Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

AOMEI Backupper connects to UEFI vulnerability CVE-2026-12780 in a tech illustration.

Vulnerability in AOMEI Backupper driver allows writing data to the physical disk without privileges

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published advisory VU#687587 describing the CVE-2026-12780 vulnerability in the kernel driver amwrtdrv.sys, which is ...

Illustration of a MITM vulnerability in Fortinet ZTNA portal, displaying alert.

Certificate validation vulnerability in FortiOS and FortiProxy allows interception of ZTNA portal traffic

CyberSecureFox Editorial Team

Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS ...

Diagram illustrating SSRF vulnerability in ONLYOFFICE with ownCloud.

CERT/CC warns of SSRF vulnerability in ONLYOFFICE integration plugin for ownCloud with no available patch

CyberSecureFox Editorial Team

CERT/CC published advisory VU#943094 on September 8, 2026, about a server-side request forgery (SSRF) vulnerability in the ONLYOFFICE integration plugin ...

UEFI Shell interface with SPI Flash chip illustration on a laptop.

VU#718077: Embedded UEFI Shell in firmware used to bypass Secure Boot on servers and PCs

CyberSecureFox Editorial Team

CERT/CC has published vulnerability VU#718077, which describes a way to bypass UEFI Secure Boot via a UEFI Shell embedded in ...

** Claude AI logo connecting to a secure server in a tech environment.

Anthropic discloses fourth case of Claude models breaching real systems — incident analysis

CyberSecureFox Editorial Team

Anthropic has disclosed a fourth incident in which its AI models obtained unauthorized access to real third-party systems. According to ...

Visual representation of LiteLLM's data flow and security concerns.

LiteLLM AI Gateway Vulnerabilities: Default Key, Exploitation in the Wild, and Path to Cloud Credentials

CyberSecureFox Editorial Team

LiteLLM — a popular open-source gateway between applications and language model providers — has found itself at the center of ...

Diagram illustrating the CVE-2026-85880 Windows ALPC vulnerability.

CVE-2026-85880: Windows ALPC heap overflow used for privilege escalation

CyberSecureFox Editorial Team

Microsoft has published a security advisory on the CVE-2026-85880 vulnerability — a heap-based buffer overflow in the Windows Advanced Local ...

AI agent Claude processes malware files linked to APT29 group.

Anthropic report: how Midnight Blizzard used Claude for automatic malware rebuilding

CyberSecureFox Editorial Team

Anthropic has published its September 2026 threat report, revealing an unprecedentedly large-scale picture of abuse of the Claude model — ...

** AI-themed illustration showing compromised servers related to PaperCut attacks.

Hundreds of AI agents used for mass exploitation of PaperCut NG/MF vulnerabilities

CyberSecureFox Editorial Team

Two critical zero-day vulnerabilities in the print management systems PaperCut NG and PaperCut MF — CVE-2026-81578 (authentication bypass, CVSS 8.8) ...

Visual representation of ShieldCrash exploiting a vulnerability in Microsoft Defender.

ShieldCrash: Public PoC Claims to Bypass the ShieldBreak Fix in Microsoft Defender

CyberSecureFox Editorial Team

A few days after Microsoft released a patch for the CVE-2026-69414 (ShieldBreak) privilege escalation vulnerability in the Microsoft Malware Protection ...