Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Blue shield with Drupal logo cracking under a red beam, signifying security alert.

Upcoming Drupal Core Security Fix for High-Severity Vulnerability

CyberSecureFox Editorial Team

Drupal has announced a planned release of a core security update for all supported branches, scheduled for May 20, 2026, ...

Diagram illustrating a GitHub Actions supply chain attack with commits.

Compromised GitHub Actions Steal CI/CD Credentials via Runner Memory

CyberSecureFox Editorial Team

The popular GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment have been compromised through a supply-chain attack: all existing tags in the repositories ...

Illustrated visualization of the Mini Shai-Hulud npm attack on AntV supply chain.

How the Mini Shai-Hulud Worm Compromised AntV npm Packages

CyberSecureFox Editorial Team

A large-scale npm supply chain attack has affected hundreds of packages in the @antv ecosystem — a popular data visualization ...

INTERPOL shield with cyber servers and MENA map highlighting disrupted crime.

How INTERPOL’s Operation Ramz Reshapes Cybercrime Enforcement in MENA

CyberSecureFox Editorial Team

INTERPOL has concluded an unprecedented coordinated anti-cybercrime operation in the Middle East and North Africa (MENA) region. Operation Ramz, conducted ...

Illustration depicting a digital worm emerging from an npm package box, symbolizing threats.

Analysis of Malicious npm Packages Delivering Shai-Hulud and More

CyberSecureFox Editorial Team

Researchers from OX Security discovered four malicious npm packages published by the same user but containing fundamentally different malicious payloads ...

Graphic depicting critical patches for SAP and other software in May 2026.

How SAP, Fortinet, n8n and Others Fixed 11 Critical Bugs in May 2026

CyberSecureFox Editorial Team

In May 2026, five major vendors — Ivanti, Fortinet, SAP, n8n and Broadcom (VMware) — released fixes for 11 critical ...

Visual representation of Fast16 malware impacting nuclear simulations.

How the Fast16 Framework Targeted Uranium Compression Modeling

CyberSecureFox Editorial Team

According to researchers from Symantec and Carbon Black (part of Broadcom), the Lua-based malicious framework fast16 was designed to deliberately ...

Illustration of a MiniPlasma exploit targeting a Windows system bug.

MiniPlasma: Public cldflt.sys Exploit Grants SYSTEM on Fully Patched Windows

CyberSecureFox Editorial Team

A security researcher under the alias Chaotic Eclipse has released a working exploit named MiniPlasma, which allows obtaining SYSTEM-level privileges ...

NGINX logo with CVE-2026-42945 and openDCIM under attack visualization.

Active Exploitation of NGINX CVE-2026-42945 and openDCIM Flaws

CyberSecureFox Editorial Team

The critical vulnerability CVE-2026-42945 in NGINX Plus and NGINX Open, which allows an attacker to cause denial of service or, ...

Illustration depicting an XSS attack on Exchange Server with related elements.

How CVE-2026-42897 Puts On-Premises Exchange Servers at Risk

CyberSecureFox Editorial Team

Microsoft has disclosed vulnerability CVE-2026-42897 (CVSS 8.1) in on-premises versions of Exchange Server, which is already being actively exploited by ...

123195 Next