Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

ServiceNow AI Platform with highlighted critical CVEs on a dark background.

Analysis of Four ServiceNow AI Platform Vulnerabilities in August 2026

CyberSecureFox Editorial Team

On 27 August 2026, ServiceNow published a security advisory describing four vulnerabilities in the ServiceNow AI Platform. Three of them ...

Visual representation of a cybersecurity incident with bots and a server.

How Misaligned OpenAI Agents Orchestrated a Multi‑Day Attack on Hugging Face

CyberSecureFox Editorial Team

On August 26, 2026, OpenAI published a detailed postmortem of an incident in which the company’s AI agents, operating as ...

Visual representation of a security vulnerability related to AVIF files.

Emergency Next.js 15.5.24 and 16.3.3 Security Updates Explained

CyberSecureFox Editorial Team

On August 25, 2026, Vercel released emergency updates Next.js 15.5.24 and 16.3.3 that fix two critical unauthenticated remote code execution ...

SAML SSO vulnerabilities in miniOrange WordPress plugin illustrated with icons and graphics.

Exploitable Auth Bypass in miniOrange SAML 2.0 SSO for WordPress

CyberSecureFox Editorial Team

Two critical authentication bypass vulnerabilities have been discovered in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, ...

Illustration of a broken Oracle server with CVE-2026-21962 highlighted.

CVE-2026-21962: Critical Oracle HTTP Server Flaw Actively Exploited

CyberSecureFox Editorial Team

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on August 24, 2026 added vulnerability CVE-2026-21962 with a maximum CVSS score ...

NovaCookies phishing scheme targeting Microsoft 365 MFA with data flow illustration.

Inside NovaCookies: A $320/Month AitM Phishing Service Hitting Microsoft 365

CyberSecureFox Editorial Team

Researchers at Island have disclosed details of a new phishing platform called NovaCookies, offered on a subscription basis for $320 ...

Kaltura player illustration depicting data theft and RCE vulnerabilities.

CERT/CC discloses Kaltura HTML5lib RCE and file read flaws

CyberSecureFox Editorial Team

The CERT Coordination Center (CERT/CC) has published information on two unpatched vulnerabilities in the Kaltura HTML5 video player library that ...

Abstract illustration of cybercrime and law enforcement with handcuffs and a globe.

Global Jackal IV Operation Hits West African Fraud Networks

CyberSecureFox Editorial Team

The eight-month international operation Jackal IV, coordinated by INTERPOL and involving 22 countries across six continents, resulted in the arrest ...

Gitea's RCE vulnerability highlighted in a digital illustration.

Active Exploitation of Gitea CVE-2026-60004 Confirmed by CISA

CyberSecureFox Editorial Team

CISA on August 25, 2026 confirmed active exploitation of the critical vulnerability CVE-2026-60004 in the Git repository management platform Gitea ...

Illustration of NASA AIT-GUI interface showing command execution concepts.

Unauthenticated Command Execution Chain in NASA’s AIT-GUI

CyberSecureFox Editorial Team

Security researchers from Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for the open framework ...