Cybersecurity News

Stay up-to-date with the latest cybersecurity news and developments in the cybersecurity landscape. Be the first to know about the latest threats, current innovations, and major trends in the cyber universe. Check our Cyber News section for the freshest information.

Man concerned about critical ASP.NET Core vulnerability on computer screen.

Microsoft fixes critical Kestrel flaw (CVE-2025-55315) enabling HTTP request smuggling

CyberSecureFox 🦊

Microsoft has shipped fixes for a critical vulnerability in the Kestrel web server used by ASP.NET Core, tracked as CVE-2025-55315 ...

Split scene shows a hacker on one side and secure messaging on the other.

US Court Bans NSO Group From Targeting WhatsApp, Orders Data Deletion, Cuts Damages to $4M

CyberSecureFox 🦊

A US federal court in the Northern District of California has issued a permanent injunction against Israeli spyware developer NSO ...

Law enforcement officers surround a building labeled SIMCARTEL with parked vehicles.

Europol Dismantles SIMCARTEL: Inside the Global SIM-Farm Network Powering OTP Abuse and Fake Accounts

CyberSecureFox 🦊

European law enforcement has dismantled a large-scale SIM-farm ecosystem in an operation codenamed SIMCARTEL, disrupting a global pipeline for phishing, ...

Bright orange flower in foreground with Golden Gate Bridge and San Francisco skyline.

GlassWorm Malware Exploits VS Code Extensions in Significant Supply Chain Attack

CyberSecureFox 🦊

Koi Security has documented a significant software supply chain attack in the Visual Studio Code ecosystem. A self-propagating malware dubbed ...

Man monitors screen displaying malware alert in a tech workspace.

Malicious npm package “https-proxy-utils” delivers AdaptixC2 and underscores open-source supply chain exposure

CyberSecureFox 🦊

Security researchers at Kaspersky identified a malicious npm package, https-proxy-utils, masquerading as a proxy utility and abusing npm lifecycle scripts ...

Abandoned library with "БИБЛИОТЕКА" sign, surrounded by overgrown vegetation.

TARmageddon (CVE-2025-62518): Critical Rust tar parsing flaw enables RCE in tokio‑tar and forks

CyberSecureFox 🦊

Security researchers at Edera have disclosed a critical logic flaw in the abandoned Rust library async‑tar and multiple forks, including ...

SQL Server cabinet contrasted with shadowy figures hacking into it.

PassiveNeuron zeros in on Windows Server: new APT wave leverages SQL abuse, Cobalt Strike, and custom implants

CyberSecureFox 🦊

A newly observed campaign by the PassiveNeuron threat actor underscores a strategic pivot toward server-side targets. According to Kaspersky’s Global ...

Laptop screen displaying VirtualBox logo with a warning symbol overlay.

Oracle VirtualBox on macOS ARM: Two CVEs Enable VM Escape, Patched in October 2025 CPU

CyberSecureFox 🦊

Two vulnerabilities in Oracle VirtualBox, tracked as CVE-2025-62592 and CVE-2025-61760, can be chained to escape from a guest virtual machine ...

Hooded figure typing on a laptop, with eerie portraits and chess pieces nearby.

ColdRiver pivots to ClickFix: NoRobot and MaybeRobot replace LostKeys in stealthier social engineering campaigns

CyberSecureFox 🦊

Google’s Threat Intelligence Group (GTIG) reports a rapid shift in the tradecraft of the Russian‑language threat actor ColdRiver—also tracked as ...

Phone displaying account recovery screen with a photo and prompt.

Google Adds “Recovery Contacts” to Gmail: A Human-Assisted, Phishing-Resistant Path to Account Recovery

CyberSecureFox 🦊

Google is expanding Gmail account recovery with a new option called Recovery Contacts, a human-assisted mechanism that lets users designate ...