Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Microsoft tightens IE Mode in Edge after attacks leveraging Chakra zero-day
Microsoft has revised how Internet Explorer (IE) Mode is invoked in Edge following a wave of attacks observed in August ...
Microsoft’s October Patch Tuesday Fixes 173 Vulnerabilities, Including Six Zero‑Days Under Active Attack
Microsoft’s October Patch Tuesday delivers fixes for 173 security vulnerabilities across its ecosystem, including six zero‑day issues. By Microsoft’s definition, ...
Signed UEFI Shell on Framework Linux devices can disable Secure Boot checks, Eclypsium warns
Approximately 200,000 Framework devices running Linux were shipped with legitimately signed UEFI Shell components that include the memory modify (mm) ...
Discord support breach fuels third‑party risk debate as 5CA disputes involvement
Discord has disclosed a third‑party support incident that exposed a subset of users’ identity document images and fragments of payment ...
Unity discloses Magecart web skimming on SpeedTree checkout, exposing payment data
Unity Technologies has disclosed a compromise of the SpeedTree storefront in which a malicious JavaScript was injected into the checkout ...
North Korean APT UNC5342 weaponizes EtherHiding to deliver malware via smart contracts
Google’s Threat Intelligence Group (GTIG) has linked North Korean threat actor UNC5342 to a new wave of attacks that, since ...
FBI Seizes BreachForums Domain as Salesforce‑Linked Extortion Persists: What Organizations Need to Know
The FBI has formally seized the Breachforums[.]hn domain, one of the most active cybercrime forums used in 2025 for leaking ...
Windows 11 updates disrupt HTTP/2 on localhost (127.0.0.1): what broke and how to mitigate
Windows 11 users report that recent updates—October cumulative KB5066835 and the September preview KB5065789—cause localhost instability by breaking HTTP/2 connections ...
F5 discloses state‑sponsored intrusion impacting BIG‑IP development environment; 44 vulnerabilities fixed
F5 has disclosed a cybersecurity incident attributed to a state‑sponsored threat actor that maintained persistent access to segments of its ...
Rust-Based ChaosBot Leverages Discord C2, LNK Phishing, and WMI to Evade Enterprise Defenses
Threat researchers at eSentire have identified a new backdoor dubbed ChaosBot, written in Rust and using Discord as command-and-control (C2). ...