no alarms and no surprises please..
-
Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting
Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle transforms victims into unwitting…
-
Finland Arrests Two Cargo Ship Crew Members Over Undersea Cable Damage
Finland Arrests Two Cargo Ship Crew Members Over Undersea Cable Damage Finnish authorities have detained all 14 crew members of a cargo vessel suspected of deliberately damaging an undersea telecommunications cable connecting Helsinki to Estonia. The ship, named Fitburg, was sailing from St. Petersburg, Russia, to Haifa, Israel, under a St. Vincent and the Grenadines…
-
VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection
VVS Stealer Uses PyArmor Obfuscation to Evade Static Analysis and Signature Detection The cybersecurity landscape is witnessing a rise in sophisticated malware that leverages legitimate tools to mask malicious intent. A prime example is VVS Stealer (also styled VVS $tealer). This Python-based malware family has been actively marketed on Telegram since April 2025. This threat…
-
Handala Hackers Breach Telegram Accounts Linked to Israeli Officials
Handala Hackers Breach Telegram Accounts Linked to Israeli Officials In December 2025, the Iran-linked hacking group known as Handala escalated its influence operations against Israel’s political establishment by publishing material it claimed was… Go to gbhackers.com
-
Google Tasks Feature Exploited in New Sophisticated Phishing Campaign
Google Tasks Feature Exploited in New Sophisticated Phishing Campaign Over 3,000 organisations, predominantly in manufacturing, fell victim to a sophisticated phishing campaign in December 2025 that leveraged Google’s own application infrastructure to bypass… Go to gbhackers.com
-
Hacker Group Claims Responsibility for Alleged Tokyo FM Broadcasting Breach
Hacker Group Claims Responsibility for Alleged Tokyo FM Broadcasting Breach A threat actor operating under the alias “victim” has claimed responsibility for a significant data breach targeting Tokyo FM Broadcasting Co., Ltd., a central… Go to gbhackers.com
-
Cognizant Faces Multiple US Class-Action Lawsuits After TriZetto Data Breach
Cognizant Faces Multiple US Class-Action Lawsuits After TriZetto Data Breach Cognizant Technology Solutions is facing a wave of legal challenges in the United States following a significant data breach at its subsidiary, TriZetto Provider… Go to gbhackers.com
-
RondoDoX Botnet Abuses React2Shell Vulnerability for Malware Deployment
RondoDoX Botnet Abuses React2Shell Vulnerability for Malware Deployment CloudSEK has uncovered a sustained nine-month campaign by the RondoDoX botnet operation, revealing rapid exploitation of emerging vulnerabilities including the critical React2Shell vulnerability. Analysis… Go to gbhackers.com
-
Covenant Health says May data breach impacted nearly 478,000 patients
Covenant Health says May data breach impacted nearly 478,000 patients The Covenant Health organization has revised to nearly 500,000 the number of individuals affected by a data breach discovered last May. […] Ionut Ilascu Go to bleepingcomputer
-
Cryptocurrency theft attacks traced to 2022 LastPass breach
Cryptocurrency theft attacks traced to 2022 LastPass breach Blockchain investigation firm TRM Labs says ongoing cryptocurrency thefts have been traced to the 2022 LastPass breach, with attackers draining wallets years after encrypted vaults were stolen and laundering the crypto through Russian exchanges. […] Lawrence Abrams Go to bleepingcomputer
-
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass Over 10,000 Internet-exposed Fortinet firewalls are still vulnerable to attacks exploiting a five-year-old two-factor authentication (2FA) bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Google is testing a new image AI and it’s going to be its fastest model
Google is testing a new image AI and it’s going to be its fastest model Google is testing a new image AI model called “Nano Banana 2 Flash,” and it’s going to be as good as the Gemini 3 Pro Nano Banana, but it’ll be cheaper. […] Mayank Parmar Go to bleepingcomputer
-
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack Trust Wallet believes the compromise of its web browser to steal roughly $8.5 million from over 2,500 crypto wallets is likely related to an “industry-wide” Sha1-Hulud attack in November. […] Sergiu Gatlan Go to bleepingcomputer
-
10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability
10,000+ Fortinet Firewalls Still Exposed to 5-year Old MFA Bypass Vulnerability Over 10,000 Fortinet firewalls worldwide remain vulnerable to CVE-2020-12812, a multi-factor authentication (MFA) bypass flaw disclosed over five and a half years ago. Shadowserver recently added the issue to its daily Vulnerable HTTP Report, highlighting persistent exposure amid active exploitation confirmed by Fortinet in…
-
Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts
Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope—the breaches targeted Telegram accounts specifically, not complete device access. The group…
-
Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack
Hackers Abusing Google Tasks Notification for Sophisticated Phishing Attack Hackers have launched a sophisticated phishing campaign exploiting Google Tasks notifications to target over 3,000 organizations worldwide, primarily in the manufacturing sector. The December 2025 attacks signal a dangerous shift in email-based threats, in which attackers abuse legitimate Google infrastructure rather than spoofing domains or forging…
-
RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware
RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware A sophisticated threat group has intensified its campaign against organizations by leveraging the latest vulnerabilities in web applications and Internet of Things (IoT) devices. The RondoDoX botnet, tracked through exposed command-and-control logs spanning nine months from March to December 2025, demonstrates a relentless approach to…
-
Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement
Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement A sophisticated phishing campaign is currently circulating within the Cardano community, posing significant risks to users seeking to download the newly announced Eternl Desktop application. The attack leverages a professionally crafted email claiming to promote a legitimate wallet solution designed for secure Cardano token…
-
Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia
Transparent Tribe Launches New RAT Attacks Against Indian Government and Academia The threat actor known as Transparent Tribe has been attributed to a fresh set of attacks targeting Indian governmental, academic, and strategic entities with a remote access trojan (RAT) that grants them persistent control over compromised hosts. “The campaign employs deceptive delivery techniques, including…
-
The ROI Problem in Attack Surface Management
The ROI Problem in Attack Surface Management Attack Surface Management (ASM) tools promise reduced risk. What they usually deliver is more information. Security teams deploy ASM, asset inventories grow, alerts start flowing, and dashboards fill up. There is visible activity and measurable output. But when leadership asks a simple question, “Is this reducing incidents?” the…
-
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign Cybersecurity researchers have disclosed details of a phishing campaign that involves the attackers impersonating legitimate Google-generated messages by abusing Google Cloud’s Application Integration service to distribute emails. The activity, Check Point said, takes advantage of the trust associated with Google Cloud infrastructure to send the…
-
Friday Squid Blogging: Squid Found in Light Fixture
Friday Squid Blogging: Squid Found in Light Fixture Probably a college prank. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Flock Exposes Its AI-Enabled Surveillance Cameras
Flock Exposes Its AI-Enabled Surveillance Cameras 404 Media has the story: Unlike many of Flock’s cameras, which are designed to capture license plates as people drive by, Flock’s Condor cameras are pan-tilt-zoom (PTZ) cameras designed to record and track people, not vehicles. Condor cameras can be set to automatically zoom in on people’s faces as…
-
Debugging DNS response times with tshark, (Fri, Jan 2nd)
Debugging DNS response times with tshark, (Fri, Jan 2nd) One of my holiday projects was to redo and optimize part of my home network. One of my homelab servers failed in November. I had only thrown the replacement in the rack to get going, but some cleanup was needed. In addition, a lot of other “layer…
-
The Kimwolf Botnet is Stalking Your Local Network
The Kimwolf Botnet is Stalking Your Local Network The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been exploited for months already, and it’s time for a broader awareness of the threat. The short version is that everything you thought…
-
Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats
Cybersecurity Predictions for 2026: Navigating the Future of Digital Threats Cybersecurity experts discuss 2026 predictions, highlighting the rise of AI-driven threats, the shift to resilience over prevention, and the urgent need for advanced security measures to combat evolving risks Kristina Beek, Rob Wright Go to gbhackers.com
-
CTO New Year Resolutions for a More Secure 2026
CTO New Year Resolutions for a More Secure 2026 From securing MCPs and supply chain defenses to formal AI and quantum governance, experts share their wish lists for cyber safety in 2026. Ericka Chickowski, Contributing Writer Go to gbhackers.com
-
OpenAI is offering $20 ChatGPT Plus for free to some users
OpenAI is offering $20 ChatGPT Plus for free to some users If you’re already subscribed to ChatGPT Plus, which costs $20, you can request OpenAI to cancel your subscription, and it may offer one month of free usage. […] Mayank Parmar Go to bleepingcomputer
-
The biggest cybersecurity and cyberattack stories of 2025
