no alarms and no surprises please..
-
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users A new malware campaign has surfaced that uses GitHub repositories to spread the WebRAT malware by disguising it as proof-of-concept exploits and gaming utilities. The malware targets users searching for game cheats, pirated software, and application patches, particularly for popular titles like Rust,…
-
Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised
Ransomware Attack on Romanian Waters Authority – 1,000+ IT Systems Compromised Romania’s National Administration “Apele Române” (Romanian Waters) disclosed a severe ransomware attack on December 20, 2025. That compromised approximately 1,000 IT systems across the agency and 10 of its 11 regional water basin administrations. The incident affected critical infrastructure responsible for managing the country’s…
-
Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects
Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects Law enforcement agencies across 19 African nations have achieved a landmark victory against cybercrime. Arresting 574 suspects and dismantling six ransomware variants during Operation Sentinel, a month-long coordinated crackdown that concluded on November 27. The operation, which ran from October 27 to November 27, targeted…
-
A brush with online fraud: What are brushing scams and how do I stay safe?
A brush with online fraud: What are brushing scams and how do I stay safe? Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow. Go to eset
-
Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component
Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation Go to eset
-
TR-25-0479 (Tenda Güvenlik Bildirimi)
TR-25-0479 (Tenda Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0478 (NVIDIA Güvenlik Zafiyeti)
TR-25-0478 (NVIDIA Güvenlik Zafiyeti) Go to usom.gov
-
TR-25-0477 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0477 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0476 (Hotech Yazılım – Otello Güvenlik Bildirimi)
TR-25-0476 (Hotech Yazılım – Otello Güvenlik Bildirimi) Go to usom.gov
-
Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites
Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites Cybersecurity researchers have discovered two malicious Google Chrome extensions with the same name and published by the same developer that come with capabilities to intercept traffic and capture user credentials. The extensions are advertised as a “multi-location network speed test plug-in” for developers and…
-
INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty
INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty A law enforcement operation coordinated by INTERPOL has led to the recovery of $3 million and the arrest of 574 suspects by authorities from 19 countries, amidst a continued crackdown on cybercrime networks in Africa. The coordinated effort, named Operation Sentinel, took place between October…
-
Passwd: A walkthrough of the Google Workspace Password Manager
Passwd: A walkthrough of the Google Workspace Password Manager Passwd is designed specifically for organizations operating within Google Workspace. Rather than competing as a general consumer password manager, its purpose is narrow, and business-focused: secure credential storage, controlled sharing, and seamless Workspace integration. The platform emphasizes practicality over feature overload, aiming to provide a reliable…
-
U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme
U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme The U.S. Justice Department (DoJ) on Monday announced the seizure of a web domain and database that it said was used to further a criminal scheme designed to target and defraud Americans by means of bank account takeover fraud. The domain in question,…
-
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances A critical security vulnerability has been disclosed in the n8n workflow automation platform that, if successfully exploited, could result in arbitrary code execution under certain circumstances. The vulnerability, tracked as CVE-2025-68613, carries a CVSS score of 9.9 out of a maximum of…
-
Denmark Accuses Russia of Conducting Two Cyberattacks
Denmark Accuses Russia of Conducting Two Cyberattacks News: The Danish Defence Intelligence Service (DDIS) announced on Thursday that Moscow was behind a cyber-attack on a Danish water utility in 2024 and a series of distributed denial-of-service (DDoS) attacks on Danish websites in the lead-up to the municipal and regional council elections in November. The first,…
-
