Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Billboard featuring "ChatGPT ATLAs" overlooking a river and cityscape.

CSRF + Persistent Memory Flaw Exposes ChatGPT Atlas to Stealthy Prompt Injection

CyberSecureFox Editorial Team

Security researchers at LayerX have identified a vulnerability in OpenAI’s new ChatGPT Atlas browser that combines Cross-Site Request Forgery (CSRF) ...

Rusty padlock and wax seal on dollar bills, symbolizing security and wealth.

Ransomware Payments Fall to Record Low as Data-Theft Extortion Dominates

CyberSecureFox Editorial Team

According to Coveware’s latest Q3 2025 ransomware report, the share of organizations that pay after an incident has fallen to ...

Chameleon on a padlock beside a laptop with a security warning displayed.

LastPass “Emergency Access” Phishing Targets Master Passwords and Passkeys

CyberSecureFox Editorial Team

Users of the LastPass password manager are being hit by a large‑scale phishing wave that began in mid‑October 2025. The ...

Hooded figure at a laptop with WordPress and plugin icons against a dark backdrop.

WordPress Under Attack: Mass Exploitation of GutenKit and Hunk Companion REST API RCE Flaws

CyberSecureFox Editorial Team

Wordfence has observed a large-scale, automated campaign abusing critical vulnerabilities in the WordPress plugins GutenKit and Hunk Companion. Over a ...

Man anxiously looks at a laptop displaying an anti-malware alert.

CVE-2025-11705 in Anti‑Malware Security WordPress Plugin Enables Authenticated Arbitrary File Read

CyberSecureFox Editorial Team

A high‑impact vulnerability, CVE-2025-11705, has been identified in the popular WordPress plugin Anti‑Malware Security and Brute‑Force Firewall, enabling authenticated users ...

Hand holding a fiery orb balances against a stack of mysterious papers.

Mozilla to Require Data Collection Disclosures for Firefox Extensions

CyberSecureFox Editorial Team

Mozilla is introducing mandatory data collection disclosures for Firefox extensions, aiming to strengthen transparency and user control. The new requirements ...

Building with flaming rooftop labeled "Windows Server" amidst suburban offices.

Microsoft patches critical WSUS RCE (CVE-2025-59287) amid active exploitation

CyberSecureFox Editorial Team

Microsoft has released out-of-band security updates to address a critical flaw in Windows Server Update Services (WSUS), tracked as CVE-2025-59287. ...

Businessman in suit appears troubled, surrounded by digital symbols and a hooded figure.

BlueNoroff’s GhostCall and GhostHire: macOS-focused campaigns hitting crypto and Web3 firms

CyberSecureFox Editorial Team

Kaspersky researchers have identified two coordinated BlueNoroff operations—GhostCall and GhostHire—active since April 2025 and aimed primarily at cryptocurrency and Web3 ...

Beautiful view of a canal and historic architecture under cloudy skies.

Memento Labs Confirms Dante Spyware Used in ‘Forum Troll’ Campaign Exploiting Chrome CVE‑2025‑2783

CyberSecureFox Editorial Team

Memento Labs CEO Paolo Lezzi has confirmed that the spyware known as Dante—recently detected by Kaspersky during live operations—is a ...

Laptop on building rooftop emitting smoke and flames, displaying "SYSTEM FAILURE."

Brash vulnerability in Blink enables document.title DoS against Chromium browsers

CyberSecureFox Editorial Team

A newly disclosed vulnerability known as Brash abuses how the Blink rendering engine handles document.title updates, enabling a browser denial‑of‑service ...