Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Close-up of a phone call interface with headset, showing caller ID and duration.

Neon temporarily disabled after Broken Access Control exposes call data and transcripts

CyberSecureFox

In late September 2025, the call-recording app Neon shot to the top of the Apple App Store—reaching the No. 2 ...

Large building engulfed in flames with thick smoke rising into the sky.

South Korea’s Daejeon Data Center Fires Expose Systemic Resilience Gaps Across Government IT

CyberSecureFox

Two separate fires in one week at data centers in Daejeon, South Korea, triggered a nationwide disruption of public services ...

Man in a dark room, shocked while typing on a laptop displaying "IMPER."

CVE-2025-53967: Command Injection in Figma MCP Allowed RCE via Fallback Curl

CyberSecureFox

A critical security flaw in the popular Model Context Protocol (MCP) server for Figma, figma-developer-mcp, has been patched after researchers ...

Mysterious figure in a hoodie uses a laptop amidst swirling papers and lightning.

Anthropic and UK AI Safety Institute: 250 Documents Can Trigger DoS Backdoors in LLMs

CyberSecureFox

Anthropic, the UK AI Safety Institute, The Alan Turing Institute, and academic collaborators report that around 250 carefully crafted documents ...

Shadowy hand retrieves a document from a padlock beside a car.

Renault and Dacia UK disclose third‑party data breach: what customers and businesses should know

CyberSecureFox

Renault and its subsidiary Dacia have notified UK customers about a data breach stemming from a cyberattack on a third‑party ...

A red hat rests on a bust next to a laptop displaying ransom notes.

Red Hat GitLab Breach Spurs Extortion Threats and Raises CER Report Risks

CyberSecureFox

The cyber extortion landscape continues to consolidate as criminal crews specialize and collaborate. Scattered Lapsus$ Hunters has claimed responsibility for ...

Aerial view of a city landscape with red skull icon and tech labels.

RondoDox Botnet Targets Internet-Exposed IoT with Pwn2Own Techniques and n-day Exploits

CyberSecureFox

Researchers at Trend Micro have identified RondoDox, a rapidly growing IoT botnet that systematically compromises internet-exposed devices using a broad ...

CVE-2025-49844 label indicating critical security vulnerability level 10.0.

Redis Patches CVE-2025-49844: Critical Lua-Based RCE (“RediShell”) With CVSS 10.0

CyberSecureFox

Redis has released security updates to address CVE-2025-49844, a CVSS 10.0 vulnerability that has lingered in the codebase for roughly ...

Individual focused on a laptop displaying a critical security alert.

Oracle E‑Business Suite zero‑day CVE‑2025‑61882 under active exploitation: what to patch and how to defend

CyberSecureFox

A critical zero-day vulnerability tracked as CVE-2025-61882 in Oracle E‑Business Suite (EBS) has moved into active exploitation. Industry researchers report ...

Aerial view of a cityscape with 'Lockbit' and 'Babuk' icons over a building.

Attackers Weaponize Outdated Velociraptor Build (CVE-2025-6264) to Encrypt Windows and VMware ESXi

CyberSecureFox

Threat actors are repurposing a legitimate incident response tool to accelerate ransomware operations. According to Cisco Talos, adversaries are deploying ...