no alarms and no surprises please..
-
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment The police in Poland arrested three Ukrainian nationals for allegedly attempting to damage IT systems in the country using hacking equipment and for obtaining “computer data of particular importance to national defense.” […] Bill Toulas Go to bleepingcomputer
-
Google Chrome adds new security layer for Gemini AI agentic browsing
Google Chrome adds new security layer for Gemini AI agentic browsing Google Chrome is introducing a new security architecture designed to protect upcoming agentic AI browsing features powered by Gemini. […] Bill Toulas Go to bleepingcomputer
-
SAP Security Patch Day: Fix for Critical Vulnerabilities in SAP Solution Manager, NetWeaver, and Other Products
SAP Security Patch Day: Fix for Critical Vulnerabilities in SAP Solution Manager, NetWeaver, and Other Products SAP released 14 new security notes on its monthly Security Patch Day on December 9, 2025, addressing vulnerabilities across key products, including SAP Solution Manager, NetWeaver, Commerce Cloud, and more. Three critical flaws with CVSS scores exceeding 9.0 demand…
-
500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online
500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online Over 565 internet-exposed Apache Tika Server instances are vulnerable to a critical XML External Entity (XXE) injection flaw. That could enable attackers to steal sensitive data, launch denial-of-service attacks, or conduct server-side request forgery operations. The vulnerability, tracked as CVE-2025-66516, affects tika-core versions…
-
Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities
Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities PortSwigger has enhanced Burp Suite’s scanning arsenal with the latest update to its ActiveScan++ extension, introducing detection for the critical React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478). This server-side request forgery (SSRF) flaw in React applications allows attackers to execute arbitrary shell commands, potentially leading to…
-
Apple, Google and Samsung May Enable Always-On GPS in India
Apple, Google and Samsung May Enable Always-On GPS in India The Indian government is currently evaluating a controversial proposal from the telecom industry that would mandate smartphone manufacturers to enable “always-on” satellite location tracking. This move has sparked significant opposition from major technology companies, including Apple, Google, and Samsung, who argue it poses serious privacy…
-
Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware
Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware A deceptive Android application lurking in the Google Play Store, disguised as a document reader and file manager, but delivering the Anatsa banking trojan to users. Cybersecurity firm Zscaler ThreatLabz found an app named “Document Reader – File Manager” by developer ISTOQMAH.…
-
TR-25-0432 (Google Android Güvenlik Bildirimi)
TR-25-0432 (Google Android Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0431 (SAP Çoklu Ürün Güvenlik Bildirimi)
TR-25-0431 (SAP Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0430 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0430 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT
Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT Cybersecurity researchers are calling attention to a new campaign dubbed JS#SMUGGLER that has been observed leveraging compromised websites as a distribution vector for a remote access trojan named NetSupport RAT. The attack chain, analyzed by Securonix, involves three main moving parts: An obfuscated JavaScript loader…
-
⚡ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More
⚡ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More It’s been a week of chaos in code and calm in headlines. A bug that broke the internet’s favorite framework, hackers chasing AI tools, fake apps stealing cash, and record-breaking cyberattacks — all within days. If you blink, you’ll miss how fast…
-
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year?
