Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Visual representation of CVE-2026-89026 vulnerability in Issabel Framework.

Hard-coded JWT key in Issabel Framework enables operating system command execution without authentication

CyberSecureFox Editorial Team

A vulnerability CVE-2026-89026 has been discovered in the Issabel Framework web framework used to manage Asterisk-based PBX systems, allowing an ...

User accessing Cisco ISE software highlighting CVE-2026-76460 vulnerability.

Cisco ISE: critical authentication bypass vulnerability exploited in attacks — patches and guidance

CyberSecureFox Editorial Team

Cisco has published an alert about a critical vulnerability, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE Passive ...

Graphic illustrating cyber vulnerability in SolarWinds Access Rights Manager.

SolarWinds fixes remote code execution vulnerability in Access Rights Manager caused by hard-coded key

CyberSecureFox Editorial Team

On 17 September 2026, SolarWinds published a security advisory on vulnerability CVE-2026-28326 — a flaw in Access Rights Manager (ARM) ...

Unauthenticated RCE vulnerability in Orkes Conductor, CVE-2026-58138 overview.

Critical Orkes Conductor vulnerability allows OS command execution without authentication

CyberSecureFox Editorial Team

The Orkes Conductor workflow orchestration platform versions from 3.21.21 up to 3.30.2 contain a critical vulnerability CVE-2026-58138 (CVSS v4: 9.3) ...

CISA highlights Linux kernel vulnerabilities: kTLS, ebtables, AF_ALG.

CISA adds three Linux kernel vulnerabilities to the KEV catalog: exploitation details and how to protect systems

CyberSecureFox Editorial Team

On September 18, 2026, CISA added three vulnerabilities in the Linux kernel to the Known Exploited Vulnerabilities (KEV) catalog, citing ...

AI-driven security workflow for WordPress plugin updates and risk assessment.

WordPress implements automated plugin security audit before distribution

CyberSecureFox Editorial Team

The WordPress team has announced the launch of an automated security check for every plugin update before it is distributed ...

Gitea server targeted by Red Heron RCE attack affecting multiple organizations.

Red Heron campaign: how the CVE-2026-60004 vulnerability in Gitea led to compromises in six countries

CyberSecureFox Editorial Team

The critical CVE-2026-60004 vulnerability in the Gitea platform (CVSS 9.8), which we have already covered, has become the vector for ...

Illustration of a smartphone highlighting a modem vulnerability alert.

Google fixes Pixel cellular modem privilege escalation vulnerability with signs of targeted exploitation

CyberSecureFox Editorial Team

The privilege escalation vulnerability CVE-2026-58704 in the cellular modem of Google Pixel smartphones was added to CISA’s Known Exploited Vulnerabilities ...

** Visual representation of cyber threats to Russian companies.

NightEagle, Hacking Cat and Toy Ghouls: Kaspersky describes three threat clusters targeting Russian businesses

CyberSecureFox Editorial Team

Experts at Kaspersky Lab have published a series of reports on three activity clusters — NightEagle, Hacking Cat and Toy ...

Vite server illustration depicting CVE-2026-39364 vulnerability alert.

Mass scanning of Vite servers to steal cloud credentials — what is known and how to protect yourself

CyberSecureFox Editorial Team

In August 2026, F5 Labs observed a large-scale automated scanning campaign targeting internet-exposed Vite development servers. The attackers are exploiting ...