Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Split-screen showing a payment receipt and a scam alert for the same charge.

iCloud Calendar invites abused to deliver callback phishing that evades email filters

CyberSecureFox

Threat actors are exploiting iCloud Calendar invitations to deliver convincing “purchase receipts” that originate from Apple infrastructure and pass SPF, ...

Man working on a laptop with cybersecurity symbols and a grave marker in the background.

Google patches critical Chrome ServiceWorker bug (CVE-2025-10200) and Mojo flaw (CVE-2025-10201)

CyberSecureFox

Google has shipped a security update for Chrome that fixes a critical use-after-free vulnerability in the ServiceWorker component, tracked as ...

Dark metal token engraved with "GITHUB token" rests on a textured background.

NX supply chain attack: s1ngularity breach exposes 7,200 repositories, 2,180 accounts, and active tokens

CyberSecureFox

Researchers at Wiz have detailed a significant supply chain compromise involving NX, a widely used open-source build and monorepo platform ...

Woman examining a photo on a smartphone with Google Photos and C2PA displayed on a monitor.

Google adds C2PA Content Credentials to Pixel 10 and Google Photos to authenticate images and AI edits

CyberSecureFox

Google is integrating Content Credentials based on the C2PA standard into the Pixel 10 camera app and Google Photos. The ...

Aerial view of a building with large Meta logo on the roof and surrounding parking lot.

Ex-WhatsApp Whistleblower Sues Meta Over Alleged Engineer Access: What It Means for Insider Risk and Compliance

CyberSecureFox

A former WhatsApp employee has filed a whistleblower lawsuit against Meta, alleging that his February 2025 termination followed repeated efforts ...

Man in a suit analyzing a TLS certificate beside a locked DNS symbol.

Fina CA’s Unauthorized Certificates for Cloudflare’s 1.1.1.1 Expose PKI Blind Spots on Windows

CyberSecureFox

Cloudflare has confirmed that the certification authority Fina issued 12 unauthorized TLS certificates for the IP address 1.1.1.1—Cloudflare’s public DNS ...

Google headquarters overlooking a wetland and city skyline, with herons visible.

Google Refutes Gmail Breach Claims and Mass Password Reset Rumors

CyberSecureFox

Google has clarified that it did not issue a broad-based alert or force a mass password reset for Gmail users. ...

Man with smartphone showing Android logo, holding his head in distress outside Google.

Android September 2025 Security Update Fixes 120 Flaws; Two Zero‑Days Already Exploited

CyberSecureFox

Google has released the September 2025 Android Security Bulletin, addressing 120 vulnerabilities across the OS and ecosystem components. The company ...

A stressed man at a laptop showing a Windows error message.

Microsoft Tightens UAC for MSI Repair to Mitigate CVE-2025-50173, Impacting Silent Installs and Per‑User Setups

CyberSecureFox

Microsoft’s August 2025 cumulative security update for Windows (KB5063878) and subsequent releases introduced stricter User Account Control (UAC) enforcement for ...

Man interacting with a holographic display about ransomware in a futuristic setting.

PromptLock: AI-Powered Ransomware Prototype Validates LLM-Orchestrated Attack Model

CyberSecureFox

ESET has verified that samples of PromptLock uploaded to VirusTotal in late August 2025 were not part of an in-the-wild ...