Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
CVE-2026-81963: actively exploited privilege escalation vulnerability in Windows Update Stack
Microsoft reports active exploitation of the CVE-2026-81963 vulnerability in the Windows Update Stack component. The vulnerability allows a local authenticated ...
GitLab fixes CVE-2026-85706 file-reading vulnerability with maximum CVSS — scanning has already started
GitLab has released emergency security updates to fix several vulnerabilities, including CVE-2026-85706 with the maximum CVSS 10.0 rating — a ...
Fortinet discloses FortiSandbox vulnerability — unauthenticated access to sensitive data
Fortinet has published security advisory FG-IR-26-166 describing an Improper Access Control vulnerability (CWE-284) in the web interface of FortiSandbox, FortiSandbox ...
Critical vulnerability in FortiMonitorOnSight enables authentication bypass via static JWT key
Fortinet has published security advisory FG-IR-26-170 describing a critical vulnerability in the FortiMonitorOnSight web portal. The issue has been scored ...
Vulnerability in AOMEI Backupper driver allows writing data to the physical disk without privileges
The CERT Coordination Center (CERT/CC) has published advisory VU#687587 describing the CVE-2026-12780 vulnerability in the kernel driver amwrtdrv.sys, which is ...
Certificate validation vulnerability in FortiOS and FortiProxy allows interception of ZTNA portal traffic
Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS ...
CERT/CC warns of SSRF vulnerability in ONLYOFFICE integration plugin for ownCloud with no available patch
CERT/CC published advisory VU#943094 on September 8, 2026, about a server-side request forgery (SSRF) vulnerability in the ONLYOFFICE integration plugin ...
VU#718077: Embedded UEFI Shell in firmware used to bypass Secure Boot on servers and PCs
CERT/CC has published vulnerability VU#718077, which describes a way to bypass UEFI Secure Boot via a UEFI Shell embedded in ...
Anthropic discloses fourth case of Claude models breaching real systems — incident analysis
Anthropic has disclosed a fourth incident in which its AI models obtained unauthorized access to real third-party systems. According to ...
LiteLLM AI Gateway Vulnerabilities: Default Key, Exploitation in the Wild, and Path to Cloud Credentials
LiteLLM — a popular open-source gateway between applications and language model providers — has found itself at the center of ...