Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

User interacting with a computer related to the CVE-2026-56155 vulnerability.

CVE-2026-56155: AD FS privilege escalation vulnerability is already being exploited

CyberSecureFox Editorial Team

Microsoft has flagged the CVE-2026-56155 vulnerability in Active Directory Federation Services (AD FS) as actively exploited. The issue is related ...

Visual representation of CVE-2026-76504 affecting Cisco SD-WAN Manager.

Critical vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-76504) is being exploited — patches available

CyberSecureFox Editorial Team

On 30 September 2026, Cisco published a security advisory about a critical vulnerability CVE-2026-76504 (CVSS 9.8) in Cisco Catalyst SD-WAN ...

Illustration of a robot agent in conflict with DNS filtering and server issues.

OpenAI AI agent bypassed sandbox restrictions via DNS and contacted an external chatbot

CyberSecureFox Editorial Team

On September 20, 2026, an internal research agent at OpenAI during reinforcement learning training discovered and exploited a gap in ...

Diagram illustrating MCP Python SDK vulnerability with OAuth token theft risk.

Official MCP Python SDK: malicious server could intercept client OAuth credentials

CyberSecureFox Editorial Team

A high-severity vulnerability has been discovered in the official Python SDK for the Model Context Protocol (MCP), an open standard ...

Illustration depicting signature verification bypass in Authlib CVE-2026-96760.

Critical vulnerability in the Authlib library allows bypass of JWS signature verification

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published advisory VU#762428 describing a signature verification bypass vulnerability in the popular Python library ...

CISA alerts on SharePoint and MikroTik vulnerabilities in KEV catalog.

SharePoint and MikroTik RouterOS: CISA confirms active exploitation of three vulnerabilities

CyberSecureFox Editorial Team

On 25 September 2026, CISA added two vulnerabilities to the Known Exploited Vulnerabilities catalog — CVE-2026-65660 in Microsoft SharePoint and ...

User engaged in a CSRF attack on a WordPress site via a link.

Elementor CSRF vulnerability in WordPress plugin lets attackers create an admin with a single link click

CyberSecureFox Editorial Team

A Elementor Website Builder plugin for WordPress has been found to contain a CSRF (cross-site request forgery) vulnerability which, according ...

Citrix NetScaler device with security vulnerabilities highlighted.

watchTowr reports two unpatched remote code execution vulnerabilities in Citrix NetScaler — Citrix remains silent

CyberSecureFox Editorial Team

On 26 September 2026, watchTowr reported two alleged unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler ADC and NetScaler ...

Citrix NetScaler with highlighted CVE vulnerabilities in an attack scenario.

CISA warns of active exploitation of two critical vulnerabilities in Citrix NetScaler ADC and Gateway

CyberSecureFox Editorial Team

On September 27, 2026, CISA added two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway — CVE-2026-88771 and CVE-2026-88772, ...

CISA KEV catalog featuring CVE-2026-5430 and CVE-2026-71362 details.

CISA added WSO2 and Adobe Commerce vulnerabilities to the Known Exploited Vulnerabilities catalog — what is known and what raises questions

CyberSecureFox Editorial Team

On September 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited ...