Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Two contrasting representations of "sudo root access" with a lock and a skull.

CISA: Critical sudo CVE-2025-32463 actively exploited for Linux privilege escalation

CyberSecureFox Editorial Team

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2025-32463, a critical flaw in ...

Man in hood working on a computer amid a dramatic sunset with a shadowy figure behind.

Battering RAM: Hardware Attack Undermines Intel SGX and AMD SEV‑SNP Protections

CyberSecureFox Editorial Team

Researchers from KU Leuven and the University of Birmingham have disclosed Battering RAM, a hardware attack that defeats key confidential ...

Silhouettes of three people against a fiery background with a burning car.

UK issues £1.5bn UKEF guarantee to Jaguar Land Rover after cyberattack: what it means for supply chains and cyber resilience

CyberSecureFox Editorial Team

The UK government has approved a £1.5 billion credit guarantee for Jaguar Land Rover (JLR) under UK Export Finance’s Export ...

Hand placing a checkmark on a note above a cloud storage device, amidst a cracked ground.

Western Digital fixes critical My Cloud command injection (CVE-2025-30247) with firmware 5.31.108

CyberSecureFox Editorial Team

Western Digital has released firmware version 5.31.108 for My Cloud network-attached storage (NAS) devices to remediate CVE-2025-30247, a critical command ...

Close-up of a passport next to a security lock button on a keyboard.

Discord probes third-party support breach as payment and identity data exposed

CyberSecureFox Editorial Team

On 20 September 2025, Discord disclosed a security incident stemming from a compromise of a third‑party customer support provider. The ...

Man using a laptop to interact with a document management application.

MatrixPDF Builder Turns Benign PDFs into Click‑Through Phishing Lures That Bypass Gmail Filters

CyberSecureFox Editorial Team

Varonis researchers have identified MatrixPDF, a commercial builder that converts legitimate PDF files into interactive phishing decoys. The tool leverages ...

Figure silhouetted against a fiery Unity logo in a dark, dramatic setting.

Unity CVE-2025-59489: Critical Runtime Flaw Enables Code Execution on Android and Potential Privilege Escalation on Windows

CyberSecureFox Editorial Team

A high-severity vulnerability in the Unity Runtime, tracked as CVE-2025-59489 with a CVSS score of 8.4, exposes Unity-built apps to ...

Computer screens show hacking themes with a figure in a hoodie.

Red Hat probes consulting GitLab breach as Crimson Collective claims 570 GB data theft and 800 CERs exposed

CyberSecureFox Editorial Team

Ransomware group Crimson Collective claims it stole 570 GB of data from about 28,000 internal GitLab repositories associated with Red ...

Split-screen showing Outlook logo and an error message about starting Outlook.

Classic Outlook for Windows Crashes at Launch: Microsoft Probes Exchange Online Authentication Concurrency Limit

CyberSecureFox Editorial Team

Microsoft is investigating an incident that causes the classic Outlook for Windows client to crash at startup for some Microsoft ...

Futuristic scene with a woman checking a device in a high-tech environment.

Google’s Developer Verification Rule Will Gate Sideloaded Apps on Certified Android Devices

CyberSecureFox Editorial Team

Google will require that, starting in 2026, certified Android devices (phones and tablets with Google Mobile Services and Play Protect) ...