Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Exploitable Auth Bypass in miniOrange SAML 2.0 SSO for WordPress
Two critical authentication bypass vulnerabilities have been discovered in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, ...
CVE-2026-21962: Critical Oracle HTTP Server Flaw Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on August 24, 2026 added vulnerability CVE-2026-21962 with a maximum CVSS score ...
Global Jackal IV Operation Hits West African Fraud Networks
The eight-month international operation Jackal IV, coordinated by INTERPOL and involving 22 countries across six continents, resulted in the arrest ...
Active Exploitation of Gitea CVE-2026-60004 Confirmed by CISA
CISA on August 25, 2026 confirmed active exploitation of the critical vulnerability CVE-2026-60004 in the Git repository management platform Gitea ...
Unauthenticated Command Execution Chain in NASA’s AIT-GUI
Security researchers from Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for the open framework ...
GitLab CVE-2026-19478: unauthenticated project modification risk
A critical vulnerability CVE-2026-19478 with a CVSS 9.4 score has been discovered in GitLab Community Edition and Enterprise Edition. It ...
How CVE-2026-69836 Exposed Microsoft Entra ID to Remote Code Execution
Microsoft has disclosed CVE-2026-69836, a remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory) with the maximum ...
Critical macOS, vCenter, SharePoint and IKE Bugs Added to CISA KEV
On August 18, 2026, CISA added four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, confirming that they are ...