Cybersecurity News

Stay up-to-date with the latest cybersecurity news and developments in the cybersecurity landscape. Be the first to know about the latest threats, current innovations, and major trends in the cyber universe. Check our Cyber News section for the freshest information.

Close-up of a red worm next to a textured "re" tile on brown surface.

IndonesianFoods worm overwhelms npm with 100k+ spam packages

CyberSecureFox 🦊

A new self-replicating campaign is saturating the npm ecosystem with spam packages. The worm, tracked as IndonesianFoods, is publishing new ...

Woman contemplating in a dimly lit room with symbols of justice and cryptocurrency.

UK Sentences Zhimin Qian for Crypto Laundering; Police Seize 61,000 BTC Linked to China’s Largest Ponzi Scheme

CyberSecureFox 🦊

A London court has sentenced 47‑year‑old Zhimin Qian, also known as Yadi Zhang, to 11 years and 8 months in ...

Android logo with a skull and crossbones illuminated against a dark background.

Uhale digital photo frames silently load malware via v4.2.0 update, with ties to the Vo1d botnet

CyberSecureFox 🦊

Security researchers at Quokka report that multiple digital photo frames built on the Uhale platform (part of the ZEASN ecosystem, ...

Russian passport next to a padlock engraved with a Bitcoin symbol.

Russian IAB Pleads Guilty to Supplying Access for Yanluowang Ransomware

CyberSecureFox 🦊

Russian national Alexey Olegovich Volkov—known online as chubaka.kor and nets—has pleaded guilty to selling initial access used by the Yanluowang ...

Man focused on laptop displaying security vulnerabilities in Docker and Kubernetes.

Three critical runC flaws expose Docker and Kubernetes to container escape

CyberSecureFox 🦊

Three critical vulnerabilities in the OCI reference runtime runC—widely used by Docker, containerd, CRI‑O, and Kubernetes—could let attackers bypass container ...

Man interacting with a warning display about a cybersecurity vulnerability.

CVE-2025-12480: Triofox localhost trust flaw under active exploitation enables unauthenticated SYSTEM RCE

CyberSecureFox 🦊

Google Threat Intelligence warns that attackers are actively exploiting CVE-2025-12480, a critical vulnerability in Gladinet Triofox that allows unauthenticated remote ...

Text label on a device showing firmware update details and version number.

ASUS Patches Critical Authentication Bypass in DSL-AC51, DSL-N16, and DSL-AC750 (CVE-2025-59367)

CyberSecureFox 🦊

ASUS has released an emergency firmware update to remediate CVE-2025-59367, a critical authentication bypass in several DSL router models. If ...

Vintage computer displays "archive.today" next to an FBI agent reading a document.

FBI Targets archive.today Operator With Broad Data Request to Tucows

CyberSecureFox 🦊

The FBI has reportedly sought information on the operator of archive.today (also known as archive.is, archive.ph and others), one of ...

Hacker in a dark landscape, facing two large padlocks labeled with CVE numbers.

Pre‑disclosure exploitation of Citrix Bleed 2 and Cisco ISE RCE identified in broad campaign

CyberSecureFox 🦊

Amazon Threat Intelligence has documented a large-scale campaign abusing two critical 0‑day vulnerabilities: CVE-2025-5777 (Citrix Bleed 2) affecting NetScaler ADC/Gateway ...

Scenic view with a GitHub sign, Golden Gate Bridge, and wildlife in a lush landscape.

Malicious npm Package @acitons/artifact Was a GitHub Red Team Drill — What Happened and How to Protect CI/CD

CyberSecureFox 🦊

Security researchers at Veracode reported a malicious npm package, @acitons/artifact, masquerading as the legitimate @actions/artifact and targeting GitHub Actions environments. ...