Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Critical Orkes Conductor vulnerability allows OS command execution without authentication
The Orkes Conductor workflow orchestration platform versions from 3.21.21 up to 3.30.2 contain a critical vulnerability CVE-2026-58138 (CVSS v4: 9.3) ...
CISA adds three Linux kernel vulnerabilities to the KEV catalog: exploitation details and how to protect systems
On September 18, 2026, CISA added three vulnerabilities in the Linux kernel to the Known Exploited Vulnerabilities (KEV) catalog, citing ...
WordPress implements automated plugin security audit before distribution
The WordPress team has announced the launch of an automated security check for every plugin update before it is distributed ...
Red Heron campaign: how the CVE-2026-60004 vulnerability in Gitea led to compromises in six countries
The critical CVE-2026-60004 vulnerability in the Gitea platform (CVSS 9.8), which we have already covered, has become the vector for ...
Google fixes Pixel cellular modem privilege escalation vulnerability with signs of targeted exploitation
The privilege escalation vulnerability CVE-2026-58704 in the cellular modem of Google Pixel smartphones was added to CISA’s Known Exploited Vulnerabilities ...
NightEagle, Hacking Cat and Toy Ghouls: Kaspersky describes three threat clusters targeting Russian businesses
Experts at Kaspersky Lab have published a series of reports on three activity clusters — NightEagle, Hacking Cat and Toy ...
Mass scanning of Vite servers to steal cloud credentials — what is known and how to protect yourself
In August 2026, F5 Labs observed a large-scale automated scanning campaign targeting internet-exposed Vite development servers. The attackers are exploiting ...
Attack on Thai broadband provider 3BB: attacker used MeshCentral for covert root access
The threat analysis company Hunt.io identified an active intrusion into the network of 3BB, one of Thailand’s largest broadband providers. ...
Critical Cisco Secure Email Gateway vulnerability is being actively exploited — patches available
Cisco has published an advisory about a critical vulnerability CVE-2026-76461 in AsyncOS software for Cisco Secure Email Gateway. The vulnerability ...
CVE-2026-39987 in Marimo: human operator bypassed traps and reached SSH bastion in eight seconds
The critical vulnerability CVE-2026-39987 (CVSS 9.3) in Marimo interactive notebooks — pre-authentication remote code execution via the terminal WebSocket endpoint ...