Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Diagram illustrating JWT Auth Bypass vulnerability in SharePoint 2026.

How CVE-2026-55040 Lets Attackers Hijack On‑Prem SharePoint

CyberSecureFox Editorial Team

The CVE-2026-55040 vulnerability (CVSS 9.1) in the JSON Web Token validation pipeline on Microsoft SharePoint servers allows a remote unauthenticated ...

GPG subkey revoked graphic featuring Firefox, Linux, and Thunderbird icons.

Why Mozilla Revoked Its Firefox and Thunderbird Linux Signing Key

CyberSecureFox Editorial Team

Mozilla has revoked the cryptographic subkey (subkey) used to sign Firefox and Thunderbird downloads for Linux, after an unencrypted copy ...

Malware attack on macOS targeting crypto wallets and passwords.

Go-based macOS stealer uses ClickFix to drain crypto wallets

CyberSecureFox Editorial Team

Researchers at Huntress have documented a campaign in which ClickFix-style attacks are used to deliver Go-based malware to macOS. The ...

** Vishing attack graphic highlighting UNC6671 and cloud accounts.

How UNC6671 Uses Vishing and AitM to Breach Okta and Microsoft 365

CyberSecureFox Editorial Team

The extortion group UNC6671 is conducting a large-scale voice phishing (vishing) campaign against financial, legal and technology organizations in North ...

Conceptual illustration of Google ADK CI/CD workflows with key elements.

Prompt-injection bugs let low-priv bots trigger privileged CI in Google ADK

CyberSecureFox Editorial Team

Researchers at Pillar Security identified two vulnerabilities in the automation of the Google Agent Development Kit (ADK) for Python GitHub ...

Visual representation of AitM phishing targeting Microsoft 365 financial accounts.

Arctic Wolf exposes MFA-bypassing BEC against Microsoft 365

CyberSecureFox Editorial Team

Researchers at Arctic Wolf Labs have recorded a large-scale phishing campaign targeting Microsoft 365 accounts. The attackers use an adversary-in-the-middle ...

Malicious VS Code extension 'Solidity Pro' depicted stealing crypto assets.

Solidity Pro: malicious VS Code extension targeting Web3 developers

CyberSecureFox Editorial Team

Researchers from Yeeth Security discovered the malicious Solidity Pro extension for Microsoft Visual Studio Code which, while masquerading as a ...

Progress Kemp LoadMaster connected to multiple servers, highlighting CVE-2026-8037.

Progress Kemp LoadMaster CVE-2026-8037 Actively Exploited

CyberSecureFox Editorial Team

On August 7, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added vulnerability CVE-2026-8037 to the Known Exploited Vulnerabilities ...

Graphic depicting a hacker, cloud breach, and legal gavel related to Snowflake.

Snowflake Data Theft: Canadian Behind UNC5537 Admits Guilt

CyberSecureFox Editorial Team

26-year-old Canadian Connor Riley Moucka

Diagram illustrating Google Blogger's malware detection process with flagged blogs.

Mass False Positives Lock Blogger Sites After August 4, 2026 Glitch

CyberSecureFox Editorial Team

On August 4, 2026, the automatic moderation system of Google Blogger began massively blocking legitimate blogs, mistakenly classifying them as ...