The AI Fix #82: Santa Claus doesn’t exist (according to AI)
The AI Fix #82: Santa Claus doesn’t exist (according to AI) Is Santa Claus real? This Christmas special of The AI Fix podcast sets out to answer that question in the most sensible way possible: by consulting chatbots, Google’s festive killjoys, and the laws of relativistic physics. Your hosts unwrap a festive grab-bag of AI…
-
167: Threatlocker
167: Threatlocker A manufacturer gets hit with ransomware. A hospital too. Learn how Threatlocker stops these types of attacks. This episode is brought to you by Threatlocker. Sponsors This episode is sponsored by ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™,…
-
Industry Continues to Push Back on HIPAA Security Rule Overhaul
Industry Continues to Push Back on HIPAA Security Rule Overhaul Healthcare cyberattacks are on the rise, but industry organizations say the proposed changes to the security rules fall short of what’s needed. Arielle Waldman Go to gbhackers.com
-
ServiceNow Buys Armis for $7.75B, Gets ‘AI Control Tower’
ServiceNow Buys Armis for $7.75B, Gets ‘AI Control Tower’ The latest cybersecurity acquisition will help further ServiceNow’s plans for autonomous cybersecurity and building a security stack to proactively manage AI. Go to gbhackers.com
-
Amazon Fends Off 1,800 Suspected DPRK IT Job Scammers
Amazon Fends Off 1,800 Suspected DPRK IT Job Scammers The tech giant has been beset by a deluge of state-sponsored North Korean operatives, showcasing the sheer scale of the IT worker scam problem. Alexander Culafi Go to gbhackers.com
-
Nissan Discloses Data Breach Linked to Compromised Red Hat Infrastructure
Nissan Discloses Data Breach Linked to Compromised Red Hat Infrastructure Nissan Motor Co., Ltd. has disclosed a significant data breach affecting approximately 21,000 customers of Nissan Fukuoka Sales Co., Ltd. following unauthorized access to… Go to gbhackers.com
-
Blind Eagle Hackers Target Government Agencies Using PowerShell Scripts
Blind Eagle Hackers Target Government Agencies Using PowerShell Scripts Colombian government institutions are facing a sophisticated multi-stage cyberattack campaign orchestrated by the BlindEagle threat group, which leveraged compromised internal email accounts, PowerShell scripts,… Go to gbhackers.com
-
SideWinder APT Launches Cyberattacks on Indian Entities Posing as the Income Tax Department
SideWinder APT Launches Cyberattacks on Indian Entities Posing as the Income Tax Department Zscaler Threat Hunting has identified a sophisticated espionage campaign targeting Indian entities through fraudulent “Income Tax Department” portals, representing a significant evolution in the… Go to gbhackers.com
-
Microsoft Brokering File System Vulnerability Enables Local Privilege Escalation
Microsoft Brokering File System Vulnerability Enables Local Privilege Escalation Microsoft has addressed a critical use-after-free vulnerability in its Brokering File System (BFS) driver that could allow attackers to escalate privileges on Windows systems…. Go to gbhackers.com
-
PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel POSIX CPU Timers
PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel POSIX CPU Timers A critical race condition vulnerability in the Linux kernel’s POSIX CPU timers has been exposed through a detailed proof-of-concept, one of the most sophisticated… Go to gbhackers.com
-
Baker University says 2024 data breach impacts 53,000 people
Baker University says 2024 data breach impacts 53,000 people Baker University has disclosed a data breach after attackers gained access to its network one year ago and stole the personal, health, and financial information of over 53,000 individuals. […] Sergiu Gatlan Go to bleepingcomputer
-
Nissan says thousands of customers exposed in Red Hat breach
Nissan says thousands of customers exposed in Red Hat breach Nissan Motor Co. Ltd. (Nissan) has confirmed that information of thousands of its customers has been compromised after the data breach at Red Hat in September. […] Bill Toulas Go to bleepingcomputer
-
New MacSync malware dropper evades macOS Gatekeeper checks
New MacSync malware dropper evades macOS Gatekeeper checks The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application. […] Bill Toulas Go to bleepingcomputer
-
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
Interpol-led action decrypts 6 ransomware strains, arrests hundreds An Interpol-coordinated initiative called Operation Sentinel led to the arrest of 574 individuals and the recovery of $3 million linked to business email compromise, extortion, and ransomware incidents. […] Bill Toulas Go to bleepingcomputer
