no alarms and no surprises please..
-
Targeted Phishing Attack Strikes HubSpot Users
Targeted Phishing Attack Strikes HubSpot Users Evalian’s Security Operations Centre has uncovered an active, sophisticated phishing campaign targeting HubSpot customers, combining business email compromise (BEC) tactics with website compromise to… Go to gbhackers.com
-
FTC: Instacart to refund $60M over deceptive subscription tactics
FTC: Instacart to refund $60M over deceptive subscription tactics Grocery delivery service Instacart will refund $60 million to settle FTC claims that it misled customers with false advertising and unlawfully enrolled them in paid subscriptions. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 OOB update released to fix Message Queuing (MSMQ) issues
Windows 10 OOB update released to fix Message Queuing (MSMQ) issues This month’s extended security update for Windows 11 broke Message Queuing (MSMQ), which is typically used by enterprises to manage background tasks. […] Mayank Parmar Go to bleepingcomputer
-
University of Sydney suffers data breach exposing student and staff info
University of Sydney suffers data breach exposing student and staff info Hackers gained access to an online coding repository belonging to the University of Sydney and stole files with personal information of staff and students. […] Bill Toulas Go to bleepingcomputer
-
Clop ransomware targets Gladinet CentreStack in data theft attacks
Clop ransomware targets Gladinet CentreStack in data theft attacks The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign. […] Sergiu Gatlan Go to bleepingcomputer
-
New password spraying attacks target Cisco, PAN VPN gateways
New password spraying attacks target Cisco, PAN VPN gateways An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN. […] Bill Toulas Go to bleepingcomputer
-
WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls
WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices. The vulnerability, tracked as CVE-2025-14733, carries a critical severity score…
-
Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data
Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data The Clop ransomware group has launched a new data extortion campaign targeting Internet-facing Gladinet CentreStack file servers, marking another chapter in the threat actor’s pattern of exploiting file transfer solutions. The campaign appears to leverage multiple security weaknesses in CentreStack and its sister product Triofox,…
-
University of Sydney Hacked – Students and Staff Data Exposed
University of Sydney Hacked – Students and Staff Data Exposed The University of Sydney has confirmed a significant data breach affecting thousands of current and former staff members, as well as students and alums. In a message to the university community, Vice-President (Operations) Nicole Gower revealed that suspicious activity was detected in an online IT…
-
China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware
China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has unveiled a new China-aligned threat actor dubbed LongNosedGoblin. Active since at least September 2023, this advanced persistent threat (APT) group distinguishes itself by leveraging a diverse toolset of custom C#/.NET malware families.…
-
Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays
Amazon Catches North Korean IT Worker by Tracking Tiny 110ms Keystroke Delays A slight delay in keystrokes from a supposed U.S.-based IT worker alerted Amazon to a North Korean infiltrator accessing a corporate laptop. The commands should have zipped from the worker’s machine to Amazon’s Seattle headquarters in under 100 milliseconds. Instead, they trickled in…
-
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions Go to eset
-
TR-25-0468 (Microsoft Çoklu Ürün Güvenlik Bildirimi)
TR-25-0468 (Microsoft Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0467 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0467 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0466 (Utarit Bilişim – SoliClub Güvenlik Bildirimi)
TR-25-0466 (Utarit Bilişim – SoliClub Güvenlik Bildirimi) Go to usom.gov
-
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware A previously undocumented China-aligned threat cluster dubbed LongNosedGoblin has been attributed to a series of cyber attacks targeting governmental entities in Southeast Asia and Japan. The end goal of these attacks is cyber espionage, Slovak cybersecurity company ESET said in a report published today.…
-
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in OneView Software that, if successfully exploited, could result in remote code execution. The critical vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS score of 10.0. HPE OneView is an IT infrastructure management…
-
ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories
ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting…
-
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft Threat actors with ties to the Democratic People’s Republic of Korea (DPRK or North Korea) have been instrumental in driving a surge in global cryptocurrency theft in 2025, accounting for at least $2.02 billion out of more than $3.4 billion stolen from January…
