Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Diagram showcasing OXLOADER malware spreading CastleStealer via ads.

Elastic Security Labs analyzes OXLOADER and CastleStealer campaign

CyberSecureFox Editorial Team

Researchers at Elastic Security Labs have published a technical analysis of a previously unknown malware loader, OXLOADER, which is used ...

Smartphone illustration showing Android security and developer verification elements.

How Android Developer Verification Changes App Installation

CyberSecureFox Editorial Team

Starting from 30 September 2026, certified Android devices in Brazil, Indonesia, Singapore and Thailand will begin blocking standard installation of ...

D-Link routers connected by red lines to AryStinger logo in a dark setting.

How the AryStinger Botnet Exploits End-of-Life D-Link Routers

CyberSecureFox Editorial Team

Researchers from Qianxin XLab have reported a previously unknown botnet, AryStinger, which they say has compromised more than 4,000 outdated ...

Digital illustration of AryStinger Botnet concept with routers and a serpent-like figure.

How AryStinger Hijacks Old Routers and QNAP NAS for Covert Recon

CyberSecureFox Editorial Team

Researchers from QiAnXin XLab report on a new malware family, AryStinger, which infects legacy home routers based on Realtek RTL819X ...

Chrome logo and puzzle pieces representing live wallpaper extensions and ad tracking.

152 Malicious Chrome Wallpaper Extensions Used for Ad Fraud

CyberSecureFox Editorial Team

According to researchers at Socket, 152 malicious extensions were discovered in the Chrome Web Store, disguised as tools for installing ...

Visual representation of the Gravity SMTP vulnerability and its impact.

Gravity SMTP flaw leaks email API keys via unauthenticated endpoint

CyberSecureFox Editorial Team

The Gravity SMTP plugin for WordPress, installed on approximately 100,000 sites, is being massively exploited via the CVE-2026-4020 vulnerability (CVSS ...

Visual representation of SocGholish malware network disrupting fake updates.

Law Enforcement Dismantles SocGholish WordPress Malware

CyberSecureFox Editorial Team

Law enforcement agencies in the Netherlands, Canada, Germany, and the United States have conducted a coordinated operation to dismantle the ...

NGINX logo breaking through a server, highlighting critical CVE bugs.

Critical NGINX vulnerabilities CVE-2026-42530 and CVE-2026-42055 fixed by F5

CyberSecureFox Editorial Team

F5 has released security updates that address two critical vulnerabilities in NGINX Open Source and related products. Both vulnerabilities — ...

Illustration of a USB worm spreading malware via Windows computers.

Microsoft tracks Tor-based Windows crypto-clipper with USB worm

CyberSecureFox Editorial Team

The Microsoft Defender Security Research team has published an in-depth analysis of a Windows crypto-clipper campaign that combines worm-like propagation ...

Visual representation of a security flaw in Microsoft Defender, emphasizing CVE-2026-50656.

Microsoft Confirms Work on Patch for RoguePlanet CVE-2026-50656

CyberSecureFox Editorial Team

Microsoft has confirmed it is working on a fix for vulnerability CVE-2026-50656 (CVSS 7.8) in the Microsoft Malware Protection Engine, ...