-
Malicious npm package steals WhatsApp accounts and messages
Malicious npm package steals WhatsApp accounts and messages A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal WhatsApp messages, collect contacts, and gain access to the account. […] Bill Toulas Go to bleepingcomputer
-
Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials
Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Two fake Chrome extensions named “Phantom Shuttle” are deceiving thousands of users by posing as legitimate VPN services while secretly intercepting their web traffic and stealing sensitive login information. These malicious extensions, active since 2017, have been distributed to over 2,180 users through the…
-
Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan
Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan Researchers at Ontinue’s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat actors repurpose benign software to gain complete control over compromised systems while evading traditional security…
-
CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation
CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation A critical vulnerability affecting Digiever DS-2105 Pro network video recorders was added to the Known Exploited Vulnerabilities (KEV) catalog on December 22, 2025, following evidence of active exploitation in the wild. CVE-2023-52163 is a missing authorization vulnerability in Digiever DS-2105 Pro devices. That enables…
-
Hackers Using ClickFix Technique to Hide Images within the Image Files
Hackers Using ClickFix Technique to Hide Images within the Image Files Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, discovered by Huntress analysts, represents a significant shift in how cybercriminals deliver information-stealing malware…
-
Spotify Music Library With 86M Music Files Scraped by Hacktivist Group
Spotify Music Library With 86M Music Files Scraped by Hacktivist Group The shadow library known as Anna’s Archive has executed a massive scrape of Spotify, releasing a torrent collection containing approximately 86 million audio tracks and metadata for 256 million songs. The group, which typically focuses on archiving academic papers and books, claims this unauthorized…
-
TR-25-0475 (SOUND4 Çoklu Ürün Güvenlik Zafiyeti)
TR-25-0475 (SOUND4 Çoklu Ürün Güvenlik Zafiyeti) Go to usom.gov
-
TR-25-0474 (NetBT Danışmanlık Hizmetleri – e-Fatura Güvenlik Bildirimi)
TR-25-0474 (NetBT Danışmanlık Hizmetleri – e-Fatura Güvenlik Bildirimi) Go to usom.gov
-
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens Cybersecurity researchers have disclosed details of a new malicious package on the npm repository that works as a fully functional WhatsApp API, but also contains the ability to intercept every message and link the attacker’s device to a victim’s WhatsApp account. The package,…
-
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More
⚡ Weekly Recap: Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More Cyber threats last week showed how attackers no longer need big hacks to cause big damage. They’re going after the everyday tools we trust most — firewalls, browser add-ons, and even smart TVs — turning small cracks into serious…
-
How to Browse the Web More Sustainably With a Green Browser
How to Browse the Web More Sustainably With a Green Browser As the internet becomes an essential part of daily life, its environmental footprint continues to grow. Data centers, constant connectivity, and resource-heavy browsing habits all contribute to energy consumption and digital waste. While individual users may not see this impact directly, the collective effect…
-
Microsoft Is Finally Killing RC4
Microsoft Is Finally Killing RC4 After twenty-six years, Microsoft is finally upgrading the last remaining instance of the encryption algorithm RC4 in Windows. of the most visible holdouts in supporting RC4 has been Microsoft. Eventually, Microsoft upgraded Active Directory to support the much more secure AES encryption standard. But by default, Windows servers have continued…
-
Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices With attacks on the critical firewall vulnerability, WatchGuard joins a list of edge device vendors that have been targeted in recent weeks. Rob Wright Go to gbhackers.com
-
Uzbek Users Under Attack by Android SMS Stealers
Uzbek Users Under Attack by Android SMS Stealers Telegram users in Uzbekistan are being targeted with Android SMS stealer malware, and what’s worse, the attackers are improving their methods. Alexander Culafi Go to gbhackers.com
-
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
