Gitea Security Flaw Exposes Private Container Images Without Login 

A major security vulnerability has been discovered in Gitea, a widely used open-source Git hosting platform. Researchers revealed that the flaw could allow anyone to access private container images without logging in. The issue has been identified as CVE-2026-27771 and affects versions earlier than 1.26.2. Security experts warned that the vulnerability could expose sensitive software … Continued

Microsoft Defender Can Now Automatically Isolate Hacked Endpoints During Cyberattacks 

Microsoft has introduced a new cybersecurity feature in Microsoft Defender for Endpoint that can automatically isolate compromised devices during an active cyberattack. The feature is currently available in preview mode and is designed to help organizations stop attacks before they spread across the network. It works as part of Microsoft’s growing focus on automated cyber … Continued

Hackers Hijack 700+ Ghost CMS Websites in Massive ClickFix Malware Campaign 

A critical vulnerability in Ghost CMS, identified as CVE-2026-26980, has been exploited by attackers in a large-scale malware campaign. Security researchers confirmed that more than 700 websites were compromised during the attacks. The flaw received a high severity score of 9.4 because of the serious risks it created. Many of the targeted websites were running … Continued

China-Linked Webworm Hackers Exploit Discord and Microsoft Graph to Target EU Governments

China-linked cyber espionage group “Webworm” has recently been linked to a major hacking campaign targeting European government organizations and other important sectors. Security researchers discovered that the attackers were using trusted online services like Discord and Microsoft Graph to secretly communicate with infected systems. This method allowed the hackers to hide their activity inside normal … Continued

Police Shut Down “First VPN” Used by Ransomware Gangs Worldwide 

Police and international cybercrime agencies have shut down a VPN service called “First VPN” that was allegedly being used by ransomware groups and cybercriminals. Authorities said the service helped attackers hide their identities during online crimes. The operation involved several countries working together to track and seize the VPN’s infrastructure. Officials believe the platform was … Continued

Content Delivery Exploit Opens Thousands of Trusted Websites to Brand Hijacking and Malicious Script Attacks 

Cybersecurity researchers have recently warned about a serious attack method that is targeting websites through content delivery systems, also called CDNs. These systems are commonly used to improve website speed and performance by delivering files quickly to users. Many popular websites depend on third-party scripts and external services every day. Attackers are now exploiting these … Continued

Critical SEPPMail Vulnerabilities Expose Organizations to Remote Code Execution and Email Traffic Access 

SEPPMail Secure E-Mail Gateway, a platform used by many organizations for encrypted and secure email communication, has recently been found vulnerable to multiple critical security flaws. Security researchers discovered that these vulnerabilities could allow hackers to remotely access systems and even execute malicious code on affected servers. Because email gateways handle sensitive company communication every … Continued

Critical Security Alert: Ivanti, Fortinet, SAP, VMware and n8n Patch Dangerous Vulnerabilities

Several major technology companies including Ivanti, Fortinet, SAP, VMware, and n8n have released urgent security patches after researchers discovered multiple dangerous vulnerabilities in their products. The reported flaws include Remote Code Execution, SQL Injection, privilege escalation, authentication bypass, and arbitrary file access issues. Security experts are advising organizations to update affected systems immediately to avoid … Continued

Newsletter line