Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Close-up of a weathered button labeled "2FA" on a rusty surface.

Malicious Releases of chalk and strip-ansi Expose npm’s Transitive Dependency Risk in Web3‑Focused Supply Chain Attack

CyberSecureFox 🦊

A coordinated phishing campaign against a high-profile npm maintainer enabled attackers to publish malicious versions of widely used JavaScript packages, ...

Comparison of Google and AI search interfaces on contrasting backgrounds.

Google’s AI Mode in Search: What Changes, Who’s Affected, and the Security Risks to Plan For

CyberSecureFox 🦊

Google is preparing a notable shift in its Search interface: users will soon be able to set an AI mode ...

Router surrounded by a glowing skull made of binary code, representing digital threats.

TP-Link confirms TR‑069/CWMP zero‑day in consumer routers: what to know and how to mitigate

CyberSecureFox 🦊

TP-Link has confirmed a previously unknown (0‑day) vulnerability in its implementation of the TR‑069/CWMP remote management protocol used by consumer ...

Young man anxiously stares at laptop in a dimly lit office.

Largest npm Supply Chain Attack Reaches 10% of Cloud Environments—but Nets Only Dollars

CyberSecureFox 🦊

A record-scale npm supply chain incident briefly inserted malicious code into widely used JavaScript libraries, touching an estimated 10% of ...

Hooded figure types on a laptop amidst a fiery, apocalyptic cityscape.

Hacker Accidentally Installs Huntress EDR, Triggering Months of Telemetry and a Privacy Debate

CyberSecureFox 🦊

An unusual incident involving Huntress’s endpoint detection and response (EDR) agent has reignited debate over the scope of EDR telemetry, ...

Man anxiously monitors a computer during a DDoS attack notification.

Record-Scale UDP Flood Hits European DDoS Provider: 1.5 Billion PPS Underscores Packet-Rate Risks

CyberSecureFox 🦊

An unnamed European DDoS filtering provider recently withstood one of the most intense packet-rate attacks recorded: a peak of 1.5 ...

Split-screen showing a payment receipt and a scam alert for the same charge.

iCloud Calendar invites abused to deliver callback phishing that evades email filters

CyberSecureFox 🦊

Threat actors are exploiting iCloud Calendar invitations to deliver convincing “purchase receipts” that originate from Apple infrastructure and pass SPF, ...

Man working on a laptop with cybersecurity symbols and a grave marker in the background.

Google patches critical Chrome ServiceWorker bug (CVE-2025-10200) and Mojo flaw (CVE-2025-10201)

CyberSecureFox 🦊

Google has shipped a security update for Chrome that fixes a critical use-after-free vulnerability in the ServiceWorker component, tracked as ...

Dark metal token engraved with "GITHUB token" rests on a textured background.

NX supply chain attack: s1ngularity breach exposes 7,200 repositories, 2,180 accounts, and active tokens

CyberSecureFox 🦊

Researchers at Wiz have detailed a significant supply chain compromise involving NX, a widely used open-source build and monorepo platform ...

Woman examining a photo on a smartphone with Google Photos and C2PA displayed on a monitor.

Google adds C2PA Content Credentials to Pixel 10 and Google Photos to authenticate images and AI edits

CyberSecureFox 🦊

Google is integrating Content Credentials based on the C2PA standard into the Pixel 10 camera app and Google Photos. The ...