Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

CISA alerts on SharePoint and MikroTik vulnerabilities in KEV catalog.

SharePoint and MikroTik RouterOS: CISA confirms active exploitation of three vulnerabilities

CyberSecureFox Editorial Team

On 25 September 2026, CISA added two vulnerabilities to the Known Exploited Vulnerabilities catalog — CVE-2026-65660 in Microsoft SharePoint and ...

User engaged in a CSRF attack on a WordPress site via a link.

Elementor CSRF vulnerability in WordPress plugin lets attackers create an admin with a single link click

CyberSecureFox Editorial Team

A Elementor Website Builder plugin for WordPress has been found to contain a CSRF (cross-site request forgery) vulnerability which, according ...

Citrix NetScaler device with security vulnerabilities highlighted.

watchTowr reports two unpatched remote code execution vulnerabilities in Citrix NetScaler — Citrix remains silent

CyberSecureFox Editorial Team

On 26 September 2026, watchTowr reported two alleged unpatched remote code execution (RCE) vulnerabilities in Citrix NetScaler ADC and NetScaler ...

Citrix NetScaler with highlighted CVE vulnerabilities in an attack scenario.

CISA warns of active exploitation of two critical vulnerabilities in Citrix NetScaler ADC and Gateway

CyberSecureFox Editorial Team

On September 27, 2026, CISA added two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway — CVE-2026-88771 and CVE-2026-88772, ...

CISA KEV catalog featuring CVE-2026-5430 and CVE-2026-71362 details.

CISA added WSO2 and Adobe Commerce vulnerabilities to the Known Exploited Vulnerabilities catalog — what is known and what raises questions

CyberSecureFox Editorial Team

On September 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited ...

Visual representation of a zero-day exploit in F5 BIG-IP APM via OAuth.

CVE-2026-94127: critical F5 BIG-IP APM vulnerability exploited for remote code execution on OAuth servers

CyberSecureFox Editorial Team

F5 has reported active exploitation of a critical vulnerability, CVE-2026-94127, in the BIG-IP Access Policy Manager (APM) module that allows ...

Critical LFI vulnerability in WordPress core represented by code graphics.

CVE-2026-87902: local file inclusion vulnerability in WordPress — who is affected and how to stay protected

CyberSecureFox Editorial Team

On September 22, 2026, WordPress released the emergency update 7.1.2, which fixes the critical vulnerability CVE-2026-87902 (CVSS 9.2) in the ...

Illustration depicting ShinyHunters claiming FBI breach of Oracle PeopleSoft.

ShinyHunters claims it hacked the FBI: what has been confirmed and what remains just hacker claims

CyberSecureFox Editorial Team

On September 22, 2026, the ShinyHunters group claimed it had compromised systems of the U.S. Federal Bureau of Investigation (FBI) ...

Graphic depicting BigDiskBuster blocking Microsoft Defender updates.

BigDiskBuster — public PoC that can block Microsoft Defender updates by filling the disk

CyberSecureFox Editorial Team

On September 19, a tool called BigDiskBuster was published on GitHub — a proof of concept designed to block platform ...

Illustration depicting CVE-2026-65660 vulnerability in SharePoint.

CVE-2026-65660 in SharePoint: spoofing or remote code execution — what is known and what to do

CyberSecureFox Editorial Team

On 11 August 2026, Microsoft released security updates for SharePoint Server 2016, 2019, and Subscription Edition to fix the vulnerability ...