Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Xeno RAT targets Afghan finance ministry in a digital illustration.

Operation XENOFISCAL: Xeno RAT phishing hits Afghan public finance

CyberSecureFox Editorial Team

Researchers at Seqrite Labs have disclosed details of a targeted phishing campaign against Afghanistan’s Ministry of Finance, provincial revenue and ...

Dark illustration of a box with npm branding, emitting ominous smoke and eyes.

Miasma malware campaign compromises @redhat-cloud-services npm

CyberSecureFox Editorial Team

Numerous npm packages in the @redhat-cloud-services namespace were compromised as part of a campaign codenamed Miasma. According to researchers from ...

Illustration of a malicious npm package stealing tokens from a server.

Supply-chain attack targets OpenAI Codex users via npm and Android

CyberSecureFox Editorial Team

Researchers from Aikido Security discovered a malicious campaign targeting developers using OpenAI Codex. The npm package codexui-android, promoted as a ...

Illustration of a botnet being dismantled with servers and connected devices.

How Dutch Authorities Took Down a 17 Million-Device Botnet

CyberSecureFox Editorial Team

The Dutch Police, together with the National Cyber Security Centre (NCSC), announced the dismantling of one of the largest botnets ...

Visual representation of CVE-2026-0257 with network security elements.

Active Exploitation of Palo Alto GlobalProtect Auth Bypass CVE-2026-0257

CyberSecureFox Editorial Team

Palo Alto Networks has confirmed active exploitation of the CVE-2026-0257 vulnerability (CVSS 7.8) in PAN-OS and Prisma Access products. The ...

Visual representation of ChatGPT security measures against phishing threats.

How ChatGPhish and New AI Agent Exploits Expand Phishing Risk

CyberSecureFox Editorial Team

Researchers from Permiso Security disclosed an attack technique against ChatGPT called ChatGPhish, which turns routine web page summarization into a ...

Malicious Sicoob.Sdk targeting banking data with icons and code elements.

Fake Sicoob.Sdk NuGet Package Targets Banking APIs

CyberSecureFox Editorial Team

A malicious package named Sicoob.Sdk (versions 2.0.0–2.0.4) has been discovered in the NuGet registry, masquerading as the official C# SDK ...

Digital illustration depicting cyber threats targeting South Korea.

How Kimsuky Used Fake Webex and Security Tools to Hack South Korea

CyberSecureFox Editorial Team

The North Korean threat group Kimsuky (also known as Velvet Chollima) carried out a series of targeted attacks against South ...

Illustration depicting code injection vulnerability in software development.

Unpatched Gogs RCE Lets Authenticated Users Run Server Commands

CyberSecureFox Editorial Team

In Gogs—a popular solution for self-hosting Git repositories—a critical remote code execution (RCE) vulnerability with a CVSS 9.4 rating has ...