Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Visualization of Cisco SD-WAN controller with a security vulnerability highlighted.

Urgent Cisco Catalyst SD-WAN Patching for CVE-2026-20182

CyberSecureFox Editorial Team

On 14 May 2026, CISA added the vulnerability CVE-2026-20182 to the Known Exploited Vulnerabilities (KEV) catalog, setting a remediation deadline ...

Visual representation of CVE-2026-44338 with robots and security elements.

CVE-2026-44338: Authentication Bypass in PraisonAI API

CyberSecureFox Editorial Team

The critical authentication bypass vulnerability CVE-2026-44338 (CVSS 7.3) in the open multi-agent orchestration framework PraisonAI became the target of active ...

Digital keys representing vulnerabilities threatening Windows security.

Unpatched BitLocker Bypass and Privilege Escalation in Windows

CyberSecureFox Editorial Team

A researcher using the handle Chaotic Eclipse (Nightmare-Eclipse), who previously disclosed three vulnerabilities in Microsoft Defender, has published information on ...

Graphic illustrating the Fragnesia CVE-2026-46300 Linux kernel vulnerability.

Fragnesia Linux Kernel LPE via ESP-in-TCP (CVE-2026-46300)

CyberSecureFox Editorial Team

The CVE-2026-46300 vulnerability, dubbed Fragnesia, allows an unprivileged local attacker to gain root privileges by corrupting the Linux kernel page ...

Digital artwork of a cyber attack targeting Azerbaijan's oil sector.

Chinese APT Repeatedly Reenters Azerbaijani Oil & Gas Through Exchange

CyberSecureFox Editorial Team

According to Bitdefender researchers, the Chinese cyber-espionage group FamousSparrow carried out a multi-stage operation against an unnamed Azerbaijani oil and ...

Computer with Windows logo under attack, featuring network elements.

Inside MDASH: Microsoft’s Agentic AI for Windows Vulnerability Discovery

CyberSecureFox Editorial Team

Microsoft announced the MDASH (Multi-model Agentic Scanning Harness) system—a multi-model agentic platform for automated detection, validation, and proof of exploitability ...

NGINX logo with broken server, illustrating CVE-2026-42945 vulnerability.

NGINX Rift (CVE-2026-42945): 18-Year Bug Enables RCE

CyberSecureFox Editorial Team

A critical vulnerability CVE-2026-42945 (NGINX Rift, CVSS v4 9.2) has been identified in NGINX Plus and NGINX Open Source, in ...

cPanel and WHM interface with a warning about CVE-2026-41940 vulnerability.

How alleged cPanel CVE-2026-41940 is exploited for backdoors

CyberSecureFox Editorial Team

A critical vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940, is, according to researchers from QiAnXin XLab, being ...

Snake emerging from a box on a laptop, representing a cybersecurity threat.

Typosquatted Hugging Face Repository Used in AI Supply Chain Attack

CyberSecureFox Editorial Team

The malicious Open-OSS/privacy-filter repository on the Hugging Face platform, masquerading as the legitimate OpenAI Privacy Filter model, was used to ...

Giant worm labeled "Mini Shai-Hulud" emerging from a box with package icons.

How the Mini Shai-Hulud Worm Compromised npm and PyPI Supply Chains

CyberSecureFox Editorial Team

Mini Shai-Hulud, linked to the TeamPCP group, has become one of the most dangerous worms in the npm and PyPI ...

123194 Next