Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Graphic illustrating the CVE-2026-19478 bug and its effects on data.

GitLab CVE-2026-19478: unauthenticated project modification risk

CyberSecureFox Editorial Team

A critical vulnerability CVE-2026-19478 with a CVSS 9.4 score has been discovered in GitLab Community Edition and Enterprise Edition. It ...

Visual representation of RCE vulnerability in Microsoft Entra ID.

How CVE-2026-69836 Exposed Microsoft Entra ID to Remote Code Execution

CyberSecureFox Editorial Team

Microsoft has disclosed CVE-2026-69836, a remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory) with the maximum ...

Graphic depicting cybersecurity threats targeting major tech platforms.

Critical macOS, vCenter, SharePoint and IKE Bugs Added to CISA KEV

CyberSecureFox Editorial Team

On August 18, 2026, CISA added four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, confirming that they are ...

Ray DNS Rebinding RCE concept illustrated with server and laptop visuals.

CISA Confirms Active Exploitation of Ray CVE-2025-62593

CyberSecureFox Editorial Team

CISA on August 17, 2026 added vulnerability CVE-2025-62593 (CVSS 9.4) to the Known Exploited Vulnerabilities catalog, confirming that it is ...

Critical GitLab vulnerability CVE-2026-19478 allowing remote deletion.

Emergency GitLab Patch for CVE-2026-19478 on Self-Managed Servers

CyberSecureFox Editorial Team

GitLab has released an out-of-band security update to fix critical vulnerability CVE-2026-19478 with a CVSS score of 9.4, which under ...

How a GitHub Actions Workflow Exposed Snowflake’s Jira Token

CyberSecureFox Editorial Team

Researchers at Wiz identified a workflow injection vulnerability in the public GitHub repository snowflakedb/snowflake-connector-net, which allowed an attacker to execute ...

Illustration of a SQL injection attack targeting a GeoServer database.

GeoServer PostGIS SQL injection regression under active scanning

CyberSecureFox Editorial Team

A critical SQL injection vulnerability with a CVSS 9.8 score has been discovered in GeoServer, which under certain configurations can ...

Apple logo on smartphone with warning triangle and global spyware alert.

How Apple Notifies High-Risk Users About Spyware Threats

CyberSecureFox Editorial Team

Apple has sent a new batch of notifications to users the company suspects are being targeted in attacks involving commercial ...

Visual representation of global cybersecurity threat from VMware vCenter CVE-2026-59310.

VMware vCenter CVE-2026-59310 Under Active Global Attack Campaign

CyberSecureFox Editorial Team

The critical directory traversal vulnerability CVE-2026-59310 (CVSS 9.8) in Broadcom VMware vCenter Server is being actively exploited in a large-scale ...

SAP Commerce Cloud logo with a RCE vulnerability display and digital elements.

Remote Code Execution Risk in SAP Commerce Cloud (CVE-2026-58231)

CyberSecureFox Editorial Team

A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, has been discovered with a maximum CVSS score of 10.0, allowing an ...