Ukrainian hacker admits affiliate role in Nefilim ransomware gang A Ukrainian national pleaded guilty on Friday to conducting Nefilim ransomware attacks that targeted high-revenue businesses across the United States and other countries. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
Critical RCE flaw impacts over 115,000 WatchGuard firewalls Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Docker Hardened Images now open source and available for free
Docker Hardened Images now open source and available for free More than a 1,000 Docker Hardened Images (DHI) are now freely available and open source for software builders, under the Apache 2.0 license. […] Bill Toulas Go to bleepingcomputer
-
Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data
Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data Cyber criminals are changing their tactics by recruiting insiders within organizations instead of relying on traditional attack methods like brute force or social engineering. Recent findings show that employees in banks, telecom companies, and technology firms are…
-
DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks
DIG AI – Darknet AI Tool Enabling Threat Actors to Launch Sophisticated Attacks A new and ominous player has emerged in the rapidly expanding landscape of “Shadow AI.” Researchers at Resecurity have identified DIG AI, an uncensored artificial intelligence tool hosted on the darknet that is empowering threat actors to automate cyberattacks, generate illicit content,…
-
U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware
U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware The U.S. Department of Justice (DOJ) has charged 54 individuals in a sweeping crackdown on a transnational cyber-physical attack network. The indictments, announced by U.S. Attorney Lesley A. Woods, allege a massive conspiracy involving “ATM jackpotting” to fund Tren de Aragua…
-
Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more
Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped usernames, emails, and encrypted passwords from over 1.2 million accounts, underscoring the…
-
TR-25-0473 (Nagios Güvenlik Bildirim)
TR-25-0473 (Nagios Güvenlik Bildirim) Go to usom.gov
-
TR-25-0472 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0472 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0471 (Tenda Güvenlik Bildirimi)
TR-25-0471 (Tenda Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0470 (Totolink T10 Güvenlik Bildirimi)
TR-25-0470 (Totolink T10 Güvenlik Bildirimi) Go to usom.gov
-
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale Threat actors have been observed leveraging malicious dropper apps masquerading as legitimate applications to deliver an Android SMS stealer dubbed Wonderland in mobile attacks targeting users in Uzbekistan. “Previously, users received ‘pure’ Trojan APKs that acted as malware immediately upon installation,” Group-IB said…
-
ISC Stormcast For Monday, December 22nd, 2025 https://isc.sans.edu/podcastdetail/9748, (Mon, Dec 22nd)
ISC Stormcast For Monday, December 22nd, 2025 https://isc.sans.edu/podcastdetail/9748, (Mon, Dec 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Bangladeshi Operator of Fake ID Marketplaces Charged in International Fraud Case
Bangladeshi Operator of Fake ID Marketplaces Charged in International Fraud Case A 29-year-old Bangladeshi man has been indicted on federal charges for operating online marketplaces that sold fraudulent identity document templates to customers worldwide, U.S…. Go to gbhackers.com
-
RansomHouse upgrades encryption with multi-layered data processing
RansomHouse upgrades encryption with multi-layered data processing The RansomHouse ransomware-as-a-service (RaaS) has recently upgraded its encryptor, switching from a relatively simple single-phase linear technique to a more complex, multi-layered method. […] Bill Toulas Go to bleepingcomputer
-
100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild
100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild Security researchers have identified at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that attackers are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-20393, currently has no available patch,…
-
Claude Opus 4.5 Now Integrated with GitHub Copilot
Claude Opus 4.5 Now Integrated with GitHub Copilot GitHub has announced the general availability of Claude Opus 4.5, Anthropic’s advanced AI model, across its Copilot platform. This integration enhances AI capabilities for developers using GitHub’s code assistance tools. The Claude Opus 4.5 model is now accessible to users with Copilot Enterprise, Copilot Business, Copilot Pro,…
