Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
CVE-2026-87902: local file inclusion vulnerability in WordPress — who is affected and how to stay protected
On September 22, 2026, WordPress released the emergency update 7.1.2, which fixes the critical vulnerability CVE-2026-87902 (CVSS 9.2) in the ...
ShinyHunters claims it hacked the FBI: what has been confirmed and what remains just hacker claims
On September 22, 2026, the ShinyHunters group claimed it had compromised systems of the U.S. Federal Bureau of Investigation (FBI) ...
BigDiskBuster — public PoC that can block Microsoft Defender updates by filling the disk
On September 19, a tool called BigDiskBuster was published on GitHub — a proof of concept designed to block platform ...
CVE-2026-65660 in SharePoint: spoofing or remote code execution — what is known and what to do
On 11 August 2026, Microsoft released security updates for SharePoint Server 2016, 2019, and Subscription Edition to fix the vulnerability ...
Unauthenticated command execution in Bifrost via MCP client registration
Two vulnerabilities have been discovered in the open AI gateway Bifrost, which routes requests to more than 20 large language ...
Active exploitation of vulnerabilities in Zyxel GS1900 switches and Veeam Agent for Windows
On 21 September 2026, CISA added the critical CVE-2026-7273 vulnerability in Zyxel GS1900 switches to the Known Exploited Vulnerabilities (KEV) ...
Critical CVE-2026-93952 vulnerability in VeloCloud Orchestrator is being actively exploited — patches are not available for all versions
On 22 September 2026, Arista published Security Advisory 0183 describing the critical vulnerability CVE-2026-93952 in VeloCloud Orchestrator On-Prem — the ...
Libheif vulnerability allowed researchers to access OpenAI employee accounts via the forum
The CVE-2026-32882 vulnerability in the image-processing library libheif became a key link in an attack chain that, according to research ...
Microsoft fixes critical Azure AI Foundry vulnerability and five other serious bugs
Microsoft has announced that it has fixed six vulnerabilities, including CVE-2026-85889 with a maximum CVSS score of 10.0 in the ...
Click2Shell vulnerability in WordPress allows installing a theme without the administrator’s knowledge
On September 17, 2026, WordPress released version 7.1.1 — an emergency security update that fixes a vulnerability allowing a specially ...