-
The Case for Dynamic AI-SaaS Security as Copilots Scale
The Case for Dynamic AI-SaaS Security as Copilots Scale Within the past year, artificial intelligence copilots and agents have quietly permeated the SaaS applications businesses use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow now come with built-in AI assistants or agent-like features. Virtually every major SaaS vendor has rushed to embed…
-
I am not a robot: ClickFix used to deploy StealC and Qilin
I am not a robot: ClickFix used to deploy StealC and Qilin Go to sophos
-
ISC Stormcast For Friday, December 19th, 2025 https://isc.sans.edu/podcastdetail/9746, (Fri, Dec 19th)
ISC Stormcast For Friday, December 19th, 2025 https://isc.sans.edu/podcastdetail/9746, (Fri, Dec 19th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Positive trends related to public IP ranges from the year 2025, (Thu, Dec 18th)
Positive trends related to public IP ranges from the year 2025, (Thu, Dec 18th) Since the end of the year is quickly approaching, it is undoubtedly a good time to look back at what the past twelve months have brought to us… And given that the entire cyber security profession is about protecting various systems…
-
SonicWall Edge Access Devices Hit by Zero-Day Attacks
SonicWall Edge Access Devices Hit by Zero-Day Attacks In the latest attacks against the vendor’s SMA1000 devices, threat actors have chained a new zero-day flaw with a critical vulnerability disclosed earlier this year. Rob Wright Go to gbhackers.com
-
Dormant Iran APT is Still Alive, Spying on Dissidents
Dormant Iran APT is Still Alive, Spying on Dissidents “Prince of Persia” has rewritten the rules of persistence with advanced operational security and cryptographic communication with its command-and-control server. Nate Nelson, Contributing Writer Go to gbhackers.com
-
GachiLoader Deploys Payloads Using Obfuscated Node.js Malware
GachiLoader Deploys Payloads Using Obfuscated Node.js Malware Check Point Research has uncovered a sophisticated malware distribution campaign leveraging the YouTube Ghost Network to deploy GachiLoader, a novel, heavily obfuscated Node.js-based loader… Go to gbhackers.com
-
Best Security Awareness Training Platforms For 2026
Best Security Awareness Training Platforms For 2026 Security awareness training platforms empower organizations to combat rising cyber threats by educating employees on phishing, ransomware, and social engineering in 2026. These top… Go to gbhackers.com
-
Actively Exploited ASUS Vulnerability Added to CISA’s KEV List
Actively Exploited ASUS Vulnerability Added to CISA’s KEV List The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical ASUS vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in… Go to gbhackers.com
-
New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit
New Reports Reveal WAFs Are Ineffective Against Latest React2Shell Exploit TEL AVIV, Israel, Dec. 17, 2025 Miggo Security has released a comprehensive benchmark study revealing critical gaps in Web Application Firewall (WAF) protection, with the… Go to gbhackers.com
-
Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges
Hackers Actively Exploit SonicWall SMA1000 Zero-Day to Escalate Privileges SonicWall has issued an urgent security advisory warning of active exploitation of a local privilege escalation vulnerability affecting its SMA1000 appliances. The flaw, tracked… Go to gbhackers.com
-
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
Zeroday Cloud hacking event awards $320,0000 for 11 zero days The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure. […] Bill Toulas Go to bleepingcomputer
-
France arrests suspect tied to cyberattack on Interior Ministry
France arrests suspect tied to cyberattack on Interior Ministry French authorities arrested a 22-year-old suspect on Tuesday for a cyberattack that targeted France’s Ministry of the Interior earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts Amazon’s AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Access Management (IAM). […] Bill Toulas Go to bleepingcomputer
-
WhatsApp device linking abused in account hijacking attacks
WhatsApp device linking abused in account hijacking attacks Threat actors are abusing the legitimate device-linking feature to hijack WhatsApp accounts via pairing codes in a campaign dubbed GhostPairing. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
Cisco warns of unpatched AsyncOS zero-day exploited in attacks Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. […] Sergiu Gatlan Go to bleepingcomputer
-
Let’s Encrypt Unveils New “Generation Y” Root and 45-Day Certificates
Let’s Encrypt Unveils New “Generation Y” Root and 45-Day Certificates Let’s Encrypt, the nonprofit certificate authority powering free TLS/SSL certificates for millions of websites, announced sweeping updates to its issuance policies. The changes introduce a new “Generation Y” root hierarchy, deprecate TLS client authentication, and progressively shorten certificate lifetimes to align with CA/Browser Forum requirements.…
