Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Illustration of Bifrost AI Gateway highlighting CVE-2026-90898 vulnerability.

Unauthenticated command execution in Bifrost via MCP client registration

CyberSecureFox Editorial Team

Two vulnerabilities have been discovered in the open AI gateway Bifrost, which routes requests to more than 20 large language ...

Zyxel GS1900 switch with vulnerabilities targeting Veeam Agent highlighted.

Active exploitation of vulnerabilities in Zyxel GS1900 switches and Veeam Agent for Windows

CyberSecureFox Editorial Team

On 21 September 2026, CISA added the critical CVE-2026-7273 vulnerability in Zyxel GS1900 switches to the Known Exploited Vulnerabilities (KEV) ...

** Arista VeloCloud Orchestrator with CVE-2026-93952 alert displayed.

Critical CVE-2026-93952 vulnerability in VeloCloud Orchestrator is being actively exploited — patches are not available for all versions

CyberSecureFox Editorial Team

On 22 September 2026, Arista published Security Advisory 0183 describing the critical vulnerability CVE-2026-93952 in VeloCloud Orchestrator On-Prem — the ...

Diagram illustrating CVE-2026-32882 vulnerability in Discourse and OpenAI.

Libheif vulnerability allowed researchers to access OpenAI employee accounts via the forum

CyberSecureFox Editorial Team

The CVE-2026-32882 vulnerability in the image-processing library libheif became a key link in an attack chain that, according to research ...

User interacts with a laptop, highlighting Azure AI Foundry vulnerability alert.

Microsoft fixes critical Azure AI Foundry vulnerability and five other serious bugs

CyberSecureFox Editorial Team

Microsoft has announced that it has fixed six vulnerabilities, including CVE-2026-85889 with a maximum CVSS score of 10.0 in the ...

Illustration of WordPress theme installation process via a link.

Click2Shell vulnerability in WordPress allows installing a theme without the administrator’s knowledge

CyberSecureFox Editorial Team

On September 17, 2026, WordPress released version 7.1.1 — an emergency security update that fixes a vulnerability allowing a specially ...

Laptop on desk with alerts about TanStack npm supply chain attack.

TanStack supply chain attack led to copying of 170 private CrowdSec GitHub repositories

CyberSecureFox Editorial Team

On 11 May 2026, 84 malicious versions of 42 @tanstack/* packages were published to the npm registry — a supply ...

Visual representation of CVE-2026-89026 vulnerability in Issabel Framework.

Hard-coded JWT key in Issabel Framework enables operating system command execution without authentication

CyberSecureFox Editorial Team

A vulnerability CVE-2026-89026 has been discovered in the Issabel Framework web framework used to manage Asterisk-based PBX systems, allowing an ...

User accessing Cisco ISE software highlighting CVE-2026-76460 vulnerability.

Cisco ISE: critical authentication bypass vulnerability exploited in attacks — patches and guidance

CyberSecureFox Editorial Team

Cisco has published an alert about a critical vulnerability, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE Passive ...

Graphic illustrating cyber vulnerability in SolarWinds Access Rights Manager.

SolarWinds fixes remote code execution vulnerability in Access Rights Manager caused by hard-coded key

CyberSecureFox Editorial Team

On 17 September 2026, SolarWinds published a security advisory on vulnerability CVE-2026-28326 — a flaw in Access Rights Manager (ARM) ...