no alarms and no surprises please..
-
TR-25-0448 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0448 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0447 (Netiket Bilgi Teknolojileri – ApplyLogic – Başvuru Otomasyonu Güvenlik Bildirimi)
TR-25-0447 (Netiket Bilgi Teknolojileri – ApplyLogic – Başvuru Otomasyonu Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0446 (Aksis Bilgisayar Hizmetleri – AxOnboard Güvenlik Bildirimi)
TR-25-0446 (Aksis Bilgisayar Hizmetleri – AxOnboard Güvenlik Bildirimi) Go to usom.gov
-
Hamas-Linked Hackers Probe Middle Eastern Diplomats
Hamas-Linked Hackers Probe Middle Eastern Diplomats Hamas’s best hackers have been maturing, building better malware, and spreading their attacks more widely across the region. Nate Nelson, Contributing Writer Go to gbhackers.com
-
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild. The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an…
-
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More Stories
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More Stories This week’s cyber stories show how fast the online world can turn risky. Hackers are sneaking malware into movie downloads, browser add-ons, and even software updates people trust. Tech giants and governments are racing to plug new holes while arguing…
-
NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems
NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems Cybersecurity researchers have disclosed details of a new fully-featured Windows backdoor called NANOREMOTE that uses the Google Drive API for command-and-control (C2) purposes. According to a report from Elastic Security Labs, the malware shares code similarities with another implant codenamed FINALDRAFT (aka Squidoor)…
-
The Impact of Robotic Process Automation (RPA) on Identity and Access Management
The Impact of Robotic Process Automation (RPA) on Identity and Access Management As enterprises refine their strategies for handling Non-Human Identities (NHIs), Robotic Process Automation (RPA) has become a powerful tool for streamlining operations and enhancing security. However, since RPA bots have varying levels of access to sensitive information, enterprises must be prepared to mitigate…
-
WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor
WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor An advanced persistent threat (APT) known as WIRTE has been attributed to attacks targeting government and diplomatic entities across the Middle East with a previously undocumented malware suite dubbed AshTag since 2020. Palo Alto Networks Unit 42 is tracking the activity cluster under the name…
-
A big finish to 2025 in December’s Patch Tuesday
A big finish to 2025 in December’s Patch Tuesday A month with no Critical-severity Windows bugs is overshadowed by a mass of Mariner mop-up Angela Gunn Go to sophos
-
React2Shell flaw (CVE-2025-55182) exploited for remote code execution
React2Shell flaw (CVE-2025-55182) exploited for remote code execution The availability of exploit code will likely lead to more widespread opportunistic attacks Mindi McDowell Go to sophos
-
GOLD SALEM tradecraft for deploying Warlock ransomware
GOLD SALEM tradecraft for deploying Warlock ransomware Analysis of the tradecraft evolution across 6 months and 11 incidents Mindi McDowell Go to sophos
-
AIs Exploiting Smart Contracts
AIs Exploiting Smart Contracts I have long maintained that smart contracts are a dumb idea: that a human process is actually a security feature. Here’s some interesting research on training AIs to automatically exploit smart contracts: AI models are increasingly good at cyber tasks, as we’ve written about before. But what is the economic impact…
-
ISC Stormcast For Friday, December 12th, 2025 https://isc.sans.edu/podcastdetail/9736, (Fri, Dec 12th)
ISC Stormcast For Friday, December 12th, 2025 https://isc.sans.edu/podcastdetail/9736, (Fri, Dec 12th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Attackers Exploited Gogs Zero-Day Flaw for Months
Attackers Exploited Gogs Zero-Day Flaw for Months Wiz disclosed a still-unpatched vulnerability in self-hosted Git service Gogs, which is a bypass for a previous RCE bug disclosed last year. Alexander Culafi Go to gbhackers.com
-
AI in OT Sparks Cascade of Complex Challenges
AI in OT Sparks Cascade of Complex Challenges Using artificial intelligence in operational technology environments could be a bumpy ride full of trust issues and security challenges. Arielle Waldman Go to gbhackers.com
-
Security Alert: 19 Fake PNG Extensions Found in VS Code Marketplace
Security Alert: 19 Fake PNG Extensions Found in VS Code Marketplace ReversingLabs (RL) researchers have identified a sophisticated supply chain campaign involving 19 malicious Visual Studio Code (VS Code) extensions. The campaign, which has been… Go to gbhackers.com
-
New “Spiderman” Phishing Kit Lets Hackers Build Fake Bank Login Pages Instantly
