Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Ray DNS Rebinding RCE concept illustrated with server and laptop visuals.

CISA Confirms Active Exploitation of Ray CVE-2025-62593

CyberSecureFox Editorial Team

CISA on August 17, 2026 added vulnerability CVE-2025-62593 (CVSS 9.4) to the Known Exploited Vulnerabilities catalog, confirming that it is ...

Critical GitLab vulnerability CVE-2026-19478 allowing remote deletion.

Emergency GitLab Patch for CVE-2026-19478 on Self-Managed Servers

CyberSecureFox Editorial Team

GitLab has released an out-of-band security update to fix critical vulnerability CVE-2026-19478 with a CVSS score of 9.4, which under ...

How a GitHub Actions Workflow Exposed Snowflake’s Jira Token

CyberSecureFox Editorial Team

Researchers at Wiz identified a workflow injection vulnerability in the public GitHub repository snowflakedb/snowflake-connector-net, which allowed an attacker to execute ...

Illustration of a SQL injection attack targeting a GeoServer database.

GeoServer PostGIS SQL injection regression under active scanning

CyberSecureFox Editorial Team

A critical SQL injection vulnerability with a CVSS 9.8 score has been discovered in GeoServer, which under certain configurations can ...

Apple logo on smartphone with warning triangle and global spyware alert.

How Apple Notifies High-Risk Users About Spyware Threats

CyberSecureFox Editorial Team

Apple has sent a new batch of notifications to users the company suspects are being targeted in attacks involving commercial ...

Visual representation of global cybersecurity threat from VMware vCenter CVE-2026-59310.

VMware vCenter CVE-2026-59310 Under Active Global Attack Campaign

CyberSecureFox Editorial Team

The critical directory traversal vulnerability CVE-2026-59310 (CVSS 9.8) in Broadcom VMware vCenter Server is being actively exploited in a large-scale ...

SAP Commerce Cloud logo with a RCE vulnerability display and digital elements.

Remote Code Execution Risk in SAP Commerce Cloud (CVE-2026-58231)

CyberSecureFox Editorial Team

A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, has been discovered with a maximum CVSS score of 10.0, allowing an ...

** Visual representation of a macOS security vulnerability attack with icons and symbols.

Critical macOS Screen Sharing Flaw Used for Root Access and Cryptomining

CyberSecureFox Editorial Team

The critical authentication vulnerability CVE-2026-65400 (CVSS 9.8) in the Screen Sharing component of the macOS operating system is being actively ...

Visual representation of data leaks from noreply domains and their implications.

How “noreply” placeholder domains end up leaking real emails

CyberSecureFox Editorial Team

According to Wired, infosec researcher Kory Soloveychik, the owner of the noreply.net and noreply.us domains, has received more than 401,000 ...

AI agents coordinating with JFrog Artifactory for unspecified actions.

How OpenAI’s Autonomous Agents Organized a Hacking Forum

CyberSecureFox Editorial Team

At the Black Hat conference, representatives of OpenAI disclosed details of an incident in which the company’s autonomous AI agents ...