Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Graphic illustrating the Fragnesia CVE-2026-46300 Linux kernel vulnerability.

Fragnesia Linux Kernel LPE via ESP-in-TCP (CVE-2026-46300)

CyberSecureFox Editorial Team

The CVE-2026-46300 vulnerability, dubbed Fragnesia, allows an unprivileged local attacker to gain root privileges by corrupting the Linux kernel page ...

Digital artwork of a cyber attack targeting Azerbaijan's oil sector.

Chinese APT Repeatedly Reenters Azerbaijani Oil & Gas Through Exchange

CyberSecureFox Editorial Team

According to Bitdefender researchers, the Chinese cyber-espionage group FamousSparrow carried out a multi-stage operation against an unnamed Azerbaijani oil and ...

Computer with Windows logo under attack, featuring network elements.

Inside MDASH: Microsoft’s Agentic AI for Windows Vulnerability Discovery

CyberSecureFox Editorial Team

Microsoft announced the MDASH (Multi-model Agentic Scanning Harness) system—a multi-model agentic platform for automated detection, validation, and proof of exploitability ...

NGINX logo with broken server, illustrating CVE-2026-42945 vulnerability.

NGINX Rift (CVE-2026-42945): 18-Year Bug Enables RCE

CyberSecureFox Editorial Team

A critical vulnerability CVE-2026-42945 (NGINX Rift, CVSS v4 9.2) has been identified in NGINX Plus and NGINX Open Source, in ...

cPanel and WHM interface with a warning about CVE-2026-41940 vulnerability.

How alleged cPanel CVE-2026-41940 is exploited for backdoors

CyberSecureFox Editorial Team

A critical vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940, is, according to researchers from QiAnXin XLab, being ...

Snake emerging from a box on a laptop, representing a cybersecurity threat.

Typosquatted Hugging Face Repository Used in AI Supply Chain Attack

CyberSecureFox Editorial Team

The malicious Open-OSS/privacy-filter repository on the Hugging Face platform, masquerading as the legitimate OpenAI Privacy Filter model, was used to ...

Giant worm labeled "Mini Shai-Hulud" emerging from a box with package icons.

How the Mini Shai-Hulud Worm Compromised npm and PyPI Supply Chains

CyberSecureFox Editorial Team

Mini Shai-Hulud, linked to the TeamPCP group, has become one of the most dangerous worms in the npm and PyPI ...

Android Trojan graphic depicting malware activity and cryptocurrency connections.

TrickMo C turns infected Androids into TON-based proxy nodes

CyberSecureFox Editorial Team

Researchers at ThreatFabric have identified a new variant of the Android trojan TrickMo, which uses the decentralized network The Open ...

Red diamond under dome with locks surrounded by boxes and bugs.

RubyGems blocks new registrations after suspected malware campaign

CyberSecureFox Editorial Team

RubyGems — the standard package manager for the Ruby programming language — has temporarily blocked new account registration after an ...

Exim server illustration highlighting CVE-2026-45185 vulnerability.

Critical GnuTLS Use-After-Free Vulnerability in Exim (CVE-2026-45185)

CyberSecureFox Editorial Team

The Exim project has released an emergency security update that fixes the CVE-2026-45185 use-after-free vulnerability, which leads to heap corruption ...