Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

** Vishing attack graphic highlighting UNC6671 and cloud accounts.

How UNC6671 Uses Vishing and AitM to Breach Okta and Microsoft 365

CyberSecureFox Editorial Team

The extortion group UNC6671 is conducting a large-scale voice phishing (vishing) campaign against financial, legal and technology organizations in North ...

Conceptual illustration of Google ADK CI/CD workflows with key elements.

Prompt-injection bugs let low-priv bots trigger privileged CI in Google ADK

CyberSecureFox Editorial Team

Researchers at Pillar Security identified two vulnerabilities in the automation of the Google Agent Development Kit (ADK) for Python GitHub ...

Visual representation of AitM phishing targeting Microsoft 365 financial accounts.

Arctic Wolf exposes MFA-bypassing BEC against Microsoft 365

CyberSecureFox Editorial Team

Researchers at Arctic Wolf Labs have recorded a large-scale phishing campaign targeting Microsoft 365 accounts. The attackers use an adversary-in-the-middle ...

Malicious VS Code extension 'Solidity Pro' depicted stealing crypto assets.

Solidity Pro: malicious VS Code extension targeting Web3 developers

CyberSecureFox Editorial Team

Researchers from Yeeth Security discovered the malicious Solidity Pro extension for Microsoft Visual Studio Code which, while masquerading as a ...

Progress Kemp LoadMaster connected to multiple servers, highlighting CVE-2026-8037.

Progress Kemp LoadMaster CVE-2026-8037 Actively Exploited

CyberSecureFox Editorial Team

On August 7, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added vulnerability CVE-2026-8037 to the Known Exploited Vulnerabilities ...

Graphic depicting a hacker, cloud breach, and legal gavel related to Snowflake.

Snowflake Data Theft: Canadian Behind UNC5537 Admits Guilt

CyberSecureFox Editorial Team

26-year-old Canadian Connor Riley Moucka

Diagram illustrating Google Blogger's malware detection process with flagged blogs.

Mass False Positives Lock Blogger Sites After August 4, 2026 Glitch

CyberSecureFox Editorial Team

On August 4, 2026, the automatic moderation system of Google Blogger began massively blocking legitimate blogs, mistakenly classifying them as ...

Visual representation of cyber threats related to ScreenConnect abuse.

Attackers Abuse ScreenConnect and Fake Roblox Cheats to Deliver Malware

CyberSecureFox Editorial Team

Researchers at Securonix have uncovered an active multi-wave campaign dubbed SMOKE#SCREEN, in which attackers use phishing lures — fake Adobe ...

Key vulnerability icons representing HashiCorp, Veeam, and Django fixes.

HashiCorp, Veeam and Django patch 11 new CVEs in 2026

CyberSecureFox Editorial Team

HashiCorp, Veeam and the Django Software Foundation released fixes in early August 2026 for 11 vulnerabilities, three of which are ...

TeamCity interface displaying a highlighted RCE vulnerability alert.

Active Exploitation of CVE-2026-63077 in JetBrains TeamCity Confirmed by CISA

CyberSecureFox Editorial Team

CISA on August 5, 2026 added the vulnerability CVE-2026-63077 to the Known Exploited Vulnerabilities (KEV) catalog, confirming its active exploitation. ...