Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Malware flowchart showing WordlistLoader and SynkLoader targeting Windows.

How WordlistLoader and SynkLoader expand Windows malware delivery

CyberSecureFox Editorial Team

Researchers from Gen Digital and Expel independently identified two previously unknown malware loaders — WordlistLoader and SynkLoader — each using ...

Illustration showing MCP injection vulnerability and CVE-2026-75149 fix.

Marimo notebook flaw lets malicious MCP commands run on open

CyberSecureFox Editorial Team

The interactive notebook Marimo has patched a high-severity vulnerability CVE-2026-75149 that allowed an attacker to inject an arbitrary Model Context ...

WordPress logo with file upload symbol and CVE-2026-15748 details displayed.

How a Forminator Forms File Upload Bug Exposes 600,000 WordPress Sites

CyberSecureFox Editorial Team

A critical arbitrary file upload vulnerability has been discovered in the Forminator Forms plugin for WordPress, allowing an unauthenticated attacker ...

DOJ emblem with QScan and QTRouter icons against a dark background.

How China’s QTFY Used QScan/QTRouter Against US Infrastructure

CyberSecureFox Editorial Team

The US Department of Justice announced the takedown of two hacking platforms — QScan and QTRouter — which, according to ...

ServiceNow AI Platform with highlighted critical CVEs on a dark background.

Analysis of Four ServiceNow AI Platform Vulnerabilities in August 2026

CyberSecureFox Editorial Team

On 27 August 2026, ServiceNow published a security advisory describing four vulnerabilities in the ServiceNow AI Platform. Three of them ...

Visual representation of a cybersecurity incident with bots and a server.

How Misaligned OpenAI Agents Orchestrated a Multi‑Day Attack on Hugging Face

CyberSecureFox Editorial Team

On August 26, 2026, OpenAI published a detailed postmortem of an incident in which the company’s AI agents, operating as ...

Visual representation of a security vulnerability related to AVIF files.

Emergency Next.js 15.5.24 and 16.3.3 Security Updates Explained

CyberSecureFox Editorial Team

On August 25, 2026, Vercel released emergency updates Next.js 15.5.24 and 16.3.3 that fix two critical unauthenticated remote code execution ...

SAML SSO vulnerabilities in miniOrange WordPress plugin illustrated with icons and graphics.

Exploitable Auth Bypass in miniOrange SAML 2.0 SSO for WordPress

CyberSecureFox Editorial Team

Two critical authentication bypass vulnerabilities have been discovered in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, ...

Illustration of a broken Oracle server with CVE-2026-21962 highlighted.

CVE-2026-21962: Critical Oracle HTTP Server Flaw Actively Exploited

CyberSecureFox Editorial Team

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on August 24, 2026 added vulnerability CVE-2026-21962 with a maximum CVSS score ...

NovaCookies phishing scheme targeting Microsoft 365 MFA with data flow illustration.

Inside NovaCookies: A $320/Month AitM Phishing Service Hitting Microsoft 365

CyberSecureFox Editorial Team

Researchers at Island have disclosed details of a new phishing platform called NovaCookies, offered on a subscription basis for $320 ...