You are here

LinuxSecurity.com

Subscribe to Feed LinuxSecurity.com
The central voice for Linux and Open Source security news.
Përditësimi: 16 orë 20 min më parë

Fortinet FortiSandbox Critical Command Execution Risk Exploit 2026-39813

Enj, 18/06/2026 - 4:49md
Fortinet has confirmed active exploitation of three FortiSandbox vulnerabilities. One allows attackers to bypass login controls, while the other two enable command execution directly on the appliance. Combined, they create a path from unauthenticated access to direct interaction with a system many organizations trust to analyze suspicious content.

Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers

Mër, 17/06/2026 - 6:27md
The Joomla Content Editor (JCE), one of the most widely deployed editor extensions for Joomla websites, is currently under active attack due to a critical vulnerability.

Malicious JetBrains Plugins: The IDE Is Now a Supply-Chain Attack

Mër, 17/06/2026 - 6:11md
At least 15 malicious plugins and nearly 70,000 installs later, developers are being reminded that trusted marketplaces can become supply-chain attack vectors overnight.  

FreeRDP 3.27 Raises the Baseline for Secure Remote Access

Mar, 16/06/2026 - 4:32md
Remote access tools do not need dramatic new features to improve security. Sometimes the more useful change is quieter, like stronger defaults that make weak encryption harder to use by accident.

SimpleHelp Authentication Bypass Exposes Remote Access Security Risk

Mar, 16/06/2026 - 4:22md
Remote support platforms sit close to the systems attackers want most: administrator workflows, technician accounts, and managed endpoints. That is why the SimpleHelp OIDC flaw is more serious than a routine authentication bypass vulnerability. For organizations running these platforms on Linux-based infrastructure, the risk is compounded by the ease with which these services are deployed and integrated into larger management stacks.

Cisco SD-WAN Vulnerability: Why Security Starts With the Management Plane

Mar, 16/06/2026 - 4:04md
For those of us who live and breathe Linux and open-source infrastructure, the "management plane" is usually just a collection of familiar tools—SSH, APIs, and centralized orchestration. But in the world of proprietary enterprise networking, the management plane is often a black box. Cisco’s latest SD-WAN issue serves as a stark reminder that even when these proprietary systems rely on Linux components under the hood, their centralized nature makes them the ultimate high-value target.

Does Linux Give Users a False Sense of Security? What This Year's Biggest Linux Security Incidents Actually Reveal

Hën, 15/06/2026 - 10:26md
If more than 12 million enterprise systems can be exposed by flaws in a security control designed to harden Linux, it's probably worth asking whether Linux gives people a false sense of security. That's a question that has come up repeatedly throughout 2026.

Fedora AI Contributor Incident Highlights New Open Source Risks

Pre, 12/06/2026 - 3:56md
A Fedora contributor account recently came under scrutiny for apparently AI-generated activity that disrupted the project's bug tracker.