no alarms and no surprises please..
-
New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins A Spanish-speaking phishing operation targeting Microsoft Outlook users has been active since March 2025, using a sophisticated kit that shows clear indicators of AI-assisted development. The campaign, tracked through a unique signature of four mushroom emojis embedded in the string “OUTL,” has been…
-
Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks Public reports about cyberattacks often present a polished picture—threat actors working methodically through a well-planned playbook with every action perfectly executed. This perception leads many to believe that modern attackers operate with machine-like precision, seamlessly moving from one objective to another without facing obstacles. However,…
-
2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers
2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers A coordinated exploitation campaign that generated more than 2.5 million malicious requests against Adobe ColdFusion servers and 47+ other technology platforms during the Christmas 2025 holiday period. The operation was attributed to a single threat actor operating from Japan-based infrastructure. This indicates an advanced scanning…
-
TR-25-0490 (D Link Güvenlik Bildirimi)
TR-25-0490 (D Link Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0489 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0489 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More
⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A…
-
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 potentially susceptible instances identified across the world. The vulnerability in question is CVE-2025-14847 (CVSS score: 8.7), which allows an unauthenticated attacker to remotely leak sensitive data from the MongoDB server…
-
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials Cybersecurity researchers have disclosed details of what has been described as a “sustained and targeted” spear-phishing campaign that has published over two dozen packages to the npm registry to facilitate credential theft. The activity, which involved uploading 27 npm packages from six different…
-
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials. Throughout 2024, ChatGPT vulnerabilities allowed unauthorized extraction of user data from AI…
-
Are We Ready to Be Governed by Artificial Intelligence?
Are We Ready to Be Governed by Artificial Intelligence? Artificial Intelligence (AI) overlords are a common trope in science-fiction dystopias, but the reality looks much more prosaic. The technologies of artificial intelligence are already pervading many aspects of democratic government, affecting our lives in ways both large and small. This has occurred largely without our…
-
Happy 16th Birthday, KrebsOnSecurity.com!
Happy 16th Birthday, KrebsOnSecurity.com! KrebsOnSecurity.com celebrates its 16th anniversary today! A huge “thank you” to all of our readers — newcomers, long-timers and drive-by critics alike. Your engagement this past year here has been tremendous and truly a salve on a handful of dark days. Happily, comeuppance was a strong theme running through our coverage…
-
SBOMs in 2026: Some Love, Some Hate, Much Ambivalence
SBOMs in 2026: Some Love, Some Hate, Much Ambivalence With a new year upon us, software and cybersecurity experts disagree on the utility of software bill of materials — in theory, SBOMs are great, but in practice, they’re a mess. Robert Lemos, Contributing Writer Go to gbhackers.com
-
5 Threats That Defined Security in 2025
5 Threats That Defined Security in 2025 2025 included a number of monumental threats, from the global attacks of Salt Typhoon to dangerous vulnerabilities like React2Shell. Alexander Culafi Go to gbhackers.com
-
Hacktivist Proxies and the Normalization of Cyber Pressure Campaigns
Hacktivist Proxies and the Normalization of Cyber Pressure Campaigns A significant shift in the cyber threat landscape has been identified in a new research report, distinguishing modern “Hacktivist Proxy Operations” from traditional digital… Go to gbhackers.com
-
MongoBleed Detector Launched to Identify Critical MongoDB Flaw (CVE-2025-14847)
MongoBleed Detector Launched to Identify Critical MongoDB Flaw (CVE-2025-14847) Security researchers have released an open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting multiple… Go to gbhackers.com
-
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web. […] Ionut Ilascu Go to bleepingcomputer
-
Hacker claims to leak WIRED database with 2.3 million records
Hacker claims to leak WIRED database with 2.3 million records A hacker claims to have breached Condé Nast and leaked an alleged WIRED database containing more than 2.3 million subscriber records, while also warning that they plan to release up to 40 million additional records for other Condé Nast properties. […] Lawrence Abrams Go to…
-
MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)
MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847) An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases. The vulnerability allows attackers to extract sensitive information, including credentials, session tokens, and personally identifiable information, directly from server memory without requiring authentication. The flaw exists…
-
OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks
OpenAI Hardened ChatGPT Atlas Against Prompt Injection Attacks OpenAI has rolled out a critical security update to ChatGPT Atlas, its browser-based AI agent, introducing advanced defenses against prompt injection attacks. The update marks a significant step in protecting users from emerging adversarial threats targeting agentic AI systems. What Are Prompt Injection Attacks? Prompt injection attacks…
-
Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records
Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records Hackers have leaked a database containing over 2.3 million WIRED subscriber records, marking a major breach at Condé Nast, the parent company. The threat actor “Lovely” claims this is just the start, promising to release up to 40 million more records from brands like…
-
MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk
MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk A high-severity unauthenticated information-leak vulnerability in MongoDB Server, dubbed MongoBleed after the infamous Heartbleed bug, is now being actively exploited in real-world attacks. MongoDB has disclosed CVE-2025-14847, a critical flaw affecting multiple supported and legacy server versions that allows unauthenticated remote attackers to…
-
Weekly Update 484
Weekly Update 484 I think the start of this week’s video really nailed it for the techies amongst us: shit doesn’t work, you change something random and now shit works and yu have no idea why 🤷♂️ Such was my audio this week and apoligise to those of you watching the video below for the…
-
Hackers Compromise Trust Wallet Chrome Extension, Users Claim Millions Stolen
Hackers Compromise Trust Wallet Chrome Extension, Users Claim Millions Stolen Trust Wallet users suffered devastating losses exceeding $7 million after cybercriminals compromised the Chrome browser extension version 2.68.0, released on December 24, 2025. The… Go to gbhackers.com
-
Massive Rainbow Six Siege breach gives players billions of credits
Massive Rainbow Six Siege breach gives players billions of credits Ubisoft’s Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players, manipulate in-game moderation feeds, and grant massive amounts of in-game currency and cosmetic items to accounts worldwide. […] Lawrence Abrams Go to bleepingcomputer
-
Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability
Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability The chaos surrounding Ubisoft escalated significantly today as the first group of hackers, previously known for silent exploits, initiated a highly visible and disruptive takeover of Rainbow Six Siege servers. Players worldwide are reporting a massive influx of in-game currency, unwarranted bans, and taunting messages…
-
87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released
87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory. Dubbed “MongoBleed” due to its automated similarities to the infamous Heartbleed bug, the flaw tracks as CVE-2025-14847 and carries a CVSS score of 7.5.…
-
Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data
Mongobleed PoC Exploit Tool Released for MongoDB Flaw that Exposes Sensitive Data A proof-of-concept (PoC) exploit dubbed “mongobleed” for CVE-2025-14847, a critical unauthenticated memory leak vulnerability in MongoDB’s zlib decompression handling. Dubbed by its creator Joe Desimone as a way to bleed sensitive server memory, the flaw lets attackers remotely extract uninitialized data without credentials,…
-
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described as a case of improper handling of length parameter inconsistency, which arises when a program fails…
-
ISC Stormcast For Sunday, December 28th, 2025 https://isc.sans.edu/podcastdetail/9750, (Sun, Dec 28th)
ISC Stormcast For Sunday, December 28th, 2025 https://isc.sans.edu/podcastdetail/9750, (Sun, Dec 28th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Google Introduces Option to Change @gmail.com Email Addresses
Google Introduces Option to Change @gmail.com Email Addresses For years, Google users have been stuck with the email addresses they created when they first signed up. If you picked an embarrassing username… Go to gbhackers.com
-
Critical LangChain Vulnerability Allows Attackers to Steal Sensitive Secrets
Critical LangChain Vulnerability Allows Attackers to Steal Sensitive Secrets A critical security vulnerability in LangChain, one of the world’s most widely deployed AI frameworks, enables attackers to extract environment variable secrets and, through… Go to gbhackers.com
-
OpenAI’s ChatGPT ads will allegedly prioritize sponsored content in answers
OpenAI’s ChatGPT ads will allegedly prioritize sponsored content in answers OpenAI is reportedly mulling a new form of ads on ChatGPT called “sponsored content,” which could influence your buying decisions. […] Mayank Parmar Go to bleepingcomputer
-
Fake Grubhub emails promise tenfold return on sent cryptocurrency
Fake Grubhub emails promise tenfold return on sent cryptocurrency Grubhub users received fraudulent messages, apparently from a company email address, promising a tenfold bitcoin payout in return for a transfer to a specified wallet. […] Ionut Ilascu Go to bleepingcomputer
-
Trust Wallet confirms extension hack led to $7 million crypto theft
