Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Mass scanning of Vite servers to steal cloud credentials — what is known and how to protect yourself
In August 2026, F5 Labs observed a large-scale automated scanning campaign targeting internet-exposed Vite development servers. The attackers are exploiting ...
Attack on Thai broadband provider 3BB: attacker used MeshCentral for covert root access
The threat analysis company Hunt.io identified an active intrusion into the network of 3BB, one of Thailand’s largest broadband providers. ...
Critical Cisco Secure Email Gateway vulnerability is being actively exploited — patches available
Cisco has published an advisory about a critical vulnerability CVE-2026-76461 in AsyncOS software for Cisco Secure Email Gateway. The vulnerability ...
CVE-2026-39987 in Marimo: human operator bypassed traps and reached SSH bastion in eight seconds
The critical vulnerability CVE-2026-39987 (CVSS 9.3) in Marimo interactive notebooks — pre-authentication remote code execution via the terminal WebSocket endpoint ...
CVE-2026-68820 — use-after-free in Windows AFD for WinSock with confirmed exploitation
The CVE-2026-68820 vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) component is being actively exploited by attackers. According ...
CVE-2026-81963: actively exploited privilege escalation vulnerability in Windows Update Stack
Microsoft reports active exploitation of the CVE-2026-81963 vulnerability in the Windows Update Stack component. The vulnerability allows a local authenticated ...
GitLab fixes CVE-2026-85706 file-reading vulnerability with maximum CVSS — scanning has already started
GitLab has released emergency security updates to fix several vulnerabilities, including CVE-2026-85706 with the maximum CVSS 10.0 rating — a ...
Fortinet discloses FortiSandbox vulnerability — unauthenticated access to sensitive data
Fortinet has published security advisory FG-IR-26-166 describing an Improper Access Control vulnerability (CWE-284) in the web interface of FortiSandbox, FortiSandbox ...
Critical vulnerability in FortiMonitorOnSight enables authentication bypass via static JWT key
Fortinet has published security advisory FG-IR-26-170 describing a critical vulnerability in the FortiMonitorOnSight web portal. The issue has been scored ...