The biggest cybersecurity and cyberattack stories of 2025 2025 was a big year for cybersecurity, with cyberattacks, data breaches, threat groups reaching new notoriety levels, and, of course, zero-day flaws exploited in breaches. Some stories, though, were more impactful or popular with our readers than others. This article explores 15 of the biggest cybersecurity stories…
-
New GlassWorm malware wave targets Macs with trojanized crypto wallets
New GlassWorm malware wave targets Macs with trojanized crypto wallets A fourth wave of the “GlassWorm” campaign is targeting macOS developers with malicious VSCode/OpenVSX extensions that deliver trojanized versions of crypto wallet applications. […] Bill Toulas Go to bleepingcomputer
-
Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild
Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild The cybersecurity community was alarmed in late December 2025 when MongoDB announced a serious vulnerability called “Mongobleed” (CVE-2025-14847). This high-severity flaw allows unauthenticated attackers to steal sensitive data directly from server memory. With a CVSS score of 8.7 and over 87,000 potentially vulnerable MongoDB…
-
Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics
Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics After a decade of disappearing from the cybersecurity landscape, the Careto threat group, also known as “The Mask,” has resurfaced with sophisticated new attack methods targeting high-profile organizations. Security researchers have identified fresh evidence of Careto’s activity, revealing how the group…
-
Apache NuttX Vulnerability Let Attackers to Crash Systems
Apache NuttX Vulnerability Let Attackers to Crash Systems A newly disclosed use-after-free vulnerability in Apache NuttX RTOS could allow attackers to cause system crashes and unintended filesystem operations, prompting urgent security warnings for users running network-exposed services. The flaw, tracked as CVE-2025-48769 and rated moderate in severity, affects a wide range of NuttX versions and…
-
Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild
Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild The cybersecurity landscape in 2025 has been marked by an unprecedented surge in critical vulnerabilities, with over 21,500 CVEs disclosed in the first half of the year alone, representing a 16-18% increase compared to 2024. Among these, a select group of vulnerabilities stands out…
-
WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups
WhatsApp Crypt Tool to Encrypt and Decrypt WhatsApp Backups An open-source solution for handling encrypted WhatsApp backups. The wa-crypt-tools suite, hosted on GitHub, decrypts and encrypts .crypt12, .crypt14, and .crypt15 files from WhatsApp and WhatsApp Business, provided users supply the required key file or 64-character key. wa-crypt-tools simplifies access to WhatsApp’s end-to-end encrypted backups, which…
-
ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories
ThreatsDay Bulletin: GhostAd Drain, macOS Attacks, Proxy Botnets, Cloud Exploits, and 12+ Stories The first ThreatsDay Bulletin of 2026 lands on a day that already feels symbolic — new year, new breaches, new tricks. If the past twelve months taught defenders anything, it’s that threat actors don’t pause for holidays or resolutions. They just evolve…
-
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers Cybersecurity researchers have disclosed details of a persistent nine-month-long campaign that has targeted Internet of Things (IoT) devices and web applications to enroll them into a botnet known as RondoDox. As of December 2025, the activity has been observed leveraging the recently…
-
How To Browse Faster and Get More Done Using Adapt Browser
How To Browse Faster and Get More Done Using Adapt Browser As web browsers evolve into all-purpose platforms, performance and productivity often suffer. Feature overload, excessive background processes, and fragmented workflows can slow down browsing sessions and introduce unnecessary friction, especially for users who rely on the browser as a primary work environment. This article…
-
GlassWorm Malware Turns VS Code Extensions into an Attack Vector Against macOS
GlassWorm Malware Turns VS Code Extensions into an Attack Vector Against macOS GlassWorm has returned with a dangerous new evolution. The notorious self-propagating malware, which first surfaced in October as an invisible Unicode-based threat in VS… Go to gbhackers.com
-
New Cybercrime Tool “ErrTraffic” Enables Automated ClickFix Attacks
New Cybercrime Tool “ErrTraffic” Enables Automated ClickFix Attacks The cybercriminal underground has entered a new phase of industrialization. Hudson Rock researchers have uncovered ErrTraffic v2, a sophisticated ClickFix-as-a-Service platform that commoditizes deceptive… Go to gbhackers.com
-
NeuroSploit v2 Launches as AI-Powered Penetration Testing Framework
NeuroSploit v2 Launches as AI-Powered Penetration Testing Framework NeuroSploit v2 is an advanced AI-powered penetration testing framework designed to automate and enhance offensive security operations. Leveraging cutting-edge large language model (LLM) technology,… Go to gbhackers.com
-
