Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Kaltura player illustration depicting data theft and RCE vulnerabilities.

CERT/CC discloses Kaltura HTML5lib RCE and file read flaws

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published information on two unpatched vulnerabilities in the Kaltura HTML5 video player library that ...

Abstract illustration of cybercrime and law enforcement with handcuffs and a globe.

Global Jackal IV Operation Hits West African Fraud Networks

CyberSecureFox Editorial Team

The eight-month international operation Jackal IV, coordinated by INTERPOL and involving 22 countries across six continents, resulted in the arrest ...

Gitea's RCE vulnerability highlighted in a digital illustration.

Active Exploitation of Gitea CVE-2026-60004 Confirmed by CISA

CyberSecureFox Editorial Team

CISA on August 25, 2026 confirmed active exploitation of the critical vulnerability CVE-2026-60004 in the Git repository management platform Gitea ...

Illustration of NASA AIT-GUI interface showing command execution concepts.

Unauthenticated Command Execution Chain in NASA’s AIT-GUI

CyberSecureFox Editorial Team

Security researchers from Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for the open framework ...

Graphic illustrating the CVE-2026-19478 bug and its effects on data.

GitLab CVE-2026-19478: unauthenticated project modification risk

CyberSecureFox Editorial Team

A critical vulnerability CVE-2026-19478 with a CVSS 9.4 score has been discovered in GitLab Community Edition and Enterprise Edition. It ...

Visual representation of RCE vulnerability in Microsoft Entra ID.

How CVE-2026-69836 Exposed Microsoft Entra ID to Remote Code Execution

CyberSecureFox Editorial Team

Microsoft has disclosed CVE-2026-69836, a remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory) with the maximum ...

Graphic depicting cybersecurity threats targeting major tech platforms.

Critical macOS, vCenter, SharePoint and IKE Bugs Added to CISA KEV

CyberSecureFox Editorial Team

On August 18, 2026, CISA added four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, confirming that they are ...

Ray DNS Rebinding RCE concept illustrated with server and laptop visuals.

CISA Confirms Active Exploitation of Ray CVE-2025-62593

CyberSecureFox Editorial Team

CISA on August 17, 2026 added vulnerability CVE-2025-62593 (CVSS 9.4) to the Known Exploited Vulnerabilities catalog, confirming that it is ...

Critical GitLab vulnerability CVE-2026-19478 allowing remote deletion.

Emergency GitLab Patch for CVE-2026-19478 on Self-Managed Servers

CyberSecureFox Editorial Team

GitLab has released an out-of-band security update to fix critical vulnerability CVE-2026-19478 with a CVSS score of 9.4, which under ...

How a GitHub Actions Workflow Exposed Snowflake’s Jira Token

CyberSecureFox Editorial Team

Researchers at Wiz identified a workflow injection vulnerability in the public GitHub repository snowflakedb/snowflake-connector-net, which allowed an attacker to execute ...