Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

User interacts with a digital alert for 224 removed malicious apps.

SlopAds Ad-Fraud Network Dismantled: 224 Android Apps Pulled from Google Play

CyberSecureFox 🦊

Google has removed 224 malicious Android apps from Google Play linked to the SlopAds ad‑fraud operation. According to Satori Threat ...

Police officer leads handcuffed man in orange jumpsuit outside a prison at dusk.

Appeals Court Sends BreachForums Admin ‘Pompompurin’ to Prison: What It Means for Cybercrime and Enterprise Risk

CyberSecureFox 🦊

A federal appeals court has vacated a previously lenient sentence and imposed a three‑year prison term on 22‑year‑old Connor Brian ...

Two contrasting scenes of a payment card transaction displaying $655.00.

KioSoft CVE-2025-8699: Vulnerable Prepaid NFC Cards Abused to Inflate Balances, Patch Arrived a Year Later

CyberSecureFox 🦊

Security researchers at SEC Consult (Eviden) uncovered a critical flaw in certain KioSoft prepaid NFC cards that power self-service payments ...

Man interacts with a digital interface featuring Microsoft and Cloudflare logos.

Microsoft and Cloudflare Dismantle RaccoonO365 Phishing-as-a-Service Targeting Microsoft 365

CyberSecureFox 🦊

Microsoft’s Digital Crimes Unit (DCU) and Cloudflare have jointly disrupted the RaccoonO365 phishing-as-a-service (PhaaS) operation used to steal Microsoft 365 ...

Man in suit with worried expression sits at desk in a bank office.

FinWise Bank Confirms Insider Data Breach Affecting American First Finance Customers

CyberSecureFox 🦊

FinWise Bank has disclosed a data security incident dated May 31, 2024, in which a former employee accessed confidential information ...

Cybersecurity duel: hacker in red and IT professional in blue, contrasting concepts.

Head Mare APT adopts multi‑stage backdoors and SSH tunneling in latest campaign

CyberSecureFox 🦊

Researchers at Kaspersky have observed a fresh wave of targeted intrusion activity by the Head Mare threat group against organizations ...

Man with a laptop showing a bat symbol against a dramatic sunset backdrop.

ComicForm runs dual-vector phishing across CIS, delivering FormBook via multi-stage .NET loader

CyberSecureFox 🦊

A new wave of targeted phishing in the CIS is being attributed to the threat group ComicForm. Active since at ...

A monstrous worm emerging from barren ground surrounded by red npm boxes.

Shai-Hulud npm Worm: Self-Spreading Attack Abuses GitHub Actions to Trojanize Dependencies and Steal Secrets

CyberSecureFox 🦊

Security researchers have reported a large-scale compromise of more than 180 npm packages by a self-replicating malware strain that automatically ...

Samsung phone displaying security alert about CVE-2025-21043 with dark background.

Samsung patches Android zero-day CVE-2025-21043 in Quramsoft image codec

CyberSecureFox 🦊

Samsung has released a security update for CVE-2025-21043, a zero-day vulnerability rated CVSS 8.8 and confirmed as exploited in targeted ...

Cursor logo by OpenVSX on a textured, rust-colored background.

WhiteCobra abuses VS Code and Open VSX with malicious VSIX extensions targeting developers

CyberSecureFox 🦊

Threat analysts at Koi Security have identified a coordinated WhiteCobra campaign abusing the VS Code Marketplace and Open VSX Registry. ...