Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The company demonstrated the race

BY The Hacker News
MIN READ 1 MIN READ
EXPLORE north_east
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements
CYBERSECURITY

Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements

Axonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelligence capabilities to IoT and OT devices. “Every security and IT leader we speak to has the same story about their asset data: a tool says one thing and reality says another,” said Moshe Ben Simon, … More → The post Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements appeared first on Help Net Security.

1 MIN READ arrow_forward
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
CYBERSECURITY

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an

1 MIN READ arrow_forward
Shadow AI is becoming enterprise security’s biggest blind spot
CYBERSECURITY

Shadow AI is becoming enterprise security’s biggest blind spot

Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026 Work Trend Index found that employees often adopt AI faster than their organizations can adapt to it. As AI is integrated into team members’ daily jobs, businesses are struggling to keep pace with governance, management practices, … More → The post Shadow AI is becoming enterprise security’s biggest blind spot appeared first on Help Net Security.

1 MIN READ arrow_forward
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
CYBERSECURITY

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those already in GitHub’s growing triage queue, will retain the previous payout terms. GitHub said the

1 MIN READ arrow_forward
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
CYBERSECURITY

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as

1 MIN READ arrow_forward