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year? The holiday season compresses risk into a short, high-stakes window. Systems run hot, teams run lean, and attackers time automated campaigns to get maximum return. Multiple industry threat reports show that bot-driven fraud, credential stuffing and account takeover attempts intensify around peak shopping…
-
Android Malware FvncBot, SeedSnatcher, and ClayRat Gain Stronger Data Theft Features
Android Malware FvncBot, SeedSnatcher, and ClayRat Gain Stronger Data Theft Features Cybersecurity researchers have disclosed details of two new Android malware families dubbed FvncBot and SeedSnatcher, as another upgraded version of ClayRat has been spotted in the wild. The findings come from Intel 471, CYFIRMA, and Zimperium, respectively. FvncBot, which masquerades as a security app…
-
Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks
Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks A critical security flaw in the Sneeit Framework plugin for WordPress is being actively exploited in the wild, per data from Wordfence. The remote code execution vulnerability in question is CVE-2025-6389 (CVSS score: 9.8), which affects all versions of the plugin…
-
Substitution Cipher Based on The Voynich Manuscript
Substitution Cipher Based on The Voynich Manuscript Here’s a fun paper: “The Naibbe cipher: a substitution cipher that encrypts Latin and Italian as Voynich Manuscript-like ciphertext“: Abstract: In this article, I investigate the hypothesis that the Voynich Manuscript (MS 408, Yale University Beinecke Library) is compatible with being a ciphertext by attempting to develop a…
-
ISC Stormcast For Tuesday, December 9th, 2025 https://isc.sans.edu/podcastdetail/9730, (Tue, Dec 9th)
ISC Stormcast For Tuesday, December 9th, 2025 https://isc.sans.edu/podcastdetail/9730, (Tue, Dec 9th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Apache Issues Max-Severity Tika CVE After Patch Miss
Apache Issues Max-Severity Tika CVE After Patch Miss The Apache Software Foundation’s earlier fix for a critical Tika flaw missed the full scope of the vulnerability, prompting an updated advisory and CVE. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Exploitation Activity Ramps Up Against React2Shell
Exploitation Activity Ramps Up Against React2Shell Attacks against CVE-2025-55182, which began almost immediately after public disclosure last week, have increased as more threat actors take advantage of the flaw. Rob Wright Go to gbhackers.com
-
US Treasury Tracks $4.5B in Ransom Payments since 2013
US Treasury Tracks $4.5B in Ransom Payments since 2013 The US Treasury’s Financial Crimes Enforcement Network shared data showing how dramatically ransomware attacks have changed over time. Alexander Culafi Go to gbhackers.com
-
‘Broadside’ Mirai Variant Targets Maritime Logistics Sector
‘Broadside’ Mirai Variant Targets Maritime Logistics Sector ‘Broadside’ is targeting a critical flaw in DVR systems to conduct command injection attacks, which can hijack devices to achieve persistence and move laterally. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Indonesia’s Gambling Industry Reveals Clues of Nationwide Cyber Involvement
Indonesia’s Gambling Industry Reveals Clues of Nationwide Cyber Involvement A massive Indonesian-speaking cybercrime operation spanning over 14 years has been uncovered, revealing a sophisticated infrastructure that shows hallmarks of state-level backing and resources… Go to gbhackers.com
-
Critical Cal.com Flaw Allows Attackers to Bypass Authentication Using Fake TOTP Codes
Critical Cal.com Flaw Allows Attackers to Bypass Authentication Using Fake TOTP Codes Cal.com has disclosed a critical authentication bypass vulnerability that could allow attackers to gain unauthorized access to user accounts by exploiting a flaw in… Go to gbhackers.com
-
Shanya EDR Killer: The New Favorite Tool for Ransomware Operators
Shanya EDR Killer: The New Favorite Tool for Ransomware Operators A sophisticated new “packer-as-a-service” tool known as Shanya has emerged in the cybercriminal underground, rapidly becoming a preferred weapon for major ransomware groups looking… Go to gbhackers.com
-
Critical React2Shell RCE Flaw Actively Exploited to Run Malicious Code
Critical React2Shell RCE Flaw Actively Exploited to Run Malicious Code A critical remote code execution vulnerability in React Server Components has emerged as an active exploitation target, with security researchers observing widespread automated attacks… Go to gbhackers.com
