Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Microsoft fixes critical Azure AI Foundry vulnerability and five other serious bugs
Microsoft has announced that it has fixed six vulnerabilities, including CVE-2026-85889 with a maximum CVSS score of 10.0 in the ...
Click2Shell vulnerability in WordPress allows installing a theme without the administrator’s knowledge
On September 17, 2026, WordPress released version 7.1.1 — an emergency security update that fixes a vulnerability allowing a specially ...
TanStack supply chain attack led to copying of 170 private CrowdSec GitHub repositories
On 11 May 2026, 84 malicious versions of 42 @tanstack/* packages were published to the npm registry — a supply ...
Hard-coded JWT key in Issabel Framework enables operating system command execution without authentication
A vulnerability CVE-2026-89026 has been discovered in the Issabel Framework web framework used to manage Asterisk-based PBX systems, allowing an ...
Cisco ISE: critical authentication bypass vulnerability exploited in attacks — patches and guidance
Cisco has published an alert about a critical vulnerability, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE Passive ...
SolarWinds fixes remote code execution vulnerability in Access Rights Manager caused by hard-coded key
On 17 September 2026, SolarWinds published a security advisory on vulnerability CVE-2026-28326 — a flaw in Access Rights Manager (ARM) ...
Critical Orkes Conductor vulnerability allows OS command execution without authentication
The Orkes Conductor workflow orchestration platform versions from 3.21.21 up to 3.30.2 contain a critical vulnerability CVE-2026-58138 (CVSS v4: 9.3) ...
CISA adds three Linux kernel vulnerabilities to the KEV catalog: exploitation details and how to protect systems
On September 18, 2026, CISA added three vulnerabilities in the Linux kernel to the Known Exploited Vulnerabilities (KEV) catalog, citing ...
WordPress implements automated plugin security audit before distribution
The WordPress team has announced the launch of an automated security check for every plugin update before it is distributed ...
Red Heron campaign: how the CVE-2026-60004 vulnerability in Gitea led to compromises in six countries
The critical CVE-2026-60004 vulnerability in the Gitea platform (CVSS 9.8), which we have already covered, has become the vector for ...