-
Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide
Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide A massive botnet targeting Android devices has emerged as one of the most significant threats in the cybersecurity landscape today. Named Kimwolf, this sophisticated malware has compromised approximately 1.8 million Android devices worldwide, including smart TVs, set-top boxes, tablets, and other Android-based systems. Security researchers discovered…
-
Security Measures at NOWPayments: What Businesses Need to Know
Security Measures at NOWPayments: What Businesses Need to Know When businesses start accepting crypto payments, security is often one of the first concerns. This is completely understandable. Crypto works differently from traditional payments, and many people want to know how their funds and transactions are protected. NOWPayments approaches security in a practical and transparent way.…
-
NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments
NAKIVO v11.1 Introduces Stronger Protection for Virtual Environments Enterprise-Grade Disaster Recovery and MSP Capabilities Now Available NAKIVO, a leading provider of data protection solutions, has released NAKIVO Backup & Replication v11.1, marking a significant leap forward in protecting virtual environments and empowering managed service providers (MSPs). After completing the closed beta testing phase, v11.1 has been…
-
Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands
Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands An active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, targeting Secure Email Gateway (formerly Email Security Appliance, ESA) and Secure Email and Web Manager (formerly Content Security Management Appliance, SMA). The attack, spotted since late November 2025 and publicly disclosed on…
-
ESET Threat Report H2 2025
ESET Threat Report H2 2025 A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts Go to eset
-
TR-25-0465 (Cisco Güvenlik Bildirimi)
TR-25-0465 (Cisco Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0464 (GG Soft Yazılım – PaperWork Güvenlik Bildirimi)
TR-25-0464 (GG Soft Yazılım – PaperWork Güvenlik Bildirimi) Go to usom.gov
-
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), has been described as an…
-
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances Cisco has alerted users to a maximum-severity zero-day flaw in Cisco AsyncOS software that has been actively exploited by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686 in attacks targeting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.…
-
SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances
SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances SonicWall has rolled out fixes to address a security flaw in Secure Mobile Access (SMA) 100 series appliances that it said has been actively exploited in the wild. The vulnerability, tracked as CVE-2025-40602 (CVSS score: 6.6), concerns a case of local privilege escalation that arises as…
-
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks
Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks A new distributed denial-of-service (DDoS) botnet known as Kimwolf has enlisted a massive army of no less than 1.8 million infected devices comprising Android-based TVs, set-top boxes, and tablets, and may be associated with another botnet known as AISURU, according to findings from QiAnXin…
-
APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign
APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign The Russian state-sponsored threat actor known as APT28 has been attributed to what has been described as a “sustained” credential-harvesting campaign targeting users of UKR[.]net, a webmail and news service popular in Ukraine. The activity, observed by Recorded Future’s Insikt Group between June 2024 and…
-
Deliberate Internet Shutdowns
Deliberate Internet Shutdowns For two days in September, Afghanistan had no internet. No satellite failed; no cable was cut. This was a deliberate outage, mandated by the Taliban government. It followed a more localized shutdown two weeks prior, reportedly instituted “to prevent immoral activities.” No additional explanation was given. The timing couldn’t have been worse:…
-
ISC Stormcast For Thursday, December 18th, 2025 https://isc.sans.edu/podcastdetail/9744, (Thu, Dec 18th)
ISC Stormcast For Thursday, December 18th, 2025 https://isc.sans.edu/podcastdetail/9744, (Thu, Dec 18th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Maybe a Little Bit More Interesting React2Shell Exploit, (Wed, Dec 17th)
Maybe a Little Bit More Interesting React2Shell Exploit, (Wed, Dec 17th) I have already talked about various React2Shell exploit attempts we have observed in the last weeks. But new varieties of the exploit are popping up, and the most recent one is using this particular version of the exploit: POST /app HTTP/1.1 Host: 81.187.66.58 Content-Type:…
-