DarkSpectre Malware Campaign Hits Chrome, Edge, and Firefox Users
DarkSpectre Malware Campaign Hits Chrome, Edge, and Firefox Users A sophisticated Chinese threat actor dubbed DarkSpectre has compromised 8.8 million users across Chrome, Edge, and Firefox through three distinct malware campaigns that have… Go to gbhackers.com
-
Malicious Manipulation of LLMs for Scalable Vulnerability Exploitation
Malicious Manipulation of LLMs for Scalable Vulnerability Exploitation A groundbreaking study from researchers at the University of Luxembourg reveals a critical security paradigm shift: large language models (LLMs) are being weaponized to… Go to gbhackers.com
-
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices New York City’s 2026 mayoral inauguration of Zohran Mamdani has published a list of banned items for the event, specifically prohibiting the Flipper Zero and Raspberry Pi devices. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers drain $3.9M from Unleash Protocol after multisig hijack
Hackers drain $3.9M from Unleash Protocol after multisig hijack The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract upgrade that allowed asset withdrawals. […] Bill Toulas Go to bleepingcomputer
-
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
RondoDox botnet exploits React2Shell flaw to breach Next.js servers The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. […] Bill Toulas Go to bleepingcomputer
-
IBM warns of critical API Connect auth bypass vulnerability
IBM warns of critical API Connect auth bypass vulnerability IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users
Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users A new wave of GlassWorm malware has emerged, marking a significant shift in targeting strategy from Windows to macOS systems. This self-propagating worm, distributed through malicious VS Code extensions on the Open VSX marketplace, has already accumulated over 50,000 downloads. The fourth wave introduces several…
-
New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks
New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks A dangerous cybercrime tool known as ErrTraffic has appeared in underground forums, making it easier for attackers to trick users into running harmful software on their devices. The tool automates what security experts call ClickFix attacks, where fake error messages push people to manually execute malicious…
-
DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware
DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns spanning seven years. The discovery reveals a level of operational sophistication rarely seen…
-
Critical IBM API Connect Vulnerability Let Attackers Bypass Logins
Critical IBM API Connect Vulnerability Let Attackers Bypass Logins A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms. Discovered during internal testing, the flaw poses a significant risk to organizations relying on the platform for API management. It grants unauthorized actors…
-
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Large Language Models (LLMs) have revolutionized software development, democratizing coding capabilities for non-programmers. However, this accessibility has introduced a severe security crisis. Advanced AI tools, designed to assist developers, are now being weaponized to automate the creation of sophisticated exploits against enterprise software. This shift fundamentally challenges…
-
TR-25-0493 (SOUND4 Çoklu Ürün Güvenlik Zafiyeti)
TR-25-0493 (SOUND4 Çoklu Ürün Güvenlik Zafiyeti) Go to usom.gov
-
TR-25-0492 (Akuvox Güvenlik Bildirimi)
TR-25-0492 (Akuvox Güvenlik Bildirimi) Go to usom.gov
-
Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack
Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for the hack of its Google Chrome extension, ultimately resulting in the theft of approximately $8.5 million in assets. “Our…
-
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster, has been attributed to a third attack campaign codenamed DarkSpectre that has impacted 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla Firefox. The activity is assessed to be the work…
-
Critical CVSS 9.8 Flaw Found in IBM API Connect Authentication System
Critical CVSS 9.8 Flaw Found in IBM API Connect Authentication System IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application. The vulnerability, tracked as CVE-2025-13915, is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system. It has…
-
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight modifications from the previous wave observed last month. The npm package that embeds the novel Shai Hulud strain is “@vietmoney/react-big-calendar,” which was uploaded…
-
LinkedIn Job Scams
LinkedIn Job Scams Interesting article on the variety of LinkedIn job scams around the world: In India, tech jobs are used as bait because the industry employs millions of people and offers high-paying roles. In Kenya, the recruitment industry is largely unorganized, so scamsters leverage fake personal referrals. In Mexico, bad actors capitalize on the…
-
Sunken Ships: Will Orgs Learn From Ivanti EPMM Attacks?