-
Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra
Microsoft Rolls Out Baseline Security Mode for Office, SharePoint, Exchange, Teams, and Entra Microsoft has begun deploying Baseline Security Mode across Microsoft 365 tenants, a new dashboard in the M365 Admin Center that centralizes recommended security configurations for Office, SharePoint, Exchange, Teams, and Entra. Announced at Ignite 2025, this opt-in feature helps administrators quickly assess…
-
Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks
Cybersecurity Professionals Plead Guilty to Launching Ransomware Attacks In a shocking betrayal of industry trust, two former cybersecurity professionals have pleaded guilty to federal charges for launching ransomware attacks against U.S. businesses. The pair, whose day jobs involved helping companies respond to hacks and negotiate ransoms, admitted to moonlighting as cybercriminals in a plot to…
-
CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware
CISA Releases New Indicators of Compromise Tied to BRICKSTORM Malware The Cybersecurity and Infrastructure Security Agency (CISA), along with the National Security Agency (NSA) and Canadian Centre for Cyber Security (Cyber Centre), has released updated indicators of compromise (IOCs) and detection signatures for BRICKSTORM malware. The latest update, published on December 19, 2025, includes an…
-
Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence
Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence Threat hunters have discerned new activity associated with an Iranian threat actor known as Infy (aka Prince of Persia), nearly five years after the hacking group was observed targeting victims in Sweden, the Netherlands, and Turkey. “The scale of Prince of Persia’s activity…
-
U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware
U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware The U.S. Department of Justice (DoJ) this week announced the indictment of 54 individuals in connection with a multi-million dollar ATM jackpotting scheme. The large-scale conspiracy involved deploying malware named Ploutus to hack into automated teller machines (ATMs) across the U.S. and force them…
-
Weekly Update 483
Weekly Update 483 Building out an IoT environment is a little like the old Maslow’s Hierarchy of Needs. All the stuff on the top is only any good if all the stuff on the bottom is good, starting with power. This week, I couldn’t even get that right, but thankfully, sparky to rescue and ensuite…
-
25,000+ FortiCloud SSO-Enabled Systems Vulnerable to Remote Exploitation
25,000+ FortiCloud SSO-Enabled Systems Vulnerable to Remote Exploitation The Shadowserver Foundation has identified over 25,000 internet-facing Fortinet devices globally with FortiCloud Single Sign-On (SSO) functionality enabled, raising concerns about potential exposure to… Go to gbhackers.com
-
Microsoft Teams Outage Causes Global Messaging Delays and Service Interruptions
Microsoft Teams Outage Causes Global Messaging Delays and Service Interruptions Microsoft Teams users worldwide experienced significant service disruptions on December 20, 2025, as the collaboration platform encountered widespread issues affecting messaging functionality and other… Go to gbhackers.com
-
BlueDelta Hackers Target Users of Popular Ukrainian Webmail and News Service
BlueDelta Hackers Target Users of Popular Ukrainian Webmail and News Service Russian state-sponsored threat group BlueDelta has conducted a sustained credential-harvesting campaign targeting users of UKR.NET, one of Ukraine’s most popular webmail and news services,… Go to gbhackers.com
-
Mapping the Emerging Alliance Between Qilin, DragonForce, and LockBit
Mapping the Emerging Alliance Between Qilin, DragonForce, and LockBit In mid-September 2025, the ransomware landscape witnessed a significant development when DragonForce announced an alliance with Qilin and LockBit on a Russian underground forum…. Go to gbhackers.com
-
Cloud Atlas Exploits Office Vulnerabilities to Execute Malicious Code
Cloud Atlas Exploits Office Vulnerabilities to Execute Malicious Code The Cloud Atlas threat group, active since 2014, continues to pose a significant risk to organizations in Eastern Europe and Central Asia through sophisticated… Go to gbhackers.com
-
Microsoft confirms Teams is down and messages are delayed
Microsoft confirms Teams is down and messages are delayed Microsoft Teams is experiencing issues, with thousands reporting problems sending messages, including delays. […] Mayank Parmar Go to bleepingcomputer
