Monday , September 28 2026

Alert

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Azure AI Foundry

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,” Microsoft …

Read More »

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Fortinet FortiGate

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that FortiOS 7.2.x and 7.4.x are affected. The listing has not been independently verified and does not confirm the existence of a new FortiGate zero-day vulnerability. The ad by Dark Web …

Read More »

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

FortiGate

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access trojan (RAT). This makes the affected devices key points for spying and stealing information. The SOCRadar Threat Research Unit has found that attackers are using CVE-2025-25249. This is a serious …

Read More »

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could let users and servers face cross-site scripting, email header issues, data access from other users, remote content tricks, and attacks that misuse server requests. The new versions, Roundcube 1.6.19 and …

Read More »