Sunken Ships: Will Orgs Learn From Ivanti EPMM Attacks? The April/May zero-day exploitations of Ivanti’s mobile device management platform meant unprecedented pwning of thousands of orgs by a Chinese APT — and history will probably repeat itself. Tara Seals Go to gbhackers.com
-
When the Cloud Rains on Everyone’s IoT Parade
When the Cloud Rains on Everyone’s IoT Parade What happens to all of those always-connected devices and Internet of Things when the cloud goes down? Disruptions to sleep, school, and smart homes, just to name a few issues. Arielle Waldman Go to gbhackers.com
-
Identity Security 2026: Four Predictions and Recommendations
Identity Security 2026: Four Predictions and Recommendations Agentic AI adoption and identity security risks, IGA expands in mid-market, SOC-identity team collaboration, and identity platform consolidation—this 2026 predictions post previews identity trends. Todd Thiemann Go to gbhackers.com
-
Contrarians No More: AI Skepticism Is on the Rise
Contrarians No More: AI Skepticism Is on the Rise Concerns about an economic bubble bursting, along with doubts regarding return on investment, suggest the tide may be turning for the artificial intelligence industry. Rob Wright Go to gbhackers.com
-
Cybersecurity Predictions 2026: An AI Arms Race and Malware Autonomy
Cybersecurity Predictions 2026: An AI Arms Race and Malware Autonomy The year ahead will see an intensified AI-driven cybersecurity arms race, with attackers leveraging autonomous malware and advanced AI technologies to outpace defenders, while security teams adopt increasingly sophisticated AI tools to combat evolving threats amidst growing vendor consolidation and platformization in the industry. Tyler…
-
Magecart Campaign Deploys 50+ Malicious Scripts to Hijack E-Commerce Transactions
Magecart Campaign Deploys 50+ Malicious Scripts to Hijack E-Commerce Transactions A sophisticated and expansive Magecart campaign has been uncovered, marking a dangerous evolution in client-side attacks. Security researchers have identified a global operation utilizing… Go to gbhackers.com
-
Hackers Promote “VOID” AV Killer Claiming Kernel-Level Defense Evasion
Hackers Promote “VOID” AV Killer Claiming Kernel-Level Defense Evasion A threat actor operating under the handle Crypt4You has begun advertising a sophisticated new offensive tool on underground cybercrime forums, marketed as a “kernel-level” security neutralization… Go to gbhackers.com
-
ESET Flags Rising Threat of AI-Driven Malware and Ransomware
ESET Flags Rising Threat of AI-Driven Malware and Ransomware The cybersecurity landscape entered a critical new era in the second half of 2025 as AI-powered malware transitioned from theoretical threat to tangible reality,… Go to gbhackers.com
-
Critical IBM API Connect Flaw Allows Attackers to Bypass Authentication
Critical IBM API Connect Flaw Allows Attackers to Bypass Authentication IBM has disclosed a critical authentication bypass vulnerability affecting its API Connect platform, assigning it a maximum CVSS severity score of 9.8. The flaw,… Go to gbhackers.com
-
New Spear-Phishing Attack Targeting Security Individuals in the Israel Region
New Spear-Phishing Attack Targeting Security Individuals in the Israel Region Israel’s National Cyber Directorate has issued an urgent alert warning of an active spear-phishing campaign specifically targeting individuals employed in security and defense-related sectors…. Go to gbhackers.com
-
Disney will pay $10 million to settle children’s data privacy lawsuit
Disney will pay $10 million to settle children’s data privacy lawsuit Disney has agreed to pay a $10 million civil penalty to settle claims that it violated the Children’s Online Privacy Protection Act by mislabeling videos and allowing data collection for targeted advertising. […] Sergiu Gatlan Go to bleepingcomputer
-
New ErrTraffic service enables ClickFix attacks via fake browser glitches
New ErrTraffic service enables ClickFix attacks via fake browser glitches A new cybercrime tool called ErrTraffic allows threat actors to automate ClickFix attacks by generating ‘fake glitches’ on compromised websites to lure users into downloading payloads or following malicious instructions […] Bill Toulas Go to bleepingcomputer
-
European Space Agency confirms breach of “external servers”
European Space Agency confirms breach of “external servers” The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as “unclassified” information on collaborative engineering activities. […] Sergiu Gatlan Go to bleepingcomputer
