Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline …

Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Spring Cloud Config provides crucial server-side and client-side support for externalized configuration in distributed systems. Recently, the Spring development team disclosed four security vulnerabilities impacting the Spring Cloud Config Server. These flaws range from medium to critical …

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major …

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major …

Multiple Critical Vulnerabilities Patched in Next.js and React Server Components

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 8, 2026 Vercel has released an extensive set of security advisories for Next.js, addressing more than a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting. The flaws affect Next.js versions 13.x through 16.x using the …

New Ivanti EPMM 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Ivanti has issued a critical security advisory for its Endpoint Manager Mobile (EPMM) product, disclosing multiple actively exploited vulnerabilities, including CVE-2026-6973, and urging all on-premises EPMM customers to apply patches immediately. At the time of disclosure, Ivanti …

CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 CISA has issued an urgent warning regarding a critical vulnerability in Palo Alto Networks PAN-OS. Tracked as CVE-2026-0300, this severe security flaw was recently added to CISA’s Known Exploited Vulnerabilities catalog on May 6, 2026. The vulnerability …

New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Cisco has issued a critical security advisory regarding a high-severity vulnerability impacting its Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO). Tracked formally as CVE-2026-20188 with a CVSS base score of 7.5, this flaw poses a …

Hackers Using Fake Claude AI Installer Pages to Trick Users Into Running Malware on Their Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Hackers are using convincing fake pages for Claude AI to trick users into running malware on their own systems. The campaign, known as “InstallFix” or the Fake Claude Installer threat, marks a sharp shift in how cybercriminals …

Scammers Use Short-Lived VoIP Numbers and Reuse Windows to Defeat Reputation-Based Blocking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 7, 2026 Phone-based scams are evolving faster than most security filters can keep up with. Attackers are now leaning heavily on Voice over Internet Protocol (VoIP) numbers that disappear before detection systems can flag them, leaving users exposed and …