Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

NGINX logo with CVE-2026-42945 and openDCIM under attack visualization.

Active Exploitation of NGINX CVE-2026-42945 and openDCIM Flaws

CyberSecureFox Editorial Team

The critical vulnerability CVE-2026-42945 in NGINX Plus and NGINX Open, which allows an attacker to cause denial of service or, ...

Illustration depicting an XSS attack on Exchange Server with related elements.

How CVE-2026-42897 Puts On-Premises Exchange Servers at Risk

CyberSecureFox Editorial Team

Microsoft has disclosed vulnerability CVE-2026-42897 (CVSS 8.1) in on-premises versions of Exchange Server, which is already being actively exploited by ...

Visualization of Cisco SD-WAN controller with a security vulnerability highlighted.

Urgent Cisco Catalyst SD-WAN Patching for CVE-2026-20182

CyberSecureFox Editorial Team

On 14 May 2026, CISA added the vulnerability CVE-2026-20182 to the Known Exploited Vulnerabilities (KEV) catalog, setting a remediation deadline ...

Visual representation of CVE-2026-44338 with robots and security elements.

CVE-2026-44338: Authentication Bypass in PraisonAI API

CyberSecureFox Editorial Team

The critical authentication bypass vulnerability CVE-2026-44338 (CVSS 7.3) in the open multi-agent orchestration framework PraisonAI became the target of active ...

Digital keys representing vulnerabilities threatening Windows security.

Unpatched BitLocker Bypass and Privilege Escalation in Windows

CyberSecureFox Editorial Team

A researcher using the handle Chaotic Eclipse (Nightmare-Eclipse), who previously disclosed three vulnerabilities in Microsoft Defender, has published information on ...

Graphic illustrating the Fragnesia CVE-2026-46300 Linux kernel vulnerability.

Fragnesia Linux Kernel LPE via ESP-in-TCP (CVE-2026-46300)

CyberSecureFox Editorial Team

The CVE-2026-46300 vulnerability, dubbed Fragnesia, allows an unprivileged local attacker to gain root privileges by corrupting the Linux kernel page ...

Digital artwork of a cyber attack targeting Azerbaijan's oil sector.

Chinese APT Repeatedly Reenters Azerbaijani Oil & Gas Through Exchange

CyberSecureFox Editorial Team

According to Bitdefender researchers, the Chinese cyber-espionage group FamousSparrow carried out a multi-stage operation against an unnamed Azerbaijani oil and ...

Computer with Windows logo under attack, featuring network elements.

Inside MDASH: Microsoft’s Agentic AI for Windows Vulnerability Discovery

CyberSecureFox Editorial Team

Microsoft announced the MDASH (Multi-model Agentic Scanning Harness) system—a multi-model agentic platform for automated detection, validation, and proof of exploitability ...

NGINX logo with broken server, illustrating CVE-2026-42945 vulnerability.

NGINX Rift (CVE-2026-42945): 18-Year Bug Enables RCE

CyberSecureFox Editorial Team

A critical vulnerability CVE-2026-42945 (NGINX Rift, CVSS v4 9.2) has been identified in NGINX Plus and NGINX Open Source, in ...

cPanel and WHM interface with a warning about CVE-2026-41940 vulnerability.

How alleged cPanel CVE-2026-41940 is exploited for backdoors

CyberSecureFox Editorial Team

A critical vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940, is, according to researchers from QiAnXin XLab, being ...