-
Critical Vulnerabilities Found in GitHub Copilot, Gemini CLI, Claude, and Other AI Tools Affect…
Critical Vulnerabilities Found in GitHub Copilot, Gemini CLI, Claude, and Other AI Tools Affect… A groundbreaking security research project has uncovered a new class of vulnerabilities affecting virtually every major AI-powered integrated development environment (IDE) and coding assistant… Go to gbhackers.com
-
OpenAI denies rolling out ads on ChatGPT paid plans
OpenAI denies rolling out ads on ChatGPT paid plans ChatGPT is allegedly showing ads to those who pay $20 for the Plus subscription, but OpenAI says this is an app recommendation feature, not an ad. […] Mayank Parmar Go to bleepingcomputer
-
Portugal updates cybercrime law to exempt security researchers
Portugal updates cybercrime law to exempt security researchers Portugal has modified its cybercrime law to establish a legal safe harbor for good-faith security research and to make hacking non-punishable under certain strict conditions. […] Bill Toulas Go to bleepingcomputer
-
Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits
Crypto User Loses $9,000 in Seconds After Clicking Instagram Ad Promising Easy Profits Jack, a Solana enthusiast using the Phantom wallet, fell victim to a sophisticated crypto drainer scam that wiped out $9,000 from his wallet almost instantly. He informed Cybersecurity News that the incident began with an attractive Instagram advertisement touting quick profits that…
-
Shanya EDR Killer Leveraged by Ransomware Groups to Clear the Way for Ransomware Infection
Shanya EDR Killer Leveraged by Ransomware Groups to Clear the Way for Ransomware Infection The cybercriminal landscape has recently witnessed the aggressive rise of “Shanya,” a potent packer-as-a-service and EDR killer now fueling major ransomware operations. Emerging on underground forums in late 2024 under the alias “VX Crypt,” this tool was engineered to supersede previous…
-
Pharma Firm Inotiv Confirms Data Breach Following Ransomware Attack
Pharma Firm Inotiv Confirms Data Breach Following Ransomware Attack A leading contract research organization specializing in pharmaceutical drug discovery and development services disclosed a significant data breach stemming from a ransomware attack that occurred in early August 2025. The Inotiv company announced the cybersecurity incident in its fiscal 2025 financial results disclosure. Revealing that threat…
-
Hundreds of Porsche Cars Immobilized Following Malfunction in Installed Satellite Security System
Hundreds of Porsche Cars Immobilized Following Malfunction in Installed Satellite Security System Owners of hundreds of Porsche vehicles across Russia are facing a sudden crisis: their high-performance cars have been rendered completely undrivable due to a widespread malfunction in the German automaker’s factory-installed alarm systems. Reports from the Rolf dealership network, Russia’s largest Porsche service…
-
Next.js Released a Scanner to Detect and Update Apps Impacted by React2Shell Vulnerability
Next.js Released a Scanner to Detect and Update Apps Impacted by React2Shell Vulnerability A dedicated command-line tool, fix-react2shell-next, to help developers immediately detect and patch the critical “React2Shell” vulnerability (CVE-2025-66478). This new scanner offers a one-line solution to identify vulnerable versions of Next.js and React Server Components (RSC). Automatically apply the required security updates included in…
-
ISC Stormcast For Monday, December 8th, 2025 https://isc.sans.edu/podcastdetail/9728, (Mon, Dec 8th)
ISC Stormcast For Monday, December 8th, 2025 https://isc.sans.edu/podcastdetail/9728, (Mon, Dec 8th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors. […] Lawrence Abrams Go to bleepingcomputer
-
New wave of VPN login attempts targets Palo Alto GlobalProtect portals
New wave of VPN login attempts targets Palo Alto GlobalProtect portals A campaign has been observed targeting Palo Alto GlobalProtect portals with login attempts and launching scanning activity against SonicWall SonicOS API endpoints. […] Bill Toulas Go to bleepingcomputer
-
LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak
LockBit 5.0 Infrastructure Exposed in New Server, IP, and Domain Leak LockBit 5.0 key infrastructure exposed, revealing the IP address 205.185.116.233, and the domain karma0.xyz is hosting the ransomware group’s latest leak site. According to researcher Rakesh Krishnan, hosted under AS53667 (PONYNET, operated by FranTech Solutions), a network frequently abused for illicit activities, the server…
