News

EY Discloses Data Breach After Third-Party Support Platform Exposes Client Tax Information

The CyberSec Guru

EY confirms a data breach after attackers compromised a third-party support platform, exposing sensitive tax client information. Here's what happened

Critical Oracle E-Business Suite Flaw Under Active Exploitation

Critical Oracle E-Business Suite Flaw Under Active Exploitation, CISA Issues Urgent Warning

The CyberSec Guru

CISA confirms active exploitation of Oracle E-Business Suite vulnerability CVE-2026-46817. Learn who is affected, the risks, and how to protect your systems

7-Zip Vulnerability Could Allow Remote Code Execution

7-Zip Vulnerability Could Allow Remote Code Execution, Users Urged to Update Immediately

The CyberSec Guru

Millions of 7-Zip users are urged to update after CVE-2026-14266, a heap buffer overflow vulnerability that could lead to remote code execution

F5 Patches High-Severity NGINX Vulnerabilities

F5 Patches High-Severity NGINX Vulnerabilities That Could Lead to Code Execution

The CyberSec Guru

F5 patches three high-severity NGINX vulnerabilities, including CVE-2026-42533, that could enable memory corruption, crashes, and code execution

ServiceNow CVE-2026-6875

ServiceNow Patches Critical AI Platform RCE (CVE-2026-6875), Says No Active Exploitation Observed

The CyberSec Guru

ServiceNow has patched CVE-2026-6875, a critical AI platform sandbox escape vulnerability that could allow unauthenticated RCE

CISA Warns of Exploited SonicWall

SonicWall Warns of Actively Exploited SMA 1000 Zero-Days as CISA Adds Flaws to KEV Catalog

The CyberSec Guru

SonicWall has patched two actively exploited SMA 1000 zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. CISA added both to KEV

Windows BitLocker Zero-Day Allows Physical Bypass of Disk Encryption (CVE-2026-50661)

The CyberSec Guru

Microsoft fixes CVE-2026-50661, a publicly disclosed BitLocker zero-day that allows attackers with physical access to bypass Windows disk encryption

FortiSandbox Vulnerability

FortiSandbox Vulnerability Exposes Malware Analysis VMs Through Unauthenticated VNC Access

The CyberSec Guru

Fortinet has disclosed CVE-2026-59835, a high-severity FortiSandbox vulnerability that allows unauthenticated access to VNC servers of malware analysis VMs

Progress Confirms ShareFile Zero-Day Behind Emergency Storage Zone Shutdown

Progress Confirms ShareFile Zero-Day Behind Emergency Storage Zone Shutdown, Releases Security Updates

The CyberSec Guru

Progress Software has released patches for a high-severity ShareFile Storage Zone Controller zero-day after previously urging customers to immediately shut down vulnerable Windows servers

SAP Warns of Critical NetWeaver and Commerce Cloud Vulnerabilities

SAP Warns of Critical NetWeaver and Commerce Cloud Vulnerabilities

The CyberSec Guru

SAP fixed 16 vulnerabilities in July 2026, including three critical flaws in NetWeaver ABAP, Approuter, and Commerce Cloud. Here is what to patch