Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Vite server illustration depicting CVE-2026-39364 vulnerability alert.

Mass scanning of Vite servers to steal cloud credentials — what is known and how to protect yourself

CyberSecureFox Editorial Team

In August 2026, F5 Labs observed a large-scale automated scanning campaign targeting internet-exposed Vite development servers. The attackers are exploiting ...

Diagram illustrating a cyberattack scenario involving MeshCentral and 3BB.

Attack on Thai broadband provider 3BB: attacker used MeshCentral for covert root access

CyberSecureFox Editorial Team

The threat analysis company Hunt.io identified an active intrusion into the network of 3BB, one of Thailand’s largest broadband providers. ...

SQL injection vulnerability alert in Cisco Secure Email Gateway image.

Critical Cisco Secure Email Gateway vulnerability is being actively exploited — patches available

CyberSecureFox Editorial Team

Cisco has published an advisory about a critical vulnerability CVE-2026-76461 in AsyncOS software for Cisco Secure Email Gateway. The vulnerability ...

Marimo RCE illustration showing SSH bastion connection in 8 seconds.

CVE-2026-39987 in Marimo: human operator bypassed traps and reached SSH bastion in eight seconds

CyberSecureFox Editorial Team

The critical vulnerability CVE-2026-39987 (CVSS 9.3) in Marimo interactive notebooks — pre-authentication remote code execution via the terminal WebSocket endpoint ...

Visual representation of CVE-2026-68820 exploiting afd.sys vulnerability.

CVE-2026-68820 — use-after-free in Windows AFD for WinSock with confirmed exploitation

CyberSecureFox Editorial Team

The CVE-2026-68820 vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) component is being actively exploited by attackers. According ...

Skullcandy Dime 3 earbuds with a smartphone showing a pairing request.

CERT/CC warns: Skullcandy Dime 3 earbuds vulnerable to unauthorized Bluetooth pairing with no update path

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published advisory VU#859658 describing a vulnerability in the Skullcandy Dime 3 wireless earbuds (model ...

Laptop showing Windows Update and alert for CVE-2026-81963 exploitation.

CVE-2026-81963: actively exploited privilege escalation vulnerability in Windows Update Stack

CyberSecureFox Editorial Team

Microsoft reports active exploitation of the CVE-2026-81963 vulnerability in the Windows Update Stack component. The vulnerability allows a local authenticated ...

GitLab logo with a computer sending requests showing CVE-2026-85706.

GitLab fixes CVE-2026-85706 file-reading vulnerability with maximum CVSS — scanning has already started

CyberSecureFox Editorial Team

GitLab has released emergency security updates to fix several vulnerabilities, including CVE-2026-85706 with the maximum CVSS 10.0 rating — a ...

FortiSandbox system displaying warning of CVSS 8.9 vulnerability.

Fortinet discloses FortiSandbox vulnerability — unauthenticated access to sensitive data

CyberSecureFox Editorial Team

Fortinet has published security advisory FG-IR-26-166 describing an Improper Access Control vulnerability (CWE-284) in the web interface of FortiSandbox, FortiSandbox ...

** Visual representation of FortiMonitorOnSight authentication process vulnerability.

Critical vulnerability in FortiMonitorOnSight enables authentication bypass via static JWT key

CyberSecureFox Editorial Team

Fortinet has published security advisory FG-IR-26-170 describing a critical vulnerability in the FortiMonitorOnSight web portal. The issue has been scored ...