Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Fragnesia Linux Kernel LPE via ESP-in-TCP (CVE-2026-46300)
The CVE-2026-46300 vulnerability, dubbed Fragnesia, allows an unprivileged local attacker to gain root privileges by corrupting the Linux kernel page ...
Chinese APT Repeatedly Reenters Azerbaijani Oil & Gas Through Exchange
According to Bitdefender researchers, the Chinese cyber-espionage group FamousSparrow carried out a multi-stage operation against an unnamed Azerbaijani oil and ...
Inside MDASH: Microsoft’s Agentic AI for Windows Vulnerability Discovery
Microsoft announced the MDASH (Multi-model Agentic Scanning Harness) system—a multi-model agentic platform for automated detection, validation, and proof of exploitability ...
NGINX Rift (CVE-2026-42945): 18-Year Bug Enables RCE
A critical vulnerability CVE-2026-42945 (NGINX Rift, CVSS v4 9.2) has been identified in NGINX Plus and NGINX Open Source, in ...
How alleged cPanel CVE-2026-41940 is exploited for backdoors
A critical vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940, is, according to researchers from QiAnXin XLab, being ...
Typosquatted Hugging Face Repository Used in AI Supply Chain Attack
The malicious Open-OSS/privacy-filter repository on the Hugging Face platform, masquerading as the legitimate OpenAI Privacy Filter model, was used to ...
How the Mini Shai-Hulud Worm Compromised npm and PyPI Supply Chains
Mini Shai-Hulud, linked to the TeamPCP group, has become one of the most dangerous worms in the npm and PyPI ...
TrickMo C turns infected Androids into TON-based proxy nodes
Researchers at ThreatFabric have identified a new variant of the Android trojan TrickMo, which uses the decentralized network The Open ...
RubyGems blocks new registrations after suspected malware campaign
RubyGems — the standard package manager for the Ruby programming language — has temporarily blocked new account registration after an ...
Critical GnuTLS Use-After-Free Vulnerability in Exim (CVE-2026-45185)
The Exim project has released an emergency security update that fixes the CVE-2026-45185 use-after-free vulnerability, which leads to heap corruption ...