Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

A monstrous worm emerging from barren ground surrounded by red npm boxes.

Shai-Hulud npm Worm: Self-Spreading Attack Abuses GitHub Actions to Trojanize Dependencies and Steal Secrets

CyberSecureFox Editorial Team

Security researchers have reported a large-scale compromise of more than 180 npm packages by a self-replicating malware strain that automatically ...

Samsung phone displaying security alert about CVE-2025-21043 with dark background.

Samsung patches Android zero-day CVE-2025-21043 in Quramsoft image codec

CyberSecureFox Editorial Team

Samsung has released a security update for CVE-2025-21043, a zero-day vulnerability rated CVSS 8.8 and confirmed as exploited in targeted ...

Cursor logo by OpenVSX on a textured, rust-colored background.

WhiteCobra abuses VS Code and Open VSX with malicious VSIX extensions targeting developers

CyberSecureFox Editorial Team

Threat analysts at Koi Security have identified a coordinated WhiteCobra campaign abusing the VS Code Marketplace and Open VSX Registry. ...

Business professionals observing a holographic security display in a modern office.

Commercial Spyware Funding Surges, Exposing Policy–Finance Gap and Supply-Chain Risks

CyberSecureFox Editorial Team

The commercial spyware market is expanding rapidly, with fresh capital accelerating despite mounting policy constraints. A new Atlantic Council report ...

Colorful Google logo next to stacks of coins and a gavel on a dark background.

EU Fines Google €2.95 Billion for Adtech Self-Preferencing: What It Means for RTB, Competition, and Cybersecurity

CyberSecureFox Editorial Team

The European Commission has imposed a €2.95 billion fine on Google for abusing its dominant position in digital advertising technology ...

Smartphone displaying a glowing padlock surrounded by breaking chains.

Apple Makes Memory Integrity Enforcement Default in iOS 26 to Thwart Advanced Exploit Chains

CyberSecureFox Editorial Team

Apple has unveiled the iPhone 17 and iPhone Air alongside a new platform defense called Memory Integrity Enforcement (MIE), a ...

Man interacting with a security interface displaying a skull icon and warning message.

HybridPetya ransomware uses UEFI bootkit to bypass Secure Boot via CVE-2024-7344

CyberSecureFox Editorial Team

ESET has analyzed a new ransomware strain dubbed HybridPetya that fuses Petya/NotPetya-style tactics with UEFI bootkit capabilities. The sample, discovered ...

Silhouettes of three figures in front of a Microsoft building with a fiery background.

Microsoft Patch Tuesday: 81 fixes, two zero‑days, and critical Azure, HPC Pack, and NTLM vulnerabilities

CyberSecureFox Editorial Team

Microsoft’s September Patch Tuesday delivers security fixes for 81 vulnerabilities across its product stack. The release includes nine critical issues, ...

Aerial view of a city with a large sign announcing the AI Darwin Awards.

AI Darwin Awards Open Nominations: Lessons for LLM Security After the Replit Incident

CyberSecureFox Editorial Team

AI Darwin Awards, a new initiative that documents high-impact failures in artificial intelligence deployments, has opened nominations with a clear ...

Adobe headquarters with the Golden Gate Bridge and vibrant autumn scenery.

CVE-2025-54236 “SessionReaper” in Adobe Commerce/Magento: Critical REST API Flaw Enables Account Takeover

CyberSecureFox Editorial Team

A critical vulnerability tracked as CVE-2025-54236 and informally dubbed SessionReaper impacts Adobe Commerce and Magento, earning a CVSS 9.1 severity. ...