-
Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs
Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs In an escalating campaign targeting remote access infrastructure, threat actors have initiated active exploitation attempts against Palo Alto Networks’ GlobalProtect VPN portals. GrayNoise tracking activity report scans and exploitation efforts originating from more than 7,000 unique IP addresses worldwide, raising alarms for organizations…
-
New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads
New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads A dangerous new Android banking malware named FvncBot was first observed on November 25, 2025. This malicious tool is designed to steal sensitive financial information by logging keystrokes, recording screens, and injecting fake login pages into banking apps. The malware initially spreads through a…
-
Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions
Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows attackers to inject malicious prompts via untrusted user inputs like issue titles or pull request bodies, tricking AI models into executing privileged commands that…
-
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks Over 30 security vulnerabilities have been disclosed in various artificial intelligence (AI)-powered Integrated Development Environments (IDEs) that combine prompt injection primitives with legitimate features to achieve data exfiltration and remote code execution. The security shortcomings have been collectively named IDEsaster by…
-
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday formally added a critical security flaw impacting React Server Components (RSC) to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, CVE-2025-55182 (CVSS score: 10.0), relates to…
-
Inside Shanya, a packer-as-a-service fueling modern attacks
Inside Shanya, a packer-as-a-service fueling modern attacks The ransomware scene gains another would-be EDR killer Gabor Szappanos Go to sophos
-
Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill
Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russia’s war against Ukraine. The Nerdify homepage. The link between…
-
Rust Code Delivers Better Security, Also Streamlines DevOps
Rust Code Delivers Better Security, Also Streamlines DevOps Software teams at Google and other Rust adopters see safer code when using the memory-safe language, and also fewer rollbacks and less code review. Robert Lemos, Contributing Writer Go to gbhackers.com
-
2.15M Next.js Web Services Exposed Online, Active Attacks Reported – Update Immediately
2.15M Next.js Web Services Exposed Online, Active Attacks Reported – Update Immediately Security teams worldwide are rushing to patch systems after the disclosure of a critical React vulnerability, CVE-2025-55182, widely known as “React2Shell.” The flaw affects… Go to gbhackers.com
-
FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads
FvncBot Android Malware Steals Keystrokes and Injects Harmful Payloads A newly discovered Android banking trojan, FvncBot, has emerged as a sophisticated threat targeting mobile banking users in Poland. Researchers from Intel 471 first… Go to gbhackers.com
-
Avast Antivirus Sandbox Vulnerabilities Allow Privilege Escalation
Avast Antivirus Sandbox Vulnerabilities Allow Privilege Escalation SAFA researchers uncovered four kernel heap overflow vulnerabilities in Avast Antivirus’s aswSnx.sys driver, designated CVE-2025-13032, affecting versions before 25.3 on Windows. These flaws originate from… Go to gbhackers.com
-
Threat Actors Distribute CoinMiner Malware through USB Drives to Infect Workstations
Threat Actors Distribute CoinMiner Malware through USB Drives to Infect Workstations Cybercriminals continue to exploit USB drives as infection vectors, with recent campaigns delivering sophisticated CoinMiner malware that establishes persistent cryptocurrency-mining operations on compromised workstations…. Go to gbhackers.com
-
MuddyWater Hackers Use UDPGangster Backdoor to Bypass Network Defenses on Windows
MuddyWater Hackers Use UDPGangster Backdoor to Bypass Network Defenses on Windows The MuddyWater threat group has escalated its cyber espionage operations by deploying UDPGangster, a sophisticated UDP-based backdoor designed to infiltrate Windows systems while systematically… Go to gbhackers.com
-
Barts Health NHS discloses data breach after Oracle zero-day hack