Smashing Security podcast #448: The Kindle that got pwned
Smashing Security podcast #448: The Kindle that got pwned Think your Kindle is harmless? Think again! In this episode, we unpack a Black Hat Europe talk revealing how a boobytrapped audiobook could exploit the Amazon eBook reader – potentially letting an attacker break into your account and seize control of your credit card. Plus a…
-
Surveillance at sea: Cruise firm bans smart glasses to curb covert recording
Surveillance at sea: Cruise firm bans smart glasses to curb covert recording If you’re planning a cruise for your holidays, and cannot bear the idea of being parted from your Ray-Ban Meta smart glasses, you may want to avoid sailing with MSC Cruises. The cruise line has updated its list of prohibited items, specifically banning…
-
The AI Fix #81: ChatGPT is the last AI you’ll understand, and your teacher is a deepfake
The AI Fix #81: ChatGPT is the last AI you’ll understand, and your teacher is a deepfake In episode 81 of The AI Fix, Graham discovers that deepfakes are already marking your kids’ homework, while Mark glimpses the future when he discovers AI agents that can communicate by reading each other’s minds. Also in this…
-
Man jailed for teaching criminals how to use malware
Man jailed for teaching criminals how to use malware A 49-year-old man has received a five-and-a-half year jail sentence after admitting to creating detailed video tutorials that showed members of a criminal gang how to infect Android phones with spyware and drain their bank accounts. Read more in my article on the Hot for Security…
-
Critical Fortinet Flaws Under Active Attack
Critical Fortinet Flaws Under Active Attack Attackers targeted admin accounts, and once authenticated, exported device configurations including hashed credentials and other sensitive information. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
In Cybersecurity, Claude Leaves Other LLMs in the Dust
In Cybersecurity, Claude Leaves Other LLMs in the Dust Anthropic proves that LLMs can be fairly resistant to abuse. Most developers are either incapable of building safer tools, or unwilling to invest in doing so. Nate Nelson, Contributing Writer Go to gbhackers.com
-
‘Cellik’ Android RAT Leverages Google Play Store
‘Cellik’ Android RAT Leverages Google Play Store The remote access Trojan lets an attacker remotely control a victim’s phone and can generate malicious apps from inside the Play Store. Alexander Culafi Go to gbhackers.com
-
Attackers Use Stolen AWS Credentials in Cryptomining Campaign
Attackers Use Stolen AWS Credentials in Cryptomining Campaign Threat actors wielding stolen AWS Identity and Access Management (IAM) credentials leverage Amazon EC and EC2 infrastructure across multiple customer environments. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
GhostPoster Attack Uses PNG Icons to Compromise 50,000 Firefox Users
GhostPoster Attack Uses PNG Icons to Compromise 50,000 Firefox Users A sophisticated malware campaign dubbed “GhostPoster” has compromised approximately 50,000 Firefox users by exploiting browser extension icons. Security researchers at Koi Security discovered that… Go to gbhackers.com
-
Parked Domains Emerge as a Primary Channel for Malware and Phishing
Parked Domains Emerge as a Primary Channel for Malware and Phishing The landscape of domain parking has transformed dramatically over the past decade, shifting from a relatively benign monetization strategy to a sophisticated vector for… Go to gbhackers.com
-
ClickFix Spoof of “Word Online” Used to Spread DarkGate Malware
ClickFix Spoof of “Word Online” Used to Spread DarkGate Malware A sophisticated social engineering campaign leveraging a fake “Word Online” extension error message has been discovered distributing the notorious DarkGate malware. This attack employs… Go to gbhackers.com
-
New Moonwalk++ PoC Demonstrates How Malware Can Forge Windows Call Stacks to Evade Detection
New Moonwalk++ PoC Demonstrates How Malware Can Forge Windows Call Stacks to Evade Detection Security researchers have unveiled a dangerous new technique that allows malware to completely hide its tracks by faking Windows call stacks a method designed… Go to gbhackers.com
-
Cellik Android Malware Uses One-Click APK Builder to Hide in Play Store Apps
Cellik Android Malware Uses One-Click APK Builder to Hide in Play Store Apps A newly discovered Android Remote Access Trojan (RAT) called Cellik is democratizing sophisticated mobile surveillance attacks by bundling advanced spyware capabilities with an automated… Go to gbhackers.com
-
Cellik Android malware builds malicious versions from Google Play apps
Cellik Android malware builds malicious versions from Google Play apps A new Android malware-as-a-service (MaaS) named Cellik is being advertised on underground cybercrime forums offering a robust set of capabilities that include the option to embed it in any app available on the Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
GhostPoster attacks hide malicious JavaScript in Firefox addon logos