-
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform The Nigerian police have arrested three individuals linked to targeted Microsoft 365 cyberattacks via Raccoon0365 phishing-as-a-service. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 accounts targeted in wave of OAuth phishing attacks
Microsoft 365 accounts targeted in wave of OAuth phishing attacks Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism. […] Bill Toulas Go to bleepingcomputer
-
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections. […] Bill Toulas Go to bleepingcomputer
-
Over 25,000 FortiCloud SSO devices exposed to remote attacks
Over 25,000 FortiCloud SSO devices exposed to remote attacks Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers Weaponize SVG Files and Office Documents to Target Windows Users
Hackers Weaponize SVG Files and Office Documents to Target Windows Users Cybersecurity researchers have uncovered a sophisticated email campaign deploying a commodity loader to distribute Remote Access Trojans and information stealers. The operation primarily targets manufacturing and government organizations across Italy, Finland, and Saudi Arabia, using highly evasive techniques. Infection chain Multi-Vector Attack Strategy The…
-
Microsoft Teams Down – Users Face Messaging Delays and Service Disruptions Worldwide
Microsoft Teams Down – Users Face Messaging Delays and Service Disruptions Worldwide In a major disruption to remote work and collaboration, Microsoft Teams experienced a significant outage on Friday, affecting thousands of users across multiple regions. Reports of messaging delays, failed message deliveries, and issues with other service functions began surging around 2:30 PM ET…
-
25,000+ FortiCloud SSO-Enabled Devices Exposed to Remote Attacks
25,000+ FortiCloud SSO-Enabled Devices Exposed to Remote Attacks Over 25,000 Fortinet devices worldwide with FortiCloud Single Sign-On (SSO) enabled, leaving them potentially exposed to remote attacks. The finding stems from enhanced device fingerprinting in a new Device Identification report, which scanned global IP addresses and flagged these systems as openly advertising their SSO configuration. FortiCloud…
-
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response
Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response Torrance, United States / California, December 19th, 2025, CyberNewsWire Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface monitoring platform developed by AI SPERA, is now officially integrated into Palo Alto Networks’ Cortex XSOAR. The integration embeds…
-
BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service
BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service A new credential-harvesting campaign has been discovered targeting users of UKR.NET, a popular Ukrainian webmail and news platform. The attacks are linked to BlueDelta, a Russian state-sponsored hacker group also known as APT28, Fancy Bear, and Forest Blizzard. This group has been running…
-
TR-25-0469 (Restajet Bilgi Teknolojileri – Online Yemek Sipariş Sistemi Güvenlik Bildirimi)
TR-25-0469 (Restajet Bilgi Teknolojileri – Online Yemek Sipariş Sistemi Güvenlik Bildirimi) Go to usom.gov
-
Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers
Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers A suspected Russia-aligned group has been attributed to a phishing campaign that employs device code authentication workflows to steal victims’ Microsoft 365 credentials and conduct account takeover attacks. The activity, ongoing since September 2025, is being tracked by Proofpoint under the moniker UNK_AcademicFlare. The…
-
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as CountLoader. The campaign “uses CountLoader as the initial tool in a multistage attack…
-
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability WatchGuard has released fixes to address a critical security flaw in Fireware OS that it said has been exploited in real-world attacks. Tracked as CVE-2025-14733 (CVSS score: 9.3), the vulnerability has been described as a case of out-of-bounds write affecting the iked process that…
-
Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks
Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks Authorities in Nigeria have announced the arrest of three “high-profile internet fraud suspects” who are alleged to have been involved in phishing attacks targeting major corporations, including the main developer behind the RaccoonO365 phishing-as-a-service (PhaaS) scheme. The Nigeria Police Force National Cybercrime Centre (NPF–NCCC) said…
-
