Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Man in a dark room, shocked while typing on a laptop displaying "IMPER."

CVE-2025-53967: Command Injection in Figma MCP Allowed RCE via Fallback Curl

CyberSecureFox Editorial Team

A critical security flaw in the popular Model Context Protocol (MCP) server for Figma, figma-developer-mcp, has been patched after researchers ...

Mysterious figure in a hoodie uses a laptop amidst swirling papers and lightning.

Anthropic and UK AI Safety Institute: 250 Documents Can Trigger DoS Backdoors in LLMs

CyberSecureFox Editorial Team

Anthropic, the UK AI Safety Institute, The Alan Turing Institute, and academic collaborators report that around 250 carefully crafted documents ...

Shadowy hand retrieves a document from a padlock beside a car.

Renault and Dacia UK disclose third‑party data breach: what customers and businesses should know

CyberSecureFox Editorial Team

Renault and its subsidiary Dacia have notified UK customers about a data breach stemming from a cyberattack on a third‑party ...

A red hat rests on a bust next to a laptop displaying ransom notes.

Red Hat GitLab Breach Spurs Extortion Threats and Raises CER Report Risks

CyberSecureFox Editorial Team

The cyber extortion landscape continues to consolidate as criminal crews specialize and collaborate. Scattered Lapsus$ Hunters has claimed responsibility for ...

Aerial view of a city landscape with red skull icon and tech labels.

RondoDox Botnet Targets Internet-Exposed IoT with Pwn2Own Techniques and n-day Exploits

CyberSecureFox Editorial Team

Researchers at Trend Micro have identified RondoDox, a rapidly growing IoT botnet that systematically compromises internet-exposed devices using a broad ...

CVE-2025-49844 label indicating critical security vulnerability level 10.0.

Redis Patches CVE-2025-49844: Critical Lua-Based RCE (“RediShell”) With CVSS 10.0

CyberSecureFox Editorial Team

Redis has released security updates to address CVE-2025-49844, a CVSS 10.0 vulnerability that has lingered in the codebase for roughly ...

Individual focused on a laptop displaying a critical security alert.

Oracle E‑Business Suite zero‑day CVE‑2025‑61882 under active exploitation: what to patch and how to defend

CyberSecureFox Editorial Team

A critical zero-day vulnerability tracked as CVE-2025-61882 in Oracle E‑Business Suite (EBS) has moved into active exploitation. Industry researchers report ...

Aerial view of a cityscape with 'Lockbit' and 'Babuk' icons over a building.

Attackers Weaponize Outdated Velociraptor Build (CVE-2025-6264) to Encrypt Windows and VMware ESXi

CyberSecureFox Editorial Team

Threat actors are repurposing a legitimate incident response tool to accelerate ransomware operations. According to Cisco Talos, adversaries are deploying ...

Man worriedly analyzing Google Gemini vulnerabilities on a laptop screen.

Gemini Trifecta: Prompt-Injection Vulnerabilities in Google’s Gemini and What They Mean for LLM Security

CyberSecureFox Editorial Team

Tenable has published technical details of three now-fixed vulnerabilities in Google’s Gemini AI platform, collectively labeled Gemini Trifecta. The flaws—affecting ...

Man silhouetted against a dark stormy backdrop, typing on a laptop illuminated by a shield logo.

Microsoft Edge will automatically detect and revoke malicious sideloaded extensions

CyberSecureFox Editorial Team

Microsoft announced a new security capability for Edge that will detect and revoke malicious extensions installed outside the official Edge ...