Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Woman contemplating in a dimly lit room with symbols of justice and cryptocurrency.

UK Sentences Zhimin Qian for Crypto Laundering; Police Seize 61,000 BTC Linked to China’s Largest Ponzi Scheme

CyberSecureFox

A London court has sentenced 47‑year‑old Zhimin Qian, also known as Yadi Zhang, to 11 years and 8 months in ...

Android logo with a skull and crossbones illuminated against a dark background.

Uhale digital photo frames silently load malware via v4.2.0 update, with ties to the Vo1d botnet

CyberSecureFox

Security researchers at Quokka report that multiple digital photo frames built on the Uhale platform (part of the ZEASN ecosystem, ...

Russian passport next to a padlock engraved with a Bitcoin symbol.

Russian IAB Pleads Guilty to Supplying Access for Yanluowang Ransomware

CyberSecureFox

Russian national Alexey Olegovich Volkov—known online as chubaka.kor and nets—has pleaded guilty to selling initial access used by the Yanluowang ...

Man focused on laptop displaying security vulnerabilities in Docker and Kubernetes.

Three critical runC flaws expose Docker and Kubernetes to container escape

CyberSecureFox

Three critical vulnerabilities in the OCI reference runtime runC—widely used by Docker, containerd, CRI‑O, and Kubernetes—could let attackers bypass container ...

Man interacting with a warning display about a cybersecurity vulnerability.

CVE-2025-12480: Triofox localhost trust flaw under active exploitation enables unauthenticated SYSTEM RCE

CyberSecureFox

Google Threat Intelligence warns that attackers are actively exploiting CVE-2025-12480, a critical vulnerability in Gladinet Triofox that allows unauthenticated remote ...

Text label on a device showing firmware update details and version number.

ASUS Patches Critical Authentication Bypass in DSL-AC51, DSL-N16, and DSL-AC750 (CVE-2025-59367)

CyberSecureFox

ASUS has released an emergency firmware update to remediate CVE-2025-59367, a critical authentication bypass in several DSL router models. If ...

Vintage computer displays "archive.today" next to an FBI agent reading a document.

FBI Targets archive.today Operator With Broad Data Request to Tucows

CyberSecureFox

The FBI has reportedly sought information on the operator of archive.today (also known as archive.is, archive.ph and others), one of ...

Hacker in a dark landscape, facing two large padlocks labeled with CVE numbers.

Pre‑disclosure exploitation of Citrix Bleed 2 and Cisco ISE RCE identified in broad campaign

CyberSecureFox

Amazon Threat Intelligence has documented a large-scale campaign abusing two critical 0‑day vulnerabilities: CVE-2025-5777 (Citrix Bleed 2) affecting NetScaler ADC/Gateway ...

Scenic view with a GitHub sign, Golden Gate Bridge, and wildlife in a lush landscape.

Malicious npm Package @acitons/artifact Was a GitHub Red Team Drill — What Happened and How to Protect CI/CD

CyberSecureFox

Security researchers at Veracode reported a malicious npm package, @acitons/artifact, masquerading as the legitimate @actions/artifact and targeting GitHub Actions environments. ...

Aerial view of a Logitech building in an urban landscape beside a river.

Logitech Confirms Data Breach as Clop Targets Oracle E‑Business Suite Zero‑Day

CyberSecureFox

Logitech has notified the U.S. Securities and Exchange Commission (SEC) of an incident involving unauthorized access to company data, later ...