Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Luxshare Ransomware Attack Puts Apple and Global Electronics Supply Chain Under Scrutiny
A major ransomware incident at Chinese electronics manufacturer Luxshare, one of Apple’s key contract partners, is drawing attention to the ...
Curl Ends HackerOne Bug Bounty After Surge of AI‑Generated Vulnerability Reports
The Curl project is phasing out its bug bounty program on HackerOne after a sharp rise in low‑quality, often AI‑generated ...
PhantomCore Phishing Campaign Uses PowerShell Backdoor Against Russian and Belarusian Organizations
In January, security analysts observed a new wave of targeted phishing attacks linked to the PhantomCore threat group. According to ...
Zendesk Relay Spam Attack Exploits Global Helpdesk Systems
Users worldwide are reporting an unusual wave of spam emails arriving not from shady domains, but from legitimate customer support ...
Fortinet FortiGate Firewalls Under Massive Attack via FortiCloud SSO Vulnerability CVE-2025-59718
From mid-January, Fortinet FortiGate firewalls have come under a new wave of highly automated attacks. According to researchers at Arctic ...
Google Gemini Prompt Injection via Google Calendar Exposes New AI Security Risk
Researchers from Miggo Security have demonstrated a novel prompt injection technique against the Google Gemini AI assistant that abuses standard ...
LastPass Phishing Emails Demand 24‑Hour Backup: How to Protect Your Password Manager
Users of the popular password manager LastPass are being targeted in a new phishing campaign that impersonates official maintenance notifications. ...
GhostPoster Malicious Browser Extensions Abuse Steganography in Chrome, Firefox and Edge
A large-scale malicious browser extension campaign known as GhostPoster has been uncovered in the official extension stores for Google Chrome, ...
Android.Phantom: New Android Trojan Uses WebRTC and TensorFlowJS for Large-Scale Click Fraud
A new malware family dubbed Android.Phantom has been identified targeting Android devices through popular mobile games and pirated “premium” app ...
CrashFix: NexShield Chrome Extension Crashes Browsers to Deploy ModeloRAT
Security researchers at Huntress have documented a new browser-based attack chain dubbed CrashFix, which weaponizes a malicious Chrome extension named ...