GhostPoster attacks hide malicious JavaScript in Firefox addon logos A new campaign dubbed ‘GhostPoster’ is hiding JavaScript code in the image logo of malicious Firefox extensions counting more than 50,000 downloads, to monitor browser activity and plant a backdoor. […] Bill Toulas Go to bleepingcomputer
-
Amazon disrupts Russian GRU hackers attacking edge network devices
Amazon disrupts Russian GRU hackers attacking edge network devices The Amazon Threat Intelligence team has disrupted active operations attributed to hackers working for the Russian foreign military intelligence agency, the GRU, who targeted customers’ cloud infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Texas sues TV makers for taking screenshots of what people watch
Texas sues TV makers for taking screenshots of what people watch The Texas Attorney General sued five major television manufacturers, accusing them of illegally collecting their users’ data by secretly recording what they watch using Automated Content Recognition (ACR) technology. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit newly patched Fortinet auth bypass flaws
Hackers exploit newly patched Fortinet auth bypass flaws Hackers are exploiting critical-severity vulnerabilities affecting multiple Fortinet products to get unauthorized access to admin accounts and steal system configuration files. […] Bill Toulas Go to bleepingcomputer
-
New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users
New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users A sophisticated new malware campaign dubbed “GhostPoster” has been uncovered, leveraging a clever steganography technique to compromise approximately 50,000 Firefox users. The attack vector primarily involves seemingly innocent browser extensions, such as “Free VPN Forever,” which conceal malicious payloads within their own interface icons.…
-
Chrome Security Update – Patch for Critical Vulnerabilities that Enables Remote Code Execution
Chrome Security Update – Patch for Critical Vulnerabilities that Enables Remote Code Execution Google has released Chrome version 143.0.7499.146/.147 to address critical security vulnerabilities that could enable remote code execution on affected systems. The update is now rolling out to Windows and Mac users, with Linux receiving version 143.0.7499.146. Full deployment is expected over the…
-
BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls
BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls In a sophisticated cyberespionage campaign, the BlindEagle threat actor has once again targeted Colombian government institutions. This latest operation specifically zeroed in on an agency under the Ministry of Commerce, Industry, and Tourism, leveraging a highly effective strategy to bypass standard email security…
-
APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators
APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators A significant discovery in threat intelligence reveals that APT-C-35, commonly known as DoNot, continues to maintain an active infrastructure footprint across the internet. Security researchers have identified new infrastructure clusters linked to this India-based threat group, which has long been recognized as a state-sponsored actor with…
-
Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure
Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025. The campaign, linked to Russia’s Main Intelligence Directorate (GRU) and the notorious Sandworm group, represents a major shift in tactics. Instead of focusing…
-
TR-25-0463 (Proliz Yazılım – Öğrenci İşleri Bilgi Sistemi Güvenlik Bildirimi)
TR-25-0463 (Proliz Yazılım – Öğrenci İşleri Bilgi Sistemi Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0462 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0462 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0461 (NVIDIA Güvenlik Zafiyeti)
TR-25-0461 (NVIDIA Güvenlik Zafiyeti) Go to usom.gov
-
TR-25-0460 (HPE Güvenlik Bildirimi)
TR-25-0460 (HPE Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0459 (RedHat OpenShift Güvenlik Bildirimi)
TR-25-0459 (RedHat OpenShift Güvenlik Bildirimi) Go to usom.gov
-
Afripol Focuses on Regional Cyber Challenges, Deepening Cooperation
Afripol Focuses on Regional Cyber Challenges, Deepening Cooperation Rapid digitization, uneven cybersecurity know-how, and growing cybercriminal syndicates in the region have challenged law enforcement and prosecutors. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining. The activity, first detected by Amazon’s GuardDuty managed threat detection service and its automated security monitoring systems on November 2, 2025,…
-
Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer. The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by…
-
Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure
Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure Amazon’s threat intelligence team has disclosed details of a “years-long” Russian state-sponsored campaign that targeted Western critical infrastructure between 2021 and 2025. Targets of the campaign included energy sector organizations across Western nations, critical infrastructure providers in North America and Europe, and entities with…