-
Zoom Stealer browser extensions harvest corporate meeting intelligence
Zoom Stealer browser extensions harvest corporate meeting intelligence A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect online meeting-related data like URLs, IDs, topics, descriptions, and embedded passwords. […] Bill Toulas Go to bleepingcomputer
-
US cybersecurity experts plead guilty to BlackCat ransomware attacks
US cybersecurity experts plead guilty to BlackCat ransomware attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. […] Sergiu Gatlan Go to bleepingcomputer
-
Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass
Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass Dark web forums have become a marketplace for sophisticated malware tools, with threat actors continuously refining their capabilities to stay ahead of security solutions. The latest concerning development involves an emerging AI-powered crypter service that promises unprecedented evasion abilities, putting enterprise environments at…
-
Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control
Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-47411 and rated important, affects Apache StreamPipes versions 0.69.0 through 0.97.0. The vulnerability stems from a flawed user ID creation…
-
Open-Source C2 Platform AdaptixC2 Released With Enhanced Stability, Performance, and Speed
Open-Source C2 Platform AdaptixC2 Released With Enhanced Stability, Performance, and Speed The Adaptix Framework team has announced a significant update to AdaptixC2, an open-source post-exploitation and adversarial emulation platform designed for penetration testers. The latest version introduces significant improvements to network tunneling, the user interface, and overall system performance. One of the most notable upgrades focuses…
-
Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows
Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack demonstrates a significant…
-
Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims
Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims The cybercriminal threat actor known as Crypt4You has recently emerged on underground forums and dark web marketplaces, advertising a sophisticated tool named VOID KILLER. This malicious software operates as a kernel-level antivirus and endpoint detection response (EDR) process killer, designed to evade and neutralize security defenses.…
-
This month in security with Tony Anscombe – December 2025 edition
This month in security with Tony Anscombe – December 2025 edition As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year Go to eset
-
TR-25-0491 (Tenda Güvenlik Bildirimi)
TR-25-0491 (Tenda Güvenlik Bildirimi) Go to usom.gov
-
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a commercial spyware known as Predator, from the specially designated nationals list. The names of the…
-
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691, carries a CVSS score of 10.0. It relates…
-
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware
Silver Fox Targets Indian Users With Tax-Themed Emails Delivering ValleyRAT Malware The threat actor known as Silver Fox has turned its focus to India, using income tax-themed lures in phishing campaigns to distribute a modular remote access trojan called ValleyRAT (aka Winos 4.0). “This sophisticated attack leverages a complex kill chain involving DLL hijacking and…
-
How to Integrate AI into Modern SOC Workflows
How to Integrate AI into Modern SOC Workflows Artificial intelligence (AI) is making its way into security operations quickly, but many practitioners are still struggling to turn early experimentation into consistent operational value. This is because SOCs are adopting AI without an intentional approach to operational integration. Some teams treat it as a shortcut for…
-
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor The Chinese hacking group known as Mustang Panda has leveraged a previously undocumented kernel-mode rootkit driver to deliver a new variant of backdoor dubbed TONESHELL in a cyber attack detected in mid-2025 targeting an unspecified entity in Asia. The findings come from Kaspersky, which observed…
-
Using AI-Generated Images to Get Refunds
Using AI-Generated Images to Get Refunds Scammers are generating images of broken merchandise in order to apply for refunds. Bruce Schneier Go to bruce schneier
