Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
CVE-2026-33825 BlueHammer: Windows LPE Exploit and Researcher–Microsoft Conflict
The local privilege escalation vulnerability CVE-2026-33825 affecting Microsoft Windows has become the starting point of a public conflict between a ...
CVE-2026-10702: Public Exploit and Firefox 151.0.3 Patch
Mozilla has released an emergency update Firefox 151.0.3 that fixes the high-severity vulnerability CVE-2026-10702 in the browser’s JIT compiler. The ...
How CVE-2026-60004 Exposes Gitea and Why You Must Upgrade
Gitea has fixed a critical remote code execution vulnerability (CVE-2026-60004, CVSS 9.8) that allows a user with write access to ...
CVE-2013-4786: IPMI Password Hash Exposure Puts BMCs at Risk
According to researchers at Lava, more than 36,000 Baseboard Management Controllers (BMC) using the IPMI protocol are reachable from the ...
Critical DHCPv6 buffer overflow in odhcpd patched in OpenWrt
The OpenWrt project has released version 24.10.8, which fixes the critical vulnerability CVE-2026-53921 (CVSS 3.1: 9.8) — a stack buffer ...
NightLedger, BridgeHead and ArcBridge Used in Targeted Attacks
According researchers, the Iranian group Nimbus Manticore (also known as Mirage Kitten, Smoke Sandstorm, UNC1549) is carrying out a series ...
How MAI-Cyber-1-Flash fits into Microsoft’s MDASH cyber strategy
Microsoft has introduced MAI-Cyber-1-Flash, its first artificial intelligence model designed specifically for cybersecurity tasks. The model runs exclusively inside MDASH, ...
Arista VeloCloud Orchestrator CVE-2026-16812 Under Active Exploitation
The critical vulnerability CVE-2026-16812 with a maximum CVSS score of 10.0 in on-premises versions of Arista VeloCloud Orchestrator (VCO) has ...
Inside NVIDIA’s Open Secure AI Alliance and the NOOA agent framework
NVIDIA, together with 36 organizations, announced the creation of the Open Secure AI Alliance—a coalition to develop open technologies for ...
How Operation BlueDash abuses RMM tools via Microsoft Teams lures
Researchers from ZeroBEC disclosed details of the phishing campaign Operation BlueDash, in which attackers use fake Microsoft Teams update pages ...