVSS 9.8 pre-auth flaw in Splunk Enterprise's PostgreSQL sidecar service. An unauthenticated attacker can write files and chain the primiti…

Databases

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
SimpleHelp Authentication Bypass Exposes Remote Access Security Risk

Remote support platforms sit close to the systems attackers want most: administrator workflows, technician accounts, and managed endpoints. That is why the Sim…

Linux

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Cisco SD-WAN Vulnerability: Why Security Starts With the Management Plane

For those of us who live and breathe Linux and open-source infrastructure, the "management plane" is usually just a collection of familiar tools—SSH, APIs, and…

Linux Cisco

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
LiteLLM Vulnerability Chain: What Security Teams Running AI Gateways Need to Do Now

A three-CVE chain lets any default LiteLLM user escalate to admin and get a shell on the gateway server. A separate RCE is already in CISA's KEV. Here's what t…

The Hacker News
The Hacker News Vulnerabilities
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.The vuln…

Cisco

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Does Linux Give Users a False Sense of Security? What This Year's Biggest Linux Security Incidents Actually Reveal

If more than 12 million enterprise systems can be exposed by flaws in a security control designed to harden Linux, it's probably worth asking whether Linux giv…

Linux

The Hacker News
The Hacker News Vulnerabilities
LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidia…

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Vulnerabilities
Palo Alto’s GlobalProtect Authentication Bypass Was Exploited Four Days After Disclosure

CVE-2026-0257's GlobalProtect authentication bypass went from advisory to active exploitation in four days. The recurring pattern of perimeter device failures …

Palo Alto

Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses Breaches & leaks
Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate

A CVSS 9.3 flaw in Check Point Remote Access VPN let unauthenticated attackers bypass certificate validation by supplying a crafted IKEv1 VendorID payload — ex…

VPN

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Vulnerabilities
Langflow 1.9.0 Advisory CVE-2026-5027 High File Write Threat

Attackers are actively exploiting a high-severity vulnerability in Langflow, an open-source platform used to build and run AI workflows.

The Hacker News
The Hacker News Vulnerabilities
AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponiz…

The Hacker News
The Hacker News Vulnerabilities
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution an…

Fortinet Ivanti