Critical
Advisory
A NetScaler bug that Citrix documented as a crash in June turned out to be unauthenticated remote code execution as root. Exploitation began days after a public write-up, and CISA…
CBN-2026-020/ 27 Aug 2026
/
Cyber_Reporter
Read advisory
Medium
Report
Two INTERPOL publications this month bear directly on Mauritian businesses. Reported losses across the continent more than doubled to USD 484 million, and an eight-month operation against West African BEC…
CBN-2026-033/ 26 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
A path traversal in the vCenter syslog server went from vendor advisory to mass exploitation in five days. Researchers counted 361 victim addresses across 47 countries, and the implant left…
CBN-2026-022/ 13 Aug 2026
/
Cyber_Reporter
Read advisory
High
Advisory
A six-agency advisory documents Gunra actors deleting backup and archive data on backup infrastructure at both the production data centre and the disaster recovery centre. The same administrative credentials reached…
CBN-2026-025/ 11 Aug 2026
/
Cyber_Reporter
Read advisory
High
Advisory
Operators spoof your help-desk number, call employees on personal phones, and tell them to enrol a passkey immediately. The page is a reverse proxy. Once inside they register their own…
CBN-2026-031/ 7 Aug 2026
/
Cyber_Reporter
Read advisory
High
Report
Unit 42 profiled a ransomware-as-a-service operation that claimed around 580 victims across 77 countries in under a year. The growth driver is commercial rather than technical — a 90% affiliate…
CBN-2026-027/ 7 Aug 2026
/
Cyber_Reporter
Read advisory
High
Advisory
Attackers ask Microsoft for a device code, send it to your user, and the user types it into the genuine login page. No password prompt, no MFA challenge, no phishing…
CBN-2026-030/ 5 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
Two chained flaws gave unauthenticated root on SonicWall's SMA1000 VPN appliances three weeks before a patch existed. Attackers took user credentials and TOTP seeds, which means patching alone does not…
CBN-2026-021/ 3 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
Attackers are chaining a missing-authentication bug, a deserialisation bug and a spoofing bug against on-premises SharePoint, then stealing IIS machine keys so they can forge their own payloads afterwards. One…
CBN-2026-023/ 16 Jul 2026
/
Cyber_Reporter
Read advisory
Informational
Guide
GN 117 of 2026 turns a loose expectation under the Data Protection Act 2017 into an enforceable appointment and notification duty. The DPO must be independent, report to the highest…
CBN-2026-034/ 10 Jul 2026
/
Cyber_Reporter
Read advisory
Informational
Report
Sophos surveyed 2,158 organisations that were actually hit by ransomware. Four in five attacks started with an identity, 97% of credential-driven breaches had MFA enabled, and two thirds of encrypted…
CBN-2026-028/ 12 Jun 2026
/
Cyber_Reporter
Read advisory
High
Advisory
Veeam Backup & Replication took seven critical vulnerabilities in March and another remote code execution flaw in June. Every one of them needs only a low-privilege authenticated domain account —…
CBN-2026-026/ 10 Jun 2026
/
Cyber_Reporter
Read advisory