Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Trust Wallet Chrome Extension Hack: Supply Chain Risks for Browser Crypto Wallets
Trust Wallet, one of the most widely used non-custodial crypto wallets, has reported a serious security incident involving its Chrome ...
MongoDB CVE-2025-14847: Critical Remote Code Execution Vulnerability Exposes Databases to Attack
A newly disclosed critical vulnerability in MongoDB Server (CVE-2025-14847) allows attackers to execute arbitrary code remotely on affected databases. The ...
La Poste Cyber Attack: Massive Suspected DDoS Hits French Postal and Banking Services
France’s national postal operator La Poste has suffered a major IT disruption that temporarily took down several of its key ...
MacSync Stealer Uses Signed and Notarized Swift App to Target macOS Users
macOS is no longer a niche target for cybercriminals. The latest example is an updated variant of the MacSync stealer, ...
Nissan Data Breach Tied to Red Hat Cyber Attack Exposes Supply Chain Security Gaps
The compromise of IT systems at Red Hat has led to the exposure of personal data belonging to thousands of ...
Cosmali Loader Malware Spreads via Fake Microsoft Activation Scripts Domain in Windows Typosquatting Attack
Windows users are facing a new malware campaign in which attackers abuse a fake Microsoft Activation Scripts (MAS) domain to ...
Mamont Android Banking Trojan: Telegram-Controlled Malware Targets Russian Users
The Android banking trojan Mamont has rapidly become one of the main instruments of mobile cybercrime against Russian users. According ...
Phantom Shuttle: Malicious Chrome Proxy Extensions Hijack Traffic and Steal Sensitive Data
Two Google Chrome extensions distributed under the common name Phantom Shuttle have been identified as malicious tools that silently intercept ...
Malicious npm Package lotusbail Abused as WhatsApp Web API Library in Supply Chain Attack
A malicious npm package named lotusbail has been discovered impersonating a legitimate WhatsApp Web API client library. For several months ...
Russia’s WhatsApp Restrictions: Encryption Under Pressure and Cybersecurity Risks
Russian users of WhatsApp, the world’s largest messaging platform owned by Meta (designated an extremist organization and banned in Russia), ...