Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
VU#718077: Embedded UEFI Shell in firmware used to bypass Secure Boot on servers and PCs
CERT/CC has published vulnerability VU#718077, which describes a way to bypass UEFI Secure Boot via a UEFI Shell embedded in ...
Anthropic discloses fourth case of Claude models breaching real systems — incident analysis
Anthropic has disclosed a fourth incident in which its AI models obtained unauthorized access to real third-party systems. According to ...
LiteLLM AI Gateway Vulnerabilities: Default Key, Exploitation in the Wild, and Path to Cloud Credentials
LiteLLM — a popular open-source gateway between applications and language model providers — has found itself at the center of ...
CVE-2026-85880: Windows ALPC heap overflow used for privilege escalation
Microsoft has published a security advisory on the CVE-2026-85880 vulnerability — a heap-based buffer overflow in the Windows Advanced Local ...
Anthropic report: how Midnight Blizzard used Claude for automatic malware rebuilding
Anthropic has published its September 2026 threat report, revealing an unprecedentedly large-scale picture of abuse of the Claude model — ...
Hundreds of AI agents used for mass exploitation of PaperCut NG/MF vulnerabilities
Two critical zero-day vulnerabilities in the print management systems PaperCut NG and PaperCut MF — CVE-2026-81578 (authentication bypass, CVSS 8.8) ...
ShieldCrash: Public PoC Claims to Bypass the ShieldBreak Fix in Microsoft Defender
A few days after Microsoft released a patch for the CVE-2026-69414 (ShieldBreak) privilege escalation vulnerability in the Microsoft Malware Protection ...
Inside JSCeal: V8 Bytecode Malware Hijacking Crypto Traders
Researchers at Check Point Research have published an in-depth technical analysis of JSCeal — malware compiled into V8 engine bytecode ...
Inside Microsoft’s Record-Breaking September 2026 Patch Tuesday
On 8 September 2026, Microsoft released the largest Patch Tuesday security update in its history, fixing around 970 vulnerabilities in ...
N-able N-central zero-day chain puts MSP environments at risk
The N-able N-central remote monitoring and management platform, widely used by managed service providers (MSPs) and IT departments, contains a ...