Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Nissan Data Breach Tied to Red Hat Cyber Attack Exposes Supply Chain Security Gaps
The compromise of IT systems at Red Hat has led to the exposure of personal data belonging to thousands of ...
Cosmali Loader Malware Spreads via Fake Microsoft Activation Scripts Domain in Windows Typosquatting Attack
Windows users are facing a new malware campaign in which attackers abuse a fake Microsoft Activation Scripts (MAS) domain to ...
Mamont Android Banking Trojan: Telegram-Controlled Malware Targets Russian Users
The Android banking trojan Mamont has rapidly become one of the main instruments of mobile cybercrime against Russian users. According ...
Phantom Shuttle: Malicious Chrome Proxy Extensions Hijack Traffic and Steal Sensitive Data
Two Google Chrome extensions distributed under the common name Phantom Shuttle have been identified as malicious tools that silently intercept ...
Malicious npm Package lotusbail Abused as WhatsApp Web API Library in Supply Chain Attack
A malicious npm package named lotusbail has been discovered impersonating a legitimate WhatsApp Web API client library. For several months ...
Russia’s WhatsApp Restrictions: Encryption Under Pressure and Cybersecurity Risks
Russian users of WhatsApp, the world’s largest messaging platform owned by Meta (designated an extremist organization and banned in Russia), ...
Critical HPE OneView Vulnerability (CVE-2025-37164): Why Immediate Patching Is Essential
Hewlett Packard Enterprise (HPE) has released security updates to address a critical remote code execution (RCE) vulnerability in its infrastructure ...
Nigerian Police Disrupt Raccoon0365 Phishing-as-a-Service Targeting Microsoft 365
Nigerian law enforcement has announced the arrest of three individuals allegedly linked to the Raccoon0365 phishing-as-a-service (PhaaS) platform, a commercial ...
Cisco AsyncOS Zero-Day CVE-2025-20393 Targets Secure Email Gateway: What Security Teams Must Do Now
Cisco has formally warned customers about a critical zero-day vulnerability in Cisco AsyncOS that is already being exploited in the ...
Spotify Scraping Incident: Anna’s Archive Publishes Massive Music Metadata and Audio Dump
Pirate meta-search engine Anna’s Archive has announced what it calls the largest unauthorized Spotify scraping operation to date. According to ...