Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
MacSync Stealer Uses Signed and Notarized Swift App to Target macOS Users
macOS is no longer a niche target for cybercriminals. The latest example is an updated variant of the MacSync stealer, ...
Nissan Data Breach Tied to Red Hat Cyber Attack Exposes Supply Chain Security Gaps
The compromise of IT systems at Red Hat has led to the exposure of personal data belonging to thousands of ...
Cosmali Loader Malware Spreads via Fake Microsoft Activation Scripts Domain in Windows Typosquatting Attack
Windows users are facing a new malware campaign in which attackers abuse a fake Microsoft Activation Scripts (MAS) domain to ...
Mamont Android Banking Trojan: Telegram-Controlled Malware Targets Russian Users
The Android banking trojan Mamont has rapidly become one of the main instruments of mobile cybercrime against Russian users. According ...
Phantom Shuttle: Malicious Chrome Proxy Extensions Hijack Traffic and Steal Sensitive Data
Two Google Chrome extensions distributed under the common name Phantom Shuttle have been identified as malicious tools that silently intercept ...
Malicious npm Package lotusbail Abused as WhatsApp Web API Library in Supply Chain Attack
A malicious npm package named lotusbail has been discovered impersonating a legitimate WhatsApp Web API client library. For several months ...
Russia’s WhatsApp Restrictions: Encryption Under Pressure and Cybersecurity Risks
Russian users of WhatsApp, the world’s largest messaging platform owned by Meta (designated an extremist organization and banned in Russia), ...
Critical HPE OneView Vulnerability (CVE-2025-37164): Why Immediate Patching Is Essential
Hewlett Packard Enterprise (HPE) has released security updates to address a critical remote code execution (RCE) vulnerability in its infrastructure ...
Nigerian Police Disrupt Raccoon0365 Phishing-as-a-Service Targeting Microsoft 365
Nigerian law enforcement has announced the arrest of three individuals allegedly linked to the Raccoon0365 phishing-as-a-service (PhaaS) platform, a commercial ...
Cisco AsyncOS Zero-Day CVE-2025-20393 Targets Secure Email Gateway: What Security Teams Must Do Now
Cisco has formally warned customers about a critical zero-day vulnerability in Cisco AsyncOS that is already being exploited in the ...