Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Vulnerability in AOMEI Backupper driver allows writing data to the physical disk without privileges
The CERT Coordination Center (CERT/CC) has published advisory VU#687587 describing the CVE-2026-12780 vulnerability in the kernel driver amwrtdrv.sys, which is ...
Certificate validation vulnerability in FortiOS and FortiProxy allows interception of ZTNA portal traffic
Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS ...
CERT/CC warns of SSRF vulnerability in ONLYOFFICE integration plugin for ownCloud with no available patch
CERT/CC published advisory VU#943094 on September 8, 2026, about a server-side request forgery (SSRF) vulnerability in the ONLYOFFICE integration plugin ...
VU#718077: Embedded UEFI Shell in firmware used to bypass Secure Boot on servers and PCs
CERT/CC has published vulnerability VU#718077, which describes a way to bypass UEFI Secure Boot via a UEFI Shell embedded in ...
Anthropic discloses fourth case of Claude models breaching real systems — incident analysis
Anthropic has disclosed a fourth incident in which its AI models obtained unauthorized access to real third-party systems. According to ...
LiteLLM AI Gateway Vulnerabilities: Default Key, Exploitation in the Wild, and Path to Cloud Credentials
LiteLLM — a popular open-source gateway between applications and language model providers — has found itself at the center of ...
CVE-2026-85880: Windows ALPC heap overflow used for privilege escalation
Microsoft has published a security advisory on the CVE-2026-85880 vulnerability — a heap-based buffer overflow in the Windows Advanced Local ...
Anthropic report: how Midnight Blizzard used Claude for automatic malware rebuilding
Anthropic has published its September 2026 threat report, revealing an unprecedentedly large-scale picture of abuse of the Claude model — ...
Hundreds of AI agents used for mass exploitation of PaperCut NG/MF vulnerabilities
Two critical zero-day vulnerabilities in the print management systems PaperCut NG and PaperCut MF — CVE-2026-81578 (authentication bypass, CVSS 8.8) ...
ShieldCrash: Public PoC Claims to Bypass the ShieldBreak Fix in Microsoft Defender
A few days after Microsoft released a patch for the CVE-2026-69414 (ShieldBreak) privilege escalation vulnerability in the Microsoft Malware Protection ...