Trust Wallet confirms extension hack led to $7 million crypto theft Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers.…
-
TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data
TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data Multiple critical vulnerabilities in TeamViewer DEX Client’s Content Distribution Service (NomadBranch.exe), formerly part of 1E Client. Affecting Windows versions before 25.11 and select older branches, the flaws stem from improper input validation (CWE-20), potentially enabling attackers on the local network to execute code,…
-
M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users
M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users An information disclosure vulnerability in M-Files Server enables authenticated attackers to capture and reuse session tokens from active users. Potentially gaining unauthorized access to sensitive document management systems. The flaw, tracked as CVE-2025-13008, affects multiple versions across different release branches and carries a high-severity…
-
TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses
TrustWallet Chrome Extension Hacked – Users Reporting Millions in Losses Many Trust Wallet users saw their wallets drained of over $7 million after a security breach in the Chrome browser extension version 2.68.0, released on December 24, 2025. Blockchain investigator ZachXBT first flagged the incident on X, noting a surge in unauthorized outflows from affected…
-
TR-25-0488 (IBM Güvenlik Bildirimi)
TR-25-0488 (IBM Güvenlik Bildirimi) Go to usom.gov
-
Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code
Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a “security incident” that led to the loss of approximately $7 million. The issue, the multi‑chain, non‑custodial cryptocurrency wallet service said, impacts…
-
China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware
China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its signature MgBot backdoor in attacks targeting victims in Türkiye, China, and India. The activity, Kaspersky…
-
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even influence large language model (LLM) responses through prompt injection. LangChain Core (i.e., langchain-core) is a core Python package that’s part of the LangChain…
-
Friday Squid Blogging: Squid Camouflage
Friday Squid Blogging: Squid Camouflage New research: Abstract: Coleoid cephalopods have the most elaborate camouflage system in the animal kingdom. This enables them to hide from or deceive both predators and prey. Most studies have focused on benthic species of octopus and cuttlefish, while studies on squid focused mainly on the chromatophore system for communication.…
-
IoT Hack
IoT Hack Someone hacked an Italian ferry. It looks like the malware was installed by someone on the ferry, and not remotely. Bruce Schneier Go to bruce schneier
-
Mentorship and Diversity: Shaping the Next Generation of Cyber Experts
Mentorship and Diversity: Shaping the Next Generation of Cyber Experts Patricia Voight, CISO at Webster Bank, shares her expertise on advancing cybersecurity careers, combating financial crimes, and championing diversity in a rapidly changing industry. Kristina Beek Go to gbhackers.com
-
As More Coders Adopt AI Agents, Security Pitfalls Lurk in 2026
As More Coders Adopt AI Agents, Security Pitfalls Lurk in 2026 Developers are leaning more heavily on AI for code generation, but in 2026, the development pipeline and security need to be prioritized. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Dark Reading Opens The State of Application Security Survey
Dark Reading Opens The State of Application Security Survey Take part in the new survey from Dark Reading and help uncover trends, challenges, and solutions shaping the future of application security. Fahmida Y. Rashid Go to gbhackers.com
-
Unpatched FortiGate Security Flaw Allows Attackers to Bypass 2FA Controls
Unpatched FortiGate Security Flaw Allows Attackers to Bypass 2FA Controls A critical authentication bypass vulnerability in FortiGate devices enables threat actors to circumvent two-factor authentication (2FA) protections through case-sensitive username manipulation. The flaw, tracked… Go to gbhackers.com
-
Trust Wallet Chrome extension hack tied to millions in losses
Trust Wallet Chrome extension hack tied to millions in losses Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers. […]…
-
ChatGPT’s new formatting blocks make its UI look more like a task tool
ChatGPT’s new formatting blocks make its UI look more like a task tool OpenAI has quietly rolled out ‘formatting blocks,’ which tweak GPT’s layout to match the UI of the task it is supposed to execute. […] Mayank Parmar Go to bleepingcomputer
-
Google will finally allow you to change your @gmail.com address
Google will finally allow you to change your @gmail.com address Google will finally allow you to change your @gmail address or create a new alias, according to a new support document. […] Mayank Parmar Go to bleepingcomputer
-
Parrot 7.0 Released with New Penetration Testing and AI Tools
Parrot 7.0 Released with New Penetration Testing and AI Tools Parrot OS 7.0, codenamed Echo, launches as a complete system rewrite based on Debian 13, bringing KDE Plasma 6, Wayland by default, and fresh penetration testing tools, including a dedicated AI category. This release emphasizes lightweight theming and community-driven spins, marking a pivotal update for…
