Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
GitLab CVE-2026-19478: unauthenticated project modification risk
A critical vulnerability CVE-2026-19478 with a CVSS 9.4 score has been discovered in GitLab Community Edition and Enterprise Edition. It ...
How CVE-2026-69836 Exposed Microsoft Entra ID to Remote Code Execution
Microsoft has disclosed CVE-2026-69836, a remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory) with the maximum ...
Critical macOS, vCenter, SharePoint and IKE Bugs Added to CISA KEV
On August 18, 2026, CISA added four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, confirming that they are ...
CISA Confirms Active Exploitation of Ray CVE-2025-62593
CISA on August 17, 2026 added vulnerability CVE-2025-62593 (CVSS 9.4) to the Known Exploited Vulnerabilities catalog, confirming that it is ...
Emergency GitLab Patch for CVE-2026-19478 on Self-Managed Servers
GitLab has released an out-of-band security update to fix critical vulnerability CVE-2026-19478 with a CVSS score of 9.4, which under ...
How a GitHub Actions Workflow Exposed Snowflake’s Jira Token
Researchers at Wiz identified a workflow injection vulnerability in the public GitHub repository snowflakedb/snowflake-connector-net, which allowed an attacker to execute ...
GeoServer PostGIS SQL injection regression under active scanning
A critical SQL injection vulnerability with a CVSS 9.8 score has been discovered in GeoServer, which under certain configurations can ...
How Apple Notifies High-Risk Users About Spyware Threats
Apple has sent a new batch of notifications to users the company suspects are being targeted in attacks involving commercial ...
VMware vCenter CVE-2026-59310 Under Active Global Attack Campaign
The critical directory traversal vulnerability CVE-2026-59310 (CVSS 9.8) in Broadcom VMware vCenter Server is being actively exploited in a large-scale ...
Remote Code Execution Risk in SAP Commerce Cloud (CVE-2026-58231)
A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, has been discovered with a maximum CVSS score of 10.0, allowing an ...