Mastodon Mastodon Mastodon Mastodon

Cybersecurity News

Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.

Graphics showing VPN censorship concepts related to user privacy and restrictions.

Why Mozilla Warns UK VPN Restrictions Threaten Online Privacy

CyberSecureFox Editorial Team

Mozilla has submitted an official appeal to the Ministry of Science, Innovation and Technology of the United Kingdom (DSIT), in ...

Illustration depicting Android ad fraud with download icons and coins.

How Trapdoor Turned Android Utility Apps into a Massive Ad Fraud

CyberSecureFox Editorial Team

The HUMAN Satori Threat Intelligence team has uncovered a large-scale fraudulent operation named Trapdoor, targeting Android users. According to the ...

Nx Console logo connected to security symbols and a hacker figure.

How the Nx Console VS Code Extension Was Used to Steal Dev Credentials

CyberSecureFox Editorial Team

The popular Nx Console extension for Visual Studio Code (version 18.95.0) was compromised and used to deliver multi-stage malware that ...

GitHub logo breaking through a wall, Python container spreading malware to laptops.

TeamPCP’s Mini Shai-Hulud Campaign and the Compromise of GitHub and durabletask

CyberSecureFox Editorial Team

GitHub is investigating unauthorized access to its internal repositories, while at the same time the TeamPCP group is continuing a ...

Illustration of a phishing attack involving OAuth and Microsoft 365 with devices.

How EvilTokens Abuses OAuth Device Codes to Bypass MFA in Microsoft 365

CyberSecureFox Editorial Team

The EvilTokens platform, operating under a “phishing as a service” (PhaaS) model, according to Cloud Security Alliance data, exploits the ...

Blue shield with Drupal logo cracking under a red beam, signifying security alert.

Upcoming Drupal Core Security Fix for High-Severity Vulnerability

CyberSecureFox Editorial Team

Drupal has announced a planned release of a core security update for all supported branches, scheduled for May 20, 2026, ...

Diagram illustrating a GitHub Actions supply chain attack with commits.

Compromised GitHub Actions Steal CI/CD Credentials via Runner Memory

CyberSecureFox Editorial Team

The popular GitHub Actions actions-cool/issues-helper and actions-cool/maintain-one-comment have been compromised through a supply-chain attack: all existing tags in the repositories ...

Illustrated visualization of the Mini Shai-Hulud npm attack on AntV supply chain.

How the Mini Shai-Hulud Worm Compromised AntV npm Packages

CyberSecureFox Editorial Team

A large-scale npm supply chain attack has affected hundreds of packages in the @antv ecosystem — a popular data visualization ...

INTERPOL shield with cyber servers and MENA map highlighting disrupted crime.

How INTERPOL’s Operation Ramz Reshapes Cybercrime Enforcement in MENA

CyberSecureFox Editorial Team

INTERPOL has concluded an unprecedented coordinated anti-cybercrime operation in the Middle East and North Africa (MENA) region. Operation Ramz, conducted ...

Illustration depicting a digital worm emerging from an npm package box, symbolizing threats.

Analysis of Malicious npm Packages Delivering Shai-Hulud and More

CyberSecureFox Editorial Team

Researchers from OX Security discovered four malicious npm packages published by the same user but containing fundamentally different malicious payloads ...