-
Critical Langchain Vulnerability Let attackers Exfiltrate Sensitive Secrets from AI systems
Critical Langchain Vulnerability Let attackers Exfiltrate Sensitive Secrets from AI systems A critical vulnerability in LangChain’s core library (CVE-2025-68664) allows attackers to exfiltrate sensitive environment variables and potentially execute code through deserialization flaws. Discovered by a Cyata researcher and patched just before Christmas 2025, the issue affects one of the most popular AI frameworks with…
-
Google Now Allows Users to Change Their @gmail.com Email Address
Google Now Allows Users to Change Their @gmail.com Email Address For years, one of the most persistent frustrations for Google users has been the inability to alter their primary email address without creating an entirely new account. Whether you are stuck with an unprofessional handle created in high school or simply want a rebrand, Google…
-
100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild
100+ Cybersecurity Predictions 2026 for Industry Experts as the AI Adapted in the Wild As artificial intelligence becomes deeply embedded in enterprise operations and cybercriminal arsenals alike, the Cybersecurity Predictions 2026 landscape reveals an unprecedented convergence of autonomous threats, identity-centric attacks, and accelerated digital transformation risks. Industry experts across leading security firms, government agencies, and research institutions…
-
Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash
Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide. Tracked as CVE-2025-68615, this security flaw allows remote attackers to trigger a buffer overflow, leading to a service crash or potentially a more severe system compromise.…
-
TR-25-0487 (Verisay İletişim ve Bilgi Teknoloji – Aidango Güvenlik Bildirimi)
TR-25-0487 (Verisay İletişim ve Bilgi Teknoloji – Aidango Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0486 (Verisay İletişim ve Bilgi Teknoloji – Trizbi Güvenlik Bildirimi)
TR-25-0486 (Verisay İletişim ve Bilgi Teknoloji – Trizbi Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0485 (Verisay İletişim ve Bilgi Teknoloji – Titarus Güvenlik Bildirimi)
TR-25-0485 (Verisay İletişim ve Bilgi Teknoloji – Titarus Güvenlik Bildirimi) Go to usom.gov
-
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking everyday tools, trusted apps, and even AI assistants. What used to feel like clear-cut “hacker…
-
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets as recently as late 2025, according to new findings from TRM Labs. The blockchain…
-
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability Fortinet on Wednesday said it observed “recent abuse” of a five-year-old security flaw in FortiOS SSL VPN in the wild under certain configurations. The vulnerability in question is CVE-2020-12812 (CVSS score: 5.2), an improper authentication vulnerability in SSL VPN in FortiOS that could…
-
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network video recorders (NVRs) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2023-52163 (CVSS score: 8.8), relates to a case…
-
Evasive Panda APT: Malware Delivery via AitM and DNS Poisoning
Evasive Panda APT: Malware Delivery via AitM and DNS Poisoning Evasive Panda, a sophisticated threat actor known by the aliases Bronze Highland, Daggerfly, and StormBamboo, has escalated its offensive capabilities through a two-year campaign… Go to gbhackers.com
-
Microsoft Enhances BitLocker with Hardware Acceleration Support
Microsoft Enhances BitLocker with Hardware Acceleration Support Microsoft has officially announced a major upgrade to its encryption technology with the introduction of hardware-accelerated BitLocker. Revealed by Microsoft’s Rafal Sosnowski following the… Go to gbhackers.com
-
NVIDIA Isaac Vulnerabilities Enable Remote Code Execution Attacks
NVIDIA Isaac Vulnerabilities Enable Remote Code Execution Attacks NVIDIA released critical security updates for its Isaac Launchable platform on December 23, 2025, addressing three severe vulnerabilities that could allow unauthenticated attackers to… Go to gbhackers.com
-
Israeli Organizations Targeted by AV-Themed Malicious Word and PDF Files
Israeli Organizations Targeted by AV-Themed Malicious Word and PDF Files SEQRITE Labs’ Advanced Persistent Threat (APT) Team has uncovered a sophisticated campaign targeting Israeli organizations through weaponized Microsoft Word and PDF documents disguised as… Go to gbhackers.com
-
M-Files Vulnerability Allows Attackers to Steal Active User Session Tokens
M-Files Vulnerability Allows Attackers to Steal Active User Session Tokens A critical security vulnerability in M-Files Server could allow authenticated attackers to capture active user session tokens via the M-Files Web interface, enabling identity… Go to gbhackers.com
-
OpenAI is reportedly testing Claude-like Skills for ChatGPT
OpenAI is reportedly testing Claude-like Skills for ChatGPT OpenAI is testing a new ChatGPT feature called “Skills,” which will be similar to Claude’s feature, also called Skills. […] Mayank Parmar Go to bleepingcomputer
-
Fake MAS Windows activation domain used to spread PowerShell malware
Fake MAS Windows activation domain used to spread PowerShell malware A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the ‘Cosmali Loader’. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to let admins block external users via Defender portal