New “Spiderman” Phishing Kit Lets Hackers Build Fake Bank Login Pages Instantly A sophisticated phishing toolkit dubbed “Spiderman” has emerged as a significant threat to European banking customers, enabling cybercriminals to create convincing fake login pages… Go to gbhackers.com
-
644K+ Websites at Risk Due to Critical React Server Components Flaw
644K+ Websites at Risk Due to Critical React Server Components Flaw The Shadowserver Foundation has issued an urgent update regarding the critical “React2Shell” vulnerability, identifying a massive attack surface that remains exposed to potential exploitation…. Go to gbhackers.com
-
Parrot 7.0 Beta Introduces Debian 13 and a Fully Redesigned Desktop
Parrot 7.0 Beta Introduces Debian 13 and a Fully Redesigned Desktop Parrot Security OS has unveiled its highly anticipated 7.0 beta release, marking a significant milestone with the integration of Debian 13 and a complete… Go to gbhackers.com
-
Threat Actors Exploit ChatGPT and Grok Conversations to Deliver AMOS Stealer
Threat Actors Exploit ChatGPT and Grok Conversations to Deliver AMOS Stealer The cybersecurity landscape has reached a troubling inflection point. On December 5, 2025, Huntress identified a sophisticated campaign deploying the Atomic macOS Stealer (AMOS)… Go to gbhackers.com
-
Google fixes eighth Chrome zero-day exploited in attacks in 2025
Google fixes eighth Chrome zero-day exploited in attacks in 2025 Google has released emergency updates to fix another Chrome zero-day vulnerability exploited in the wild, marking the eighth such security flaw patched since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware A new AMOS infostealer campaign is abusing Google search ads to lure users into Grok and ChatGPT conversations that appear to offer “helpful” instructions but ultimately lead to installing the AMOS info-stealing malware on macOS. […] Bill Toulas Go to bleepingcomputer
-
New DroidLock malware locks Android devices and demands a ransom
New DroidLock malware locks Android devices and demands a ransom A new Android malware called DroidLock has emerged with capabilities to lock screens for ransom payments, erase data, access text messages, call logs, contacts, and audio data. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to warn of suspicious traffic with external domains
Microsoft Teams to warn of suspicious traffic with external domains Microsoft is working on a new Teams security feature that will analyze suspicious traffic with external domains to help IT administrators tackle potential security threats. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 10,000 Docker Hub images found leaking credentials, auth keys
Over 10,000 Docker Hub images found leaking credentials, auth keys More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys. […] Bill Toulas Go to bleepingcomputer
-
Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer
Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer A new AMOS InfoStealer campaign is abusing trust in ChatGPT to infect Mac devices under the guise of simple troubleshooting help. Victims search for a fix to a sound problem, click a sponsored ChatGPT result, and are shown what looks like a normal chat…
-
Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File
Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File Security researchers have uncovered a significant threat targeting developers through the VS Code Marketplace. A coordinated campaign involving 19 malicious extensions has been actively infiltrating the platform, with the attack remaining undetected since February 2025. These deceptive extensions carry hidden malware in…
-
Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data
Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory on affected systems. The vulnerability, tracked as CVE-2025-62468, was assigned an Important severity rating and released on December 9, 2025. The flaw stems from an…
-
Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security
Adobe Acrobat Reader Vulnerabilities Let Attackers Execute Arbitrary Code and Bypass Security Critical security updates for Acrobat and Reader are available, addressing multiple vulnerabilities that could allow attackers to execute arbitrary code and bypass essential security features. Adobe issued security bulletin APSB25-119 on December 9, 2025, with a priority rating of 3, affecting both Windows and macOS…
-
Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild
Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild Google has released an urgent security update for the Chrome browser to address a high-severity zero-day vulnerability that is currently being exploited in the wild. This emergency patch is part of the latest Stable channel update, bringing the version to 143.0.7499.109/.110 for Windows and…
-
The big catch: How whaling attacks target top executives
The big catch: How whaling attacks target top executives Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe. Go to eset
-
TR-25-0445 (D Link Güvenlik Bildirimi)
TR-25-0445 (D Link Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0444 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0444 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0443 (Adobe Experience Manager Güvenlik Bildirimi )
