Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Close-up of a gold credit card showcasing the chip and embossed numbers.

TA558 (RevengeHotels) uses LLM‑generated loaders to breach hotels and steal payment data

CyberSecureFox Editorial Team

Researchers at Kaspersky have identified a new wave of attacks by the cybercrime group known as RevengeHotels (also tracked as ...

User interacts with a digital alert for 224 removed malicious apps.

SlopAds Ad-Fraud Network Dismantled: 224 Android Apps Pulled from Google Play

CyberSecureFox Editorial Team

Google has removed 224 malicious Android apps from Google Play linked to the SlopAds ad‑fraud operation. According to Satori Threat ...

Police officer leads handcuffed man in orange jumpsuit outside a prison at dusk.

Appeals Court Sends BreachForums Admin ‘Pompompurin’ to Prison: What It Means for Cybercrime and Enterprise Risk

CyberSecureFox Editorial Team

A federal appeals court has vacated a previously lenient sentence and imposed a three‑year prison term on 22‑year‑old Connor Brian ...

Two contrasting scenes of a payment card transaction displaying $655.00.

KioSoft CVE-2025-8699: Vulnerable Prepaid NFC Cards Abused to Inflate Balances, Patch Arrived a Year Later

CyberSecureFox Editorial Team

Security researchers at SEC Consult (Eviden) uncovered a critical flaw in certain KioSoft prepaid NFC cards that power self-service payments ...

Man interacts with a digital interface featuring Microsoft and Cloudflare logos.

Microsoft and Cloudflare Dismantle RaccoonO365 Phishing-as-a-Service Targeting Microsoft 365

CyberSecureFox Editorial Team

Microsoft’s Digital Crimes Unit (DCU) and Cloudflare have jointly disrupted the RaccoonO365 phishing-as-a-service (PhaaS) operation used to steal Microsoft 365 ...

Man in suit with worried expression sits at desk in a bank office.

FinWise Bank Confirms Insider Data Breach Affecting American First Finance Customers

CyberSecureFox Editorial Team

FinWise Bank has disclosed a data security incident dated May 31, 2024, in which a former employee accessed confidential information ...

Cybersecurity duel: hacker in red and IT professional in blue, contrasting concepts.

Head Mare APT adopts multi‑stage backdoors and SSH tunneling in latest campaign

CyberSecureFox Editorial Team

Researchers at Kaspersky have observed a fresh wave of targeted intrusion activity by the Head Mare threat group against organizations ...

Man with a laptop showing a bat symbol against a dramatic sunset backdrop.

ComicForm runs dual-vector phishing across CIS, delivering FormBook via multi-stage .NET loader

CyberSecureFox Editorial Team

A new wave of targeted phishing in the CIS is being attributed to the threat group ComicForm. Active since at ...

A monstrous worm emerging from barren ground surrounded by red npm boxes.

Shai-Hulud npm Worm: Self-Spreading Attack Abuses GitHub Actions to Trojanize Dependencies and Steal Secrets

CyberSecureFox Editorial Team

Security researchers have reported a large-scale compromise of more than 180 npm packages by a self-replicating malware strain that automatically ...

Samsung phone displaying security alert about CVE-2025-21043 with dark background.

Samsung patches Android zero-day CVE-2025-21043 in Quramsoft image codec

CyberSecureFox Editorial Team

Samsung has released a security update for CVE-2025-21043, a zero-day vulnerability rated CVSS 8.8 and confirmed as exploited in targeted ...