Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Visual representation of iOS spyware delivery via Composer packages.

Malicious Packagist Themes Drop iOS Spyware and Steal Crypto

CyberSecureFox Editorial Team

Researchers from Socket discovered 13 malicious Composer packages on Packagist disguised as themes for the Vietnamese CMS platforms OphimCMS and ...

Visual representation of CVE vulnerabilities related to Langflow and Rails.

Remote Code Execution in Langflow and Rails Active Storage: CVE Analysis

CyberSecureFox Editorial Team

Two critical vulnerabilities — CVE-2026-0768 in the AI application development platform Langflow and CVE-2026-66066 (KindaRails2Shell) in the Active Storage component ...

Visual representation of a PowerShell reverse tunnel in cybersecurity context.

Microsoft analyzes TerminalFix attacks with DLL sideloading and AD recon

CyberSecureFox Editorial Team

Microsoft has published a detailed analysis of the new TerminalFix campaign, a variant of the ClickFix technique targeting organizations across ...

** WordPress logo with a security breach visualizing plugin vulnerabilities.

Critical Vulnerabilities in Popular WordPress Plugins and Themes

CyberSecureFox Editorial Team

Researchers from Wordfence and Patchstack have disclosed five critical vulnerabilities (CVSS 9.8–10.0) in widely used WordPress plugins and themes — ...

Android 17 smartphone surrounded by icons representing network security features.

How Android 17 Hardens Network Security with ECH and 2G Controls

CyberSecureFox Editorial Team

Android 17 (API level 37) introduces four major network security improvements: platform support for Encrypted Client Hello (ECH) to hide ...

Malicious extensions symbolized by a puzzle piece and cryptocurrency icons.

Superior campaign: wallet-draining malware in browser extensions

CyberSecureFox Editorial Team

Researchers at Socket identified a cluster of 19 malicious extensions — 18 for Google Chrome and one for Microsoft Edge ...

** Visual representation of a cyber attack targeting a nuclear center.

Chinese-Speaking Operator Uses ownCloud Flaw to Hack Philippine Nuclear Center

CyberSecureFox Editorial Team

CISA has added the critical vulnerability CVE-2023-49105 (CVSS 9.8) in the ownCloud platform to the Known Exploited Vulnerabilities (KEV) catalog ...

Unitree G1 EDU robot with network and Bluetooth connection vulnerabilities shown.

Root-level remote code execution chains in Unitree G1 EDU robots

CyberSecureFox Editorial Team

Security researcher Olivier Laflamme published details on August 27, 2026 of two independent remote code execution chains with root privileges ...

** Illustration showing Citrix NetScaler ADC with CVE-2026-8452 vulnerability highlighted.

CISA Flags Citrix NetScaler Bug and Five Other CVEs in KEV

CyberSecureFox Editorial Team

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August ...

Malware flowchart showing WordlistLoader and SynkLoader targeting Windows.

How WordlistLoader and SynkLoader expand Windows malware delivery

CyberSecureFox Editorial Team

Researchers from Gen Digital and Expel independently identified two previously unknown malware loaders — WordlistLoader and SynkLoader — each using ...