TR-25-0443 (Adobe Experience Manager Güvenlik Bildirimi ) Go to usom.gov
-
TR-25-0442 (İm Park Bilişim Elektronik – DijiDemi Güvenlik Bildirimi)
TR-25-0442 (İm Park Bilişim Elektronik – DijiDemi Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0441 (TAC Bilişim Hizmetleri – GoldenHorn Güvenlik Bildirimi)
TR-25-0441 (TAC Bilişim Hizmetleri – GoldenHorn Güvenlik Bildirimi) Go to usom.gov
-
Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution
Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution Huntress is warning of a new actively exploited vulnerability in Gladinet’s CentreStack and Triofox products stemming from the use of hard-coded cryptographic keys that have affected nine organizations so far. “Threat actors can potentially abuse this as a way to access the web.config…
-
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors React2Shell continues to witness heavy exploitation, with threat actors leveraging the maximum-severity security flaw in React Server Components (RSC) to deliver cryptocurrency miners and an array of previously undocumented malware families, according to new findings from Huntress. This includes a Linux backdoor called PeerBlight,…
-
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL New research has uncovered exploitation primitives in the .NET Framework that could be leveraged against enterprise-grade applications to achieve remote code execution. WatchTowr Labs, which has codenamed the “invalid cast vulnerability” SOAPwn, said the issue impacts Barracuda Service Center RMM,…
-
Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling
Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling Three security vulnerabilities have been disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol specification that could expose a local attacker to serious risks. The flaws impact PCIe Base Specification Revision 5.0 and onwards in the protocol mechanism…
-
Webinar: How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes
Webinar: How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes Cloud security is changing. Attackers are no longer just breaking down the door; they are finding unlocked windows in your configurations, your identities, and your code. Standard security tools often miss these threats because they look like normal activity. To stop them, you…
-
Sophos achieves its best-ever results in the MITRE ATT&CK Enterprise 2025 Evaluation
Sophos achieves its best-ever results in the MITRE ATT&CK Enterprise 2025 Evaluation A major milestone: Sophos XDR delivers 100% detection coverage in the latest ATT&CK Evaluation. rajansanhotra Go to sophos
-
FBI Warns of Fake Video Scams
FBI Warns of Fake Video Scams The FBI is warning of AI-assisted fake kidnapping scams: Criminal actors typically will contact their victims through text message claiming they have kidnapped their loved one and demand a ransom be paid for their release. Oftentimes, the criminal actor will express significant claims of violence towards the loved one…
-
Using AI Gemma 3 Locally with a Single CPU , (Wed, Dec 10th)
Using AI Gemma 3 Locally with a Single CPU , (Wed, Dec 10th) Several months ago, I got a Nucbox K8 Plus minicomputer to use as a Proxmox 9 server. At the time of this acquisition, I didn’t realize this minicomputer had an artificial intelligence (AI) engine [1] build in the CPU that could be…
-
ISC Stormcast For Thursday, December 11th, 2025 https://isc.sans.edu/podcastdetail/9734, (Thu, Dec 11th)
ISC Stormcast For Thursday, December 11th, 2025 https://isc.sans.edu/podcastdetail/9734, (Thu, Dec 11th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection), (Wed, Dec 10th)
Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection), (Wed, Dec 10th) Last year, Kubernetes fixed a command injection vulnerability in the Kubernetes NodeLogQuery feature (%%cve:2024-9042%%) [1]. To exploit the vulnerability, several conditions had to be met: The vulnerable node had to run Windows The attacker had to have permissions to read logs The NogeLogQuery…
-
Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report
Ransomware may have extorted over $2.1 billion between 2022-2024, but it’s not all bad news, claims FinCEN report A new report from the United States’s Financial Crimes Enforcement Network (FinCEN) has shone a revealing light on the state of the criminal industry of ransomware. The report, which examines ransomware incidents from 2022 to 2024, reveals…
-
Four years later, Irish health service offers €750 to victims of ransomware attack
Four years later, Irish health service offers €750 to victims of ransomware attack Remember when a notorious ransomware gang hit the Irish Health Service back in May 2021? Four years on, and it seems victims who had their data exposed will finally receive compensation. Read more in my article on the Hot for Security blog.…
-
Storm-0249 Abuses EDR Processes in Stealthy Attacks