Microsoft Teams to let admins block external users via Defender portal Microsoft announced that security administrators will soon be able to block external users from sending messages, calls, or meeting invitations to members of their organization via Teams. […] Sergiu Gatlan Go to bleepingcomputer
-
MongoDB warns admins to patch severe RCE flaw immediately
MongoDB warns admins to patch severe RCE flaw immediately MongoDB has warned IT admins to immediately patch a high-severity vulnerability that can be exploited in remote code execution (RCE) attacks targeting vulnerable servers. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI seizes domain storing bank credentials stolen from U.S. victims
FBI seizes domain storing bank credentials stolen from U.S. victims The U.S. government has seized the ‘web3adspanels.org’ domain and the associated database used by cybercriminals to host bank login credentials stolen in account takeover attacks. […] Bill Toulas Go to bleepingcomputer
-
Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls
Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls Cybercriminals are actively abusing a long-patched Fortinet FortiGate flaw from July 2020, slipping past two-factor authentication (2FA) on firewalls and potentially granting unauthorized access to VPNs and admin consoles. Fortinet’s PSIRT team detailed the in-the-wild attacks in a recent blog post, urging admins to audit…
-
Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security
Microsoft Unveils Hardware-Accelerated BitLocker to Enhance Performance and Security Microsoft has announced hardware-accelerated BitLocker, a significant security enhancement designed to eliminate performance bottlenecks caused by encryption on modern high-speed NVMe drives. The new technology addresses growing concerns about CPU overhead as storage devices become faster, particularly for users running intensive workloads such as gaming and…
-
Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware
Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware The Evasive Panda APT group, also known as Bronze Highland, Daggerfly, and StormBamboo, has been running targeted campaigns since November 2022, using advanced techniques to deliver the MgBot malware. The group employs adversary-in-the-middle attacks combined with DNS poisoning to compromise specific victims across…
-
Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations
Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations Security researchers at Seqrite Labs have identified a campaign called Operation IconCat, targeting Israeli organizations with weaponized documents designed to look like legitimate security tools. The attacks began in November 2025 and have compromised multiple companies across information technology, staffing services, and…
-
Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass
Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass A malicious actor known as AlphaGhoul has begun promoting a tool called NtKiller, designed to silently shut down antivirus software and endpoint detection tools. The tool was posted on an underground forum where criminals gather to buy and sell hacking services.…
-
TR-25-0484 (GNU Barcode Güvenlik Bildirimi)
TR-25-0484 (GNU Barcode Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0483 (V-SOL Güvenlik Bildirimi)
TR-25-0483 (V-SOL Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0482 (Rifatron Güvenlik Bildirimi)
TR-25-0482 (Rifatron Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0481 (Devolo Güvenlik Bildirimi)
TR-25-0481 (Devolo Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0480 (Eko Çağrı Merkezi Hizmetleri – Specto CM Güvenlik Bildirimi)
TR-25-0480 (Eko Çağrı Merkezi Hizmetleri – Specto CM Güvenlik Bildirimi) Go to usom.gov
-
New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper
New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper Cybersecurity researchers have discovered a new variant of a macOS information stealer called MacSync that’s delivered by means of a digitally signed, notarized Swift application masquerading as a messaging app installer to bypass Apple’s Gatekeeper checks. “Unlike earlier MacSync Stealer variants that primarily rely…
-
Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media
Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media The fraudulent investment scheme known as Nomani has witnessed an increase by 62%, according to data from ESET, as campaigns distributing the threat have also expanded beyond Facebook to include other social media platforms, such as YouTube. The Slovak cybersecurity company said it…
-
Attacks are Evolving: 3 Ways to Protect Your Business in 2026
Attacks are Evolving: 3 Ways to Protect Your Business in 2026 Every year, cybercriminals find new ways to steal money and data from businesses. Breaching a business network, extracting sensitive data, and selling it on the dark web has become a reliable payday. But in 2025, the data breaches that affected small and medium-sized businesses…
-
SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips
SEC Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips The U.S. Securities and Exchange Commission (SEC) has filed charges against multiple companies for their alleged involvement in an elaborate cryptocurrency scam that swindled more than $14 million from retail investors. The complaint charged crypto asset trading platforms Morocoin Tech Corp., Berge…
-
Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition
Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition Apple has been fined €98.6 million ($116 million) by Italy’s antitrust authority after finding that the company’s App Tracking Transparency (ATT) privacy framework restricted App Store competition. The Italian Competition Authority (Autorità Garante della Concorrenza e del Mercato, or AGCM) said the company’s…
-
Urban VPN Proxy Surreptitiously Intercepts AI Chats
Urban VPN Proxy Surreptitiously Intercepts AI Chats This is pretty scary: Urban VPN Proxy targets conversations across ten AI platforms: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI), Meta AI. For each platform, the extension includes a dedicated “executor” script designed to intercept and capture conversations. The harvesting is enabled by default through hardcoded…
-
Operation PCPcat Exploits Next.js and React, Impacting 59,000+ Servers
Operation PCPcat Exploits Next.js and React, Impacting 59,000+ Servers A sophisticated credential-stealing campaign named “Operation PCPcat” has compromised over 59,000 Next.js servers worldwide, exploiting critical vulnerabilities in the popular React framework to harvest… Go to gbhackers.com
-
WebRAT Malware Campaign Leveraging GitHub-Hosted Proof-of-Concept Code
WebRAT Malware Campaign Leveraging GitHub-Hosted Proof-of-Concept Code Cybersecurity specialists from the Solar 4RAYS cyberthreat research center, a division of the Solar Group, have uncovered a dangerous new malware strain dubbed “Webrat.”… Go to gbhackers.com
-
Critical MongoDB Flaw Leaks Sensitive Data Through zlib Compression
Critical MongoDB Flaw Leaks Sensitive Data Through zlib Compression MongoDB has disclosed a critical security vulnerability tracked as CVE-2025-14847 that could allow attackers to extract uninitialized heap memory from database servers without authentication…. Go to gbhackers.com
-
INTERPOL Dismantles Six Ransomware Operations, Detains 500+ Individuals
INTERPOL Dismantles Six Ransomware Operations, Detains 500+ Individuals Law enforcement agencies across 19 countries have made a significant breakthrough in combating cybercrime, arresting 574 suspects and recovering approximately USD 3 million during… Go to gbhackers.com
-
HardBit 4.0 Ransomware Abuses Unsecured RDP and SMB for Access Persistence
HardBit 4.0 Ransomware Abuses Unsecured RDP and SMB for Access Persistence HardBit ransomware continues its evolution with the release of version 4.0, introducing sophisticated mechanisms to establish persistence through vulnerable network services. The latest variant… Go to gbhackers.com
-
WebRAT malware spread via fake vulnerability exploits on GitHub
WebRAT malware spread via fake vulnerability exploits on GitHub The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. […] Bill Toulas Go to bleepingcomputer
-
Malicious extensions in Chrome Web store steal user credentials
Malicious extensions in Chrome Web store steal user credentials Two Chrome extensions in the Web Store named ‘Phantom Shuttle’ are posing as plugins for a proxy service to hijack user traffic and steal sensitive data. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams strengthens messaging security by default in January
Microsoft Teams strengthens messaging security by default in January Microsoft Teams will automatically enable messaging safety features by default in January to strengthen defenses against content tagged as malicious. […] Sergiu Gatlan Go to bleepingcomputer
-
Cyberattack knocks offline France’s postal, banking services
Cyberattack knocks offline France’s postal, banking services The French national postal service’s online services were knocked offline by “a major network incident” on Monday, disrupting digital banking and other services for millions. […] Sergiu Gatlan Go to bleepingcomputer
-
Italy fines Apple $116 million over App Store privacy policy issues
Italy fines Apple $116 million over App Store privacy policy issues Italy’s competition authority (AGCM) has fined Apple €98.6 million ($116 million) for using the App Tracking Transparency (ATT) privacy framework to abuse its dominant market position in mobile app advertising. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression
Critical MongoDB Vulnerability Exposes Sensitive Data via Zlib Compression A critical security vulnerability, tracked as CVE-2025-14847, that could allow attackers to extract uninitialized heap memory from database servers without authentication. The flaw resides in MongoDB’s zlib compression implementation and affects multiple versions of the database platform. The vulnerability enables client-side exploitation of the MongoDB Server’s zlib…
-
One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware
One Year Of Zero-Click Exploits: What 2025 Taught Us About Modern Malware The year 2025 represents a pivotal moment in cybersecurity, showcasing a remarkable evolution in zero-click exploitation techniques that significantly challenges our understanding of digital security. Unlike traditional attacks that require user interaction, such on clicking a malicious link or downloading an infected file,…