Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Visual representation of malware targeting traders via browser assembly.

How the SourTrade browser-assembled malware targets retail crypto traders

CyberSecureFox Editorial Team

Researchers at Confiant have disclosed details of a malvertising campaign called SourTrade, in which the victim’s browser independently assembles the ...

Fastjson jar displaying CVE-2026-16723 alert with data interactions.

Fastjson 1.x CVE-2026-16723 RCE: impact, exploits, fixes

CyberSecureFox Editorial Team

The critical remote code execution vulnerability CVE-2026-16723 in the Alibaba Fastjson 1.x library (versions 1.2.68–1.2.83) allows an attacker to execute ...

Zoom and Teams icons linked to a phishing hook and a Bitcoin wallet.

Inside BlueNoroff’s ClickFix Kit Masquerading as Zoom and Teams

CyberSecureFox Editorial Team

Researchers at JUMPSEC have disclosed details of an active phishing platform that, according to their findings, is linked to the ...

Digital illustration of a chatbot emphasizing cybersecurity concepts.

How the AgentForger CSRF Bug Turned ChatGPT Agents into Corporate Insiders

CyberSecureFox Editorial Team

Researchers from Zenity Labs disclosed a CSRF-class vulnerability in the OpenAI ChatGPT Agent Builder tool, which received the codename AgentForger. ...

Visual representation of a critical vulnerability related to Bing and ImageMagick.

How Bing’s image pipeline exposed critical RCE via ImageMagick delegates

CyberSecureFox Editorial Team

Microsoft has assigned two critical CVEs — CVE-2026-32194 and CVE-2026-32191 — to vulnerabilities in Bing’s image-processing infrastructure, each with a ...

WordPress logo with chains breaking and an RCE symbol emerging from a door.

How the wp2shell Vulnerability Chain Enables RCE on Vanilla WordPress

CyberSecureFox Editorial Team

Two critical vulnerabilities in WordPress — CVE-2026-63030 and CVE-2026-60137 — are being actively exploited by attackers in a chained exploit ...

Visual representation of a critical vulnerability in ServiceNow AI Platform.

CVE-2026-6875: Pre-auth Sandbox Escape RCE in ServiceNow AI Platform

CyberSecureFox Editorial Team

A critical vulnerability CVE-2026-6875 with a CVSS 9.5 score has been discovered in the ServiceNow AI Platform, allowing an unauthenticated ...

AI agent interacts with SmartLoader malware in an abstract digital space.

How FakeGit Exploits MCP Servers and AI Agents for StealC Theft

CyberSecureFox Editorial Team

Researchers from Island have identified a large-scale campaign dubbed FakeGit: according to their data, around 7,600 malicious repositories on GitHub, ...

Visual representation of Google Gemini 3.5 Flash Cyber for code security.

How Gemini 3.5 Flash Cyber Reimagines AI Code Defense

CyberSecureFox Editorial Team

Google DeepMind has introduced Gemini 3.5 Flash Cyber — a specialized artificial intelligence model designed to detect, validate, and remediate ...

Visual representation of CVE-2026-0257 linked to Qilin ransomware.

Qilin Ransomware Campaign Exploits PAN-OS CVE-2026-0257 Auth Bypass

CyberSecureFox Editorial Team

The authentication bypass vulnerability CVE-2026-0257 (CVSS 7.8) in the portal and gateway components of Palo Alto Networks PAN-OS is, according ...