Storm-0249 Abuses EDR Processes in Stealthy Attacks The initial access broker has been weaponizing endpoint detection and response (EDR) platforms and Windows utilities in recent high-precision attacks. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Copilot’s No-Code AI Agents Liable to Leak Company Data
Copilot’s No-Code AI Agents Liable to Leak Company Data Microsoft puts the power of AI in the hands of everyday non-technical Joes. It’s a nice idea, and a surefire recipe for security issues. Nate Nelson, Contributing Writer Go to gbhackers.com
-
ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery
ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery A new twist on the social engineering tactic is making waves, combining SEO poisoning and legitimate AI domains to install malware on victims’ computers. Alexander Culafi Go to gbhackers.com
-
Feds: Pro-Russia Hactivists Target US Critical Infrastructure
Feds: Pro-Russia Hactivists Target US Critical Infrastructure So far the attacks, which compromise virtual network computing (VNC) connections in OT systems, have not been particularly destructive, but this could change as they evolve. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Akira Group Targets Hyper-V and VMware ESXi with Ransomware Exploiting Vulnerabilities
Akira Group Targets Hyper-V and VMware ESXi with Ransomware Exploiting Vulnerabilities Hypervisors the invisible backbone of modern corporate IT have become the new primary battleground for ransomware groups. According to new data from Huntress, attacks… Go to gbhackers.com
-
New Vishing Attack Exploits Microsoft Teams and QuickAssist to Deploy .NET Malware
New Vishing Attack Exploits Microsoft Teams and QuickAssist to Deploy .NET Malware A sophisticated vishing campaign has emerged that combines social engineering with legitimate Microsoft tools to establish command execution chains leading to multi-stage .NET malware… Go to gbhackers.com
-
Malicious VS Code on Microsoft Registry Steals WiFi Passwords and Captures Screens
Malicious VS Code on Microsoft Registry Steals WiFi Passwords and Captures Screens Security researchers at Koi Security have uncovered a sophisticated malware campaign targeting developers through the Visual Studio Code Marketplace. The attack uses two seemingly… Go to gbhackers.com
-
SAP Security Patch Day Fixes Critical Flaws in Solution Manager, NetWeaver & More
SAP Security Patch Day Fixes Critical Flaws in Solution Manager, NetWeaver & More SAP has released its December 2025 Security Patch Day updates, addressing 14 new security notes that fix multiple critical and high‑severity vulnerabilities across key… Go to gbhackers.com
-
AI-Driven Tools Uncover GhostPenguin Backdoor Attacking Linux Servers
AI-Driven Tools Uncover GhostPenguin Backdoor Attacking Linux Servers A sophisticated Linux backdoor named GhostPenguin has been discovered by Trend Micro Research, evading detection for over four months after its initial submission to… Go to gbhackers.com
-
SAP fixes three critical vulnerabilities across multiple products
SAP fixes three critical vulnerabilities across multiple products SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws. […] Bill Toulas Go to bleepingcomputer
-
Windows PowerShell now warns when running Invoke-WebRequest scripts
Windows PowerShell now warns when running Invoke-WebRequest scripts Microsoft says Windows PowerShell now warns when running scripts that use the Invoke-WebRequest cmdlet to download web content, aiming to prevent potentially risky code from executing. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5071546 extended security update
Microsoft releases Windows 10 KB5071546 extended security update Microsoft has released the KB5071546 extended security update to resolve 57 security vulnerabilities, including three zero-day flaws. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws Microsoft’s December 2025 Patch Tuesday fixes 57 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Fortinet warns of critical FortiCloud SSO login auth bypass flaws
Fortinet warns of critical FortiCloud SSO login auth bypass flaws Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code
Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code Security update addressing a dangerous Windows PowerShell vulnerability that allows attackers to execute malicious code on affected systems. The vulnerability, tracked as CVE-2025-54100, was publicly disclosed on December 9, 2025, and represents a significant security risk for organizations worldwide. The flaw stems from improper neutralization of…
-
CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks
CISA Warns of WinRAR 0-Day RCE Vulnerability Exploited in Attacks A high-priority warning regarding a critical security flaw in WinRAR, the popular file compression tool used by millions of Windows users. The vulnerability, tracked as CVE-2025-6218, is currently being exploited by attackers to compromise systems and execute malicious code. The specific flaw is known as a…
-
Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs
Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs A critical zero-click vulnerability dubbed “GeminiJack” in Google Gemini Enterprise and previously Vertex AI Search that let attackers steal sensitive corporate data from Gmail, Calendar, and Docs with minimal effort. According to Noma Labs, it was considered an architectural flaw rather than merely a bug.…
-
Microsoft 365 Services Disruption in Australia: Users Face Access Issues in Accessing Services
Microsoft 365 Services Disruption in Australia: Users Face Access Issues in Accessing Services Users across Australia are currently grappling with significant disruptions to critical business tools as Microsoft 365 services experience a widespread outage. The incident, which began on the morning of December 10, 2025, is preventing a large number of enterprise and individual users…
-
Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild
Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that is currently being exploited in the wild. Assigned the identifier CVE-2025-62221, this elevation of privilege flaw affects a wide range of Windows…
-
TR-25-0436 (Ivanti Güvenlik Bildirimi)
TR-25-0436 (Ivanti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0435 (Talentsoft Yazılım – UNIS Güvenlik Bildirimi)
TR-25-0435 (Talentsoft Yazılım – UNIS Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0434 (Talentsoft Yazılım – e-BAP Otomasyonu Güvenlik Bildirimi)
TR-25-0434 (Talentsoft Yazılım – e-BAP Otomasyonu Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0433 (Panilux Güvenlik Bildirimi)
TR-25-0433 (Panilux Güvenlik Bildirimi) Go to usom.gov
-
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could result in an authentication bypass and code execution. The Fortinet vulnerabilities affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and relate to a case of…
-
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical security React2Shell flaw in React Server Components (RSC) to deliver a previously undocumented remote access trojan dubbed EtherRAT. “EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution,…
-
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure Four distinct threat activity clusters have been observed leveraging a malware loader known as CastleLoader, strengthening the previous assessment that the tool is offered to other threat actors under a malware-as-a-service (MaaS) model. The threat actor behind CastleLoader has been assigned the name…
-
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading The threat actor known as Storm-0249 is likely shifting from its role as an initial access broker to adopt a combination of more advanced tactics like domain spoofing, DLL side-loading, and fileless PowerShell execution to facilitate ransomware attacks. “These methods allow them to bypass…
-
How to Streamline Zero Trust Using the Shared Signals Framework
How to Streamline Zero Trust Using the Shared Signals Framework Zero Trust helps organizations shrink their attack surface and respond to threats faster, but many still struggle to implement it because their security tools don’t share signals reliably. 88% of organizations admit they’ve suffered significant challenges in trying to implement such approaches, according to Accenture.…
-
AI vs. Human Drivers
AI vs. Human Drivers Two competing arguments are making the rounds. The first is by a neurosurgeon in the New York Times. In an op-ed that honestly sounds like it was paid for by Waymo, the author calls driverless cars a “public health breakthrough”: In medical research, there’s a practice of ending a study early…
-
ISC Stormcast For Wednesday, December 10th, 2025 https://isc.sans.edu/podcastdetail/9732, (Wed, Dec 10th)
ISC Stormcast For Wednesday, December 10th, 2025 https://isc.sans.edu/podcastdetail/9732, (Wed, Dec 10th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Microsoft Patch Tuesday December 2025, (Tue, Dec 9th)
Microsoft Patch Tuesday December 2025, (Tue, Dec 9th) This release addresses 57 vulnerabilities. 3 of these vulnerabilities are rated critical. One vulnerability was already exploited, and two were publicly disclosed before the patch was released. CVE-2025-62221: This privilege escalation vulnerability in the Microsoft Cloud Files Mini Filters driver is already being exploited. CVE-2025-54100: A PowerShell…
-
The AI Fix #80: DeepSeek’s cheap GPT-5 rival, Antigravity fails, and your LLM likes it when you’re rude
The AI Fix #80: DeepSeek’s cheap GPT-5 rival, Antigravity fails, and your LLM likes it when you’re rude In episode 80 of The AI Fix, your hosts look at DeepSeek 3.2 “Speciale”, the bargain-basement model that claims GPT-5-level brains at 10% of the price, Jensen Huang’s reassuring vision of a robot fashion industry, and a…
-
Privacy concerns raised as Grok AI found to be a stalker’s best friend
Privacy concerns raised as Grok AI found to be a stalker’s best friend Grok, the AI chatbot developed by Elon Musk’s xAI, has been found to exhibit more alarming behaviour – this time revealing the home addresses of ordinary people upon request. Read more in my article on the Hot for Security blog. Graham Cluley…