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards
New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards Certain motherboard models from vendors like ASRock, ASUSTeK Computer, GIGABYTE, and MSI are affected by a security vulnerability that leaves them susceptible to early-boot direct memory access (DMA) attacks across architectures that implement a Unified Extensible Firmware Interface (UEFI) and input–output memory…
-
Friday Squid Blogging: Petting a Squid
Friday Squid Blogging: Petting a Squid Video from Reddit shows what could go wrong when you try to pet a—looks like a Humboldt—squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
AI Advertising Company Hacked
AI Advertising Company Hacked At least some of this is coming to light: Doublespeed, a startup backed by Andreessen Horowitz (a16z) that uses a phone farm to manage at least hundreds of AI-generated social media accounts and promote products has been hacked. The hack reveals what products the AI-generated accounts are promoting, often without the…
-
DLLs & TLS Callbacks, (Fri, Dec 19th)
DLLs & TLS Callbacks, (Fri, Dec 19th) Xavier’s diary entry “Abusing DLLs EntryPoint for the Fun” inspired me to do some tests with TLS Callbacks and DLLs. TLS stands for Thread Local Storage. TLS Callbacks are an execution mechanism in Windows PE files that lets code run automatically when a process or thread starts, before the…
-
Dismantling Defenses: Trump 2.0 Cyber Year in Review
Dismantling Defenses: Trump 2.0 Cyber Year in Review The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum of technology challenges, from cybersecurity and privacy to countering disinformation, fraud and corruption. These shifts, along with the president’s…
-
Cisco VPNs, Email Services Hit in Separate Threat Campaigns
Cisco VPNs, Email Services Hit in Separate Threat Campaigns The company suffered one sophisticated five-alarm campaign and one messy spray-and-pray attack, mere days apart. Nate Nelson, Contributing Writer Go to gbhackers.com
-
LongNosedGoblin Caught Snooping on Asian Governments
LongNosedGoblin Caught Snooping on Asian Governments New China-aligned APT group is deploying Group Policy to sniff through government networks across Southeast Asia and Japan. Becky Bracken Go to gbhackers.com
-
Identity Fraud Among Home Care Workers Puts Patients at Risk
Identity Fraud Among Home Care Workers Puts Patients at Risk Reports of patients being cared for by unqualified home-care aides with fake identities continue to emerge, highlighting a need for more stringent identity authentication. Arielle Waldman Go to gbhackers.com
-
A Cybersecurity Playbook for AI Adoption
A Cybersecurity Playbook for AI Adoption AI adds real value to cybersecurity today, but it cannot yet serve as a single security guardian. Here’s how organizations can safely combine AI-driven analysis with deterministic rules and proven security practices. Dirk Schrader Go to gbhackers.com
-
A Good Year for North Korean Cybercriminals
A Good Year for North Korean Cybercriminals North Korea shifted its strategy to patiently target “bigger fish” for larger payouts, using sophisticated methods to execute attacks at opportune times. Robert Lemos, Contributing Writer Go to gbhackers.com
-
New Kibana Vulnerabilities Allow Attackers to Embed Malicious Scripts
New Kibana Vulnerabilities Allow Attackers to Embed Malicious Scripts Elastic has released critical security updates to address a dangerous cross-site scripting (XSS) vulnerability affecting multiple versions of Kibana. The vulnerability, tracked as CVE-2025-68385,… Go to gbhackers.com
-
Scripted Sparrow Utilizes Automation to Generate and Dispatch Attack Messages
Scripted Sparrow Utilizes Automation to Generate and Dispatch Attack Messages Scripted Sparrow, a prolific Business Email Compromise (BEC) collective with members spanning three continents, has raised significant concerns among cybersecurity researchers due to the… Go to gbhackers.com
-
New Linux Kernel Rust Vulnerability Triggers System Crashes
New Linux Kernel Rust Vulnerability Triggers System Crashes A critical race condition vulnerability has been discovered in the Linux kernel’s Rust Binder module, potentially causing system crashes and memory corruption. Assigned CVE-2025-68260,… Go to gbhackers.com
-
Amazon Identified North Korean IT Worker by Tracking Keystroke Activity
Amazon Identified North Korean IT Worker by Tracking Keystroke Activity Amazon has uncovered a North Korean imposter posing as a U.S.-based systems administrator. The discovery was made not through traditional background checks but by… Go to gbhackers.com