-
New Tech Deployments Cyber Insurers Recommend for 2026
New Tech Deployments Cyber Insurers Recommend for 2026 An analysis of cyber-insurance claims data shows which cyber defenses actually work for policyholders. Here are six technologies that will pay off for companies in 2026. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Hacker Dumped MacBook in River in Attempt to Destroy Digital Evidence
Hacker Dumped MacBook in River in Attempt to Destroy Digital Evidence A former employee of South Korean e-commerce giant Coupang attempted to destroy evidence of a massive data theft by throwing his MacBook Air into… Go to gbhackers.com
-
Hackers Launch 2.5 Million+ Malicious Requests Targeting Adobe ColdFusion Servers
Hackers Launch 2.5 Million+ Malicious Requests Targeting Adobe ColdFusion Servers Security researchers have uncovered a massive coordinated exploitation campaign where threat actors launched over 2.5 million malicious requests against vulnerable systems during the Christmas… Go to gbhackers.com
-
Critical Zero-Day RCE Flaw in Networking Devices Exposes Over 70,000 Hosts
Critical Zero-Day RCE Flaw in Networking Devices Exposes Over 70,000 Hosts A severe unauthenticated remote code execution vulnerability has been discovered in XSpeeder networking devices, potentially affecting more than 70,000 publicly accessible hosts worldwide. Tracked… Go to gbhackers.com
-
New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones
New Bluetooth Headphone Vulnerabilities Allow Hackers to Hijack Connected Smartphones Security researchers have disclosed critical vulnerabilities in Airoha-based Bluetooth headphones that enable attackers to compromise connected smartphones through chained exploits. The three vulnerabilities CVE-2025-20700,… Go to gbhackers.com
-
Silver Fox Hackers Target Indian Entities Using Income Tax Phishing Lures
Silver Fox Hackers Target Indian Entities Using Income Tax Phishing Lures Threat intelligence researchers at CloudSEK have uncovered a sophisticated phishing campaign targeting Indian entities using Income Tax-themed lures, attributed to the Chinese-aligned Silver Fox… Go to gbhackers.com
-
Chinese state hackers use rootkit to hide ToneShell malware activity
Chinese state hackers use rootkit to hide ToneShell malware activity A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations. […] Bill Toulas Go to bleepingcomputer
-
Coupang to split $1.17 billion among 33.7 million data breach victims
Coupang to split $1.17 billion among 33.7 million data breach victims Coupang, the largest retailer in South Korea, announced $1.17 billion (1.685 trillion Won) total compensation for the 33.7 million customers whose information was exposed in the data breach discovered last month. […] Bill Toulas Go to bleepingcomputer
-
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as the KMSAuto tool for illegally activating Windows and Office software. […] Bill Toulas Go to bleepingcomputer
-
Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack
Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack Trust Wallet says attackers who compromised its browser extension right before Christmas have drained approximately $7 million from nearly 3,000 cryptocurrency wallet addresses. […] Sergiu Gatlan Go to bleepingcomputer
-
The Real-World Attacks Behind OWASP Agentic AI Top 10
The Real-World Attacks Behind OWASP Agentic AI Top 10 OWASP’s new Agentic AI Top 10 highlights real-world attacks already targeting autonomous AI systems, from goal hijacking to malicious MCP servers. Koi Security breaks down real-world incidents behind multiple categories, including two cases cited by OWASP, showing how agent tools and runtime behavior are being abused.…
-
EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack
EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated infostealer malware. Between December 19 and December 22, 2025, the official EmEditor website fell victim to unauthorized modification, serving compromised installer files to…
-
Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Chinese threat actors operating under the name Silver Fox are targeting Indian organizations through sophisticated phishing campaigns that impersonate legitimate income tax documents. The attack campaign uses authentic-looking Income Tax Department emails to trick users into downloading a malicious executable disguised as a tax-related…