-
Japanese Firms Suffer Long Tail of Ransomware Damage
Japanese Firms Suffer Long Tail of Ransomware Damage Ransomware actors have targeted manufacturers, retailers, and the Japanese government, with many organizations requiring months to recover. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday
Microsoft Fixes Exploited Zero Day in Light Patch Tuesday Proof-of-concept exploit code is publicly available for two other flaws in this month’s Patch Tuesday. In total, the company issued patches for more than 1,150 flaws this year. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Packer-as-a-Service Shanya Hides Ransomware, Kills EDR
Packer-as-a-Service Shanya Hides Ransomware, Kills EDR Shanya is the latest in an emerging field of packing malware, selling obfuscation functionality in order to help ransomware actors reach their target. Alexander Culafi Go to gbhackers.com
-
Analysts Warn of Cybersecurity Risks in Humanoid Robots
Analysts Warn of Cybersecurity Risks in Humanoid Robots Think “Blade Runner,” but the robots can be hacked more easily than your home computer. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Gemini Enterprise No-Click Flaw Exposes Sensitive Data
Gemini Enterprise No-Click Flaw Exposes Sensitive Data Google has fixed a critical vulnerability that enabled attackers to add malicious instructions to common documents to exfiltrate sensitive corporate information. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Exposing the Core Functionalities of QuasarRAT: Encrypted Configuration and Obfuscation Techniques
Exposing the Core Functionalities of QuasarRAT: Encrypted Configuration and Obfuscation Techniques In the second installment of the “Advent of Configuration Extraction” series, security researchers have unwrapped QuasarRAT, a widely-deployed .NET remote access trojan (RAT), revealing… Go to gbhackers.com
-
NVIDIA and Lakera AI Propose Unified Framework for Agent Safety
NVIDIA and Lakera AI Propose Unified Framework for Agent Safety NVIDIA and Lakera AI have introduced a groundbreaking unified security and safety framework designed to address the emerging challenges posed by autonomous AI agents… Go to gbhackers.com
-
Apple, Google, and Samsung May Soon Activate Always-On GPS in India
Apple, Google, and Samsung May Soon Activate Always-On GPS in India India’s government is considering a controversial proposal that could require smartphone manufacturers to enable satellite location tracking on all devices permanently. The plan has… Go to gbhackers.com
-
Hackers Exploit Multiple Ad Networks to Distribute Triada Malware to Android Users
Hackers Exploit Multiple Ad Networks to Distribute Triada Malware to Android Users Adex, the anti-fraud and traffic-quality platform operating under AdTech Holding, has successfully identified and neutralized a sophisticated, multi-year malware operation linked to the infamous… Go to gbhackers.com
-
US Contributes to 44% of Cyber Attacks; Public Administration Targeted for Financial Gains
US Contributes to 44% of Cyber Attacks; Public Administration Targeted for Financial Gains Global cybercrime is accelerating toward a projected cost of 15.63 trillion dollars by 2029, up from an estimated 10.5 trillion dollars today, as criminals… Go to gbhackers.com
-
Ransomware gangs turn to Shanya EXE packer to hide EDR killers
Ransomware gangs turn to Shanya EXE packer to hide EDR killers Several ransomware groups have been spotted using a packer-as-a-service (PaaS) platform named Shanya to assist in EDR (endpoint detection and response) killing operations. […] Bill Toulas Go to bleepingcomputer
-
Malicious VSCode extensions on Microsoft’s registry drop infostealers
Malicious VSCode extensions on Microsoft’s registry drop infostealers Two malicious extensions on Microsoft’s Visual Studio Code Marketplace infect developers’ machines with information-stealing malware that can take screenshots, steal credentials, and hijack browser sessions. […] Bill Toulas Go to bleepingcomputer
-
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024 A new report by the Financial Crimes Enforcement Network (FinCEN) shows that ransomware activity peaked in 2023 before falling in 2024, following a series of law enforcement actions targeting the ALPHV/BlackCat and LockBit ransomware gangs. […] Lawrence Abrams Go to bleepingcomputer
-
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment The police in Poland arrested three Ukrainian nationals for allegedly attempting to damage IT systems in the country using hacking equipment and for obtaining “computer data of particular importance to national defense.” […] Bill Toulas Go to bleepingcomputer
-
Google Chrome adds new security layer for Gemini AI agentic browsing
Google Chrome adds new security layer for Gemini AI agentic browsing Google Chrome is introducing a new security architecture designed to protect upcoming agentic AI browsing features powered by Gemini. […] Bill Toulas Go to bleepingcomputer