Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Visual representation of CVE-2026-0257 linked to Qilin ransomware.

Qilin Ransomware Campaign Exploits PAN-OS CVE-2026-0257 Auth Bypass

CyberSecureFox Editorial Team

The authentication bypass vulnerability CVE-2026-0257 (CVSS 7.8) in the portal and gateway components of Palo Alto Networks PAN-OS is, according ...

Mobile screen displaying AI bots and code, illustrating RCE attacks.

Researchers Show Invisible Screen Prompts Can Lead to RCE on Mobile AI Agents

CyberSecureFox Editorial Team

A team of researchers from Simon Fraser University, the Chinese University of Hong Kong, Shandong University and the Xingtu (QAX) ...

Digital representation of code interaction with AWS Kiro IDE interface.

Remote Code Execution in AWS Kiro IDE Through MCP Configuration Abuse

CyberSecureFox Editorial Team

Researchers from Intezer together with Kodem Security discovered in the agentic IDE AWS Kiro an attack chain that allowed an ...

Visual representation of WebDAV malware related to CVE-2025-33053.

Inside the WebDAV Malware Delivery Lab Behind the Mexico CURP Scam

CyberSecureFox Editorial Team

Researchers at Rapid7 discovered an unsecured malware delivery server containing 1,048 files — ranging from phishing lure templates and filename ...

Graphic illustrating the HollowGraph backdoor in Microsoft 365 Calendar.

How HollowGraph Uses Microsoft 365 Calendars for Covert C2

CyberSecureFox Editorial Team

Researchers from Group-IB have discovered a spyware implant called HollowGraph that uses the calendar of a compromised Microsoft 365 account ...

Visual representation of Daxin Rootkit and Stupig Backdoor threats in Taiwan.

Long-Lived Daxin Rootkit and Stupig Backdoor in Taiwanese Tech Network

CyberSecureFox Editorial Team

Teams from Symantec and the Carbon Black Threat Hunter Team have discovered an active instance of the Daxin rootkit on ...

Diagram showing data transfer from a laptop to cloud storage with warning sign.

How xAI’s Grok Build Tool Sent Full Git Repositories to Its Cloud

CyberSecureFox Editorial Team

The Grok Build CLI tool from xAI, designed to help with writing code, was, according to a researcher, uploading to ...

Visual representation of Secure Boot concepts with UEFI and Microsoft's role.

ESET finds vulnerable legacy UEFI shims undermining Secure Boot

CyberSecureFox Editorial Team

Researchers at ESET identified 11 legacy UEFI bootloaders (so-called shims) signed by Microsoft that are still considered trusted on most ...

Visual representation of CVE-2026-58644 affecting SharePoint system.

What CVE-2026-58644 in Microsoft SharePoint Means for Security

CyberSecureFox Editorial Team

On July 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2026-58644 vulnerability in Microsoft SharePoint Server ...

Visual representation of ClickLock Stealer malware affecting a macOS device.

How ClickLock Stealer Forces macOS Users to Give Up Passwords

CyberSecureFox Editorial Team

Researchers at Group-IB have discovered a new macOS infostealer, ClickLock Stealer, which uses a fundamentally different approach to obtaining the ...