-
Why Data Security and Privacy Need to Start in Code
Why Data Security and Privacy Need to Start in Code AI-assisted coding and AI app generation platforms have created an unprecedented surge in software development. Companies are now facing rapid growth in both the number of applications and the pace of change within those applications. Security and privacy teams are under significant pressure as the…
-
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass Threat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public disclosure. Cybersecurity company Arctic Wolf said it observed active intrusions involving malicious single sign-on (SSO) logins on FortiGate appliances on December 12, 2025. The…
-
Chinese Surveillance and AI
Chinese Surveillance and AI New report: “The Party’s AI: How China’s New AI Systems are Reshaping Human Rights.” From a summary article: China is already the world’s largest exporter of AI powered surveillance technology; new surveillance technologies and platforms developed in China are also not likely to simply stay there. By exposing the full scope…
-
ISC Stormcast For Wednesday, December 17th, 2025 https://isc.sans.edu/podcastdetail/9742, (Wed, Dec 17th)
ISC Stormcast For Wednesday, December 17th, 2025 https://isc.sans.edu/podcastdetail/9742, (Wed, Dec 17th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Weekly Update 482
Weekly Update 482 Perhaps it’s just the time of year where we all start to wind down a bit, or maybe I’m just tired after another massive 12 months, but this week’s vid is way late. Ok, going away to the place that had just been breached (ironic!) didn’t help, but I think in general…
-
Venezuelan Oil Company Downplays Alleged US Cyberattack
Venezuelan Oil Company Downplays Alleged US Cyberattack But media reports described the attack as causing major disruption to PDVSA, the state-owned oil and natural gas company. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Russia Hits Critical Orgs Via Misconfigured Edge Devices
Russia Hits Critical Orgs Via Misconfigured Edge Devices Amazon detailed a long-running campaign by Russia against critical infrastructure organizations, particularly in the energy sector. Alexander Culafi Go to gbhackers.com
-
Browser Extension Harvests 8M Users’ AI Chatbot Data
Browser Extension Harvests 8M Users’ AI Chatbot Data Urban VPN Proxy, which claims to protect users’ privacy, collects data from conversations with ChatGPT, Claude, Gemini, Copilot and other AI assistants. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Enterprises Gear Up for 2026’s IT Transformation
Enterprises Gear Up for 2026’s IT Transformation Experts predict big changes are coming for IT infrastructure in 2026 driven by AI adoption, hybrid cloud strategies, and evolving security demands. Arielle Waldman Go to gbhackers.com
-
Shannon: AI Pentesting Tool That Autonomously Identifies and Exploits Code Vulnerabilities
Shannon: AI Pentesting Tool That Autonomously Identifies and Exploits Code Vulnerabilities Keygraph has unveiled Shannon, a fully autonomous artificial intelligence pentester designed to discover and execute real exploits in web applications. Unlike conventional vulnerability scanners that… Go to gbhackers.com
-
Frogblight Android Malware Spoofs Government Sites to Collect SMS and Device Details
Frogblight Android Malware Spoofs Government Sites to Collect SMS and Device Details Kaspersky security researchers have uncovered a sophisticated Android banking Trojan called Frogblight that targets Turkish users by impersonating legitimate government applications. First detected in… Go to gbhackers.com
-
Android Users at Risk as Malware Poses as mParivahan and e-Challan Apps
Android Users at Risk as Malware Poses as mParivahan and e-Challan Apps A sophisticated Android malware campaign dubbed NexusRoute is actively targeting Indian users by impersonating the Indian Government Ministry, mParivahan, and e-Challan services to steal… Go to gbhackers.com
-
ClickFix Attack Abuses finger.exe to Execute Malicious Code
ClickFix Attack Abuses finger.exe to Execute Malicious Code Cybersecurity researchers have identified a resurgence in the abuse of legacy Windows protocols, specifically the finger.exe command, to facilitate social engineering attacks. Since November… Go to gbhackers.com
-
SoundCloud confirms breach after member data stolen, VPN access disrupted
SoundCloud confirms breach after member data stolen, VPN access disrupted Audio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database exposing users’ email addresses and profile information. […] Lawrence Abrams Go to bleepingcomputer
-
Google is shutting down its dark web report feature in January
Google is shutting down its dark web report feature in January Google is discontinuing its “dark web report” security tool, stating that it wants to focus on other tools it believes are more helpful. […] Mayank Parmar Go to bleepingcomputer