Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Cisco servers illustrating VPN DoS flaw CVE-2026-20349 with alert symbol.

Exploitation of Cisco ASA and FTD VPN vulnerability CVE-2026-20349

CyberSecureFox Editorial Team

Cisco has confirmed active exploitation of vulnerability CVE-2026-20349 (CVSS 8.6) in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall ...

Visual representation of Windows security patching with afd.sys file and shield.

August 2026 Microsoft Patch Tuesday: Priority Guidance for CVE-2026-68820

CyberSecureFox Editorial Team

Microsoft’s August security update addresses CVE-2026-68820 — a privilege escalation vulnerability in the Windows kernel driver afd.sys that, according to ...

Graphic representation of GPT-5.6-Cyber AI with technological elements.

How OpenAI’s GPT-5.6-Cyber Changes Cyber Defense

CyberSecureFox Editorial Team

OpenAI has introduced the specialized model GPT-5.6-Cyber, designed for zero-day vulnerability discovery, exploit chain development, and incident response. The model ...

Diagram illustrating JWT Auth Bypass vulnerability in SharePoint 2026.

How CVE-2026-55040 Lets Attackers Hijack On‑Prem SharePoint

CyberSecureFox Editorial Team

The CVE-2026-55040 vulnerability (CVSS 9.1) in the JSON Web Token validation pipeline on Microsoft SharePoint servers allows a remote unauthenticated ...

GPG subkey revoked graphic featuring Firefox, Linux, and Thunderbird icons.

Why Mozilla Revoked Its Firefox and Thunderbird Linux Signing Key

CyberSecureFox Editorial Team

Mozilla has revoked the cryptographic subkey (subkey) used to sign Firefox and Thunderbird downloads for Linux, after an unencrypted copy ...

Malware attack on macOS targeting crypto wallets and passwords.

Go-based macOS stealer uses ClickFix to drain crypto wallets

CyberSecureFox Editorial Team

Researchers at Huntress have documented a campaign in which ClickFix-style attacks are used to deliver Go-based malware to macOS. The ...

** Vishing attack graphic highlighting UNC6671 and cloud accounts.

How UNC6671 Uses Vishing and AitM to Breach Okta and Microsoft 365

CyberSecureFox Editorial Team

The extortion group UNC6671 is conducting a large-scale voice phishing (vishing) campaign against financial, legal and technology organizations in North ...

Conceptual illustration of Google ADK CI/CD workflows with key elements.

Prompt-injection bugs let low-priv bots trigger privileged CI in Google ADK

CyberSecureFox Editorial Team

Researchers at Pillar Security identified two vulnerabilities in the automation of the Google Agent Development Kit (ADK) for Python GitHub ...

Visual representation of AitM phishing targeting Microsoft 365 financial accounts.

Arctic Wolf exposes MFA-bypassing BEC against Microsoft 365

CyberSecureFox Editorial Team

Researchers at Arctic Wolf Labs have recorded a large-scale phishing campaign targeting Microsoft 365 accounts. The attackers use an adversary-in-the-middle ...

Malicious VS Code extension 'Solidity Pro' depicted stealing crypto assets.

Solidity Pro: malicious VS Code extension targeting Web3 developers

CyberSecureFox Editorial Team

Researchers from Yeeth Security discovered the malicious Solidity Pro extension for Microsoft Visual Studio Code which, while masquerading as a ...