Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Marimo RCE illustration showing SSH bastion connection in 8 seconds.

CVE-2026-39987 in Marimo: human operator bypassed traps and reached SSH bastion in eight seconds

CyberSecureFox Editorial Team

The critical vulnerability CVE-2026-39987 (CVSS 9.3) in Marimo interactive notebooks — pre-authentication remote code execution via the terminal WebSocket endpoint ...

Visual representation of CVE-2026-68820 exploiting afd.sys vulnerability.

CVE-2026-68820 — use-after-free in Windows AFD for WinSock with confirmed exploitation

CyberSecureFox Editorial Team

The CVE-2026-68820 vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) component is being actively exploited by attackers. According ...

Skullcandy Dime 3 earbuds with a smartphone showing a pairing request.

CERT/CC warns: Skullcandy Dime 3 earbuds vulnerable to unauthorized Bluetooth pairing with no update path

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published advisory VU#859658 describing a vulnerability in the Skullcandy Dime 3 wireless earbuds (model ...

Laptop showing Windows Update and alert for CVE-2026-81963 exploitation.

CVE-2026-81963: actively exploited privilege escalation vulnerability in Windows Update Stack

CyberSecureFox Editorial Team

Microsoft reports active exploitation of the CVE-2026-81963 vulnerability in the Windows Update Stack component. The vulnerability allows a local authenticated ...

GitLab logo with a computer sending requests showing CVE-2026-85706.

GitLab fixes CVE-2026-85706 file-reading vulnerability with maximum CVSS — scanning has already started

CyberSecureFox Editorial Team

GitLab has released emergency security updates to fix several vulnerabilities, including CVE-2026-85706 with the maximum CVSS 10.0 rating — a ...

FortiSandbox system displaying warning of CVSS 8.9 vulnerability.

Fortinet discloses FortiSandbox vulnerability — unauthenticated access to sensitive data

CyberSecureFox Editorial Team

Fortinet has published security advisory FG-IR-26-166 describing an Improper Access Control vulnerability (CWE-284) in the web interface of FortiSandbox, FortiSandbox ...

** Visual representation of FortiMonitorOnSight authentication process vulnerability.

Critical vulnerability in FortiMonitorOnSight enables authentication bypass via static JWT key

CyberSecureFox Editorial Team

Fortinet has published security advisory FG-IR-26-170 describing a critical vulnerability in the FortiMonitorOnSight web portal. The issue has been scored ...

AOMEI Backupper connects to UEFI vulnerability CVE-2026-12780 in a tech illustration.

Vulnerability in AOMEI Backupper driver allows writing data to the physical disk without privileges

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published advisory VU#687587 describing the CVE-2026-12780 vulnerability in the kernel driver amwrtdrv.sys, which is ...

Illustration of a MITM vulnerability in Fortinet ZTNA portal, displaying alert.

Certificate validation vulnerability in FortiOS and FortiProxy allows interception of ZTNA portal traffic

CyberSecureFox Editorial Team

Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS ...

Diagram illustrating SSRF vulnerability in ONLYOFFICE with ownCloud.

CERT/CC warns of SSRF vulnerability in ONLYOFFICE integration plugin for ownCloud with no available patch

CyberSecureFox Editorial Team

CERT/CC published advisory VU#943094 on September 8, 2026, about a server-side request forgery (SSRF) vulnerability in the ONLYOFFICE integration plugin ...