Barts Health NHS discloses data breach after Oracle zero-day hack Barts Health NHS Trust has announced that Clop ransomware actors have stolen files from a database by exploiting a vulnerability in its Oracle E-business Suite software. […] Bill Toulas Go to bleepingcomputer
-
FBI warns of virtual kidnapping scams using altered social media photos
FBI warns of virtual kidnapping scams using altered social media photos The FBI warns of criminals altering images shared on social media and using them as fake proof of life photos in virtual kidnapping ransom scams. […] Sergiu Gatlan Go to bleepingcomputer
-
A Practical Guide to Continuous Attack Surface Visibility
A Practical Guide to Continuous Attack Surface Visibility Passive scan data goes stale fast as cloud assets shift daily, leaving teams blind to real exposures. Sprocket Security shows how continuous, automated recon gives accurate, up-to-date attack surface visibility. […] Sponsored by Sprocket Security Go to bleepingcomputer
-
EU fines X $140 million over deceptive blue checkmarks
EU fines X $140 million over deceptive blue checkmarks The European Commission has fined X €120 million ($140 million) for violating transparency obligations under the Digital Services Act (DSA). […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare blames today’s outage on React2Shell mitigations
Cloudflare blames today’s outage on React2Shell mitigations Cloudflare has blamed today’s outage on the emergency patching of a critical React remote code execution vulnerability, which is now actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now
2.15M Web Services Running Next.js Exposed Over Internet, Active Exploitation Underway – Patch Now A critical unauthenticated remote code execution vulnerability dubbed “React2Shell” is actively being exploited in the wild, putting millions of web services at risk. On December 3, React disclosed CVE-2025-55182, a critical flaw in React Server Components with a CVSS score of…
-
Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges
Avast Antivirus Sandbox Vulnerabilities Let Attackers Escalate Privileges Security researchers from the SAFA team have uncovered four kernel heap overflow vulnerabilities in Avast Antivirus, all traced to the aswSnx kernel driver. The flaws, now tracked collectively as CVE-2025-13032, could allow a local attacker to escalate privileges to SYSTEM on Windows 11 if successfully exploited. The…
-
Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing
Sprocket Security Earns Repeat Recognition in G2’s Winter 2025 Relationship Index for Penetration Testing Madison, United States, December 5th, 2025, CyberNewsWire Sprocket Security is proud to announce that it has once again been recognized by G2 for “High Performer,” “Best Support,” and “Easiest to Do Business With” in the Winter 2025 Relationship Index for Penetration…
-
Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM
Criminal IP to Host Webinar: Beyond CVEs – From Visibility to Action with ASM Torrance, California, USA, December 5th, 2025, CyberNewsWire Criminal IP will host a live webinar on December 16 at 11:00 AM Pacific Time (PT), focusing on the shift in cyberattack strategies. The session will examine how an increasing number of incidents now…
-
Netflix Acquires Warner Bros. Studios and HBO in Landmark $82.7 Billion Megadeal
Netflix Acquires Warner Bros. Studios and HBO in Landmark $82.7 Billion Megadeal Netflix has struck a transformative deal to acquire Warner Bros. studios, HBO, and HBO Max from Warner Bros. Discovery (WBD) in a cash-and-stock transaction valued at $82.7 billion. The move catapults Netflix into a content powerhouse, blending its streaming dominance with Warner’s storied…
-
Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture
Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture Identity is effectively the new network boundary. It must be protected at all costs. Go to eset
-
TR-25-0429 (Synology Çoklu Ürün Güvenlik Bildirimi)
TR-25-0429 (Synology Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0428 (JavaScript (React) Güvenlik Zafiyeti)
TR-25-0428 (JavaScript (React) Güvenlik Zafiyeti) Go to usom.gov
-
TR-25-0427 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0427 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails A new agentic browser attack targeting Perplexity’s Comet browser that’s capable of turning a seemingly innocuous email into a destructive action that wipes a user’s entire Google Drive contents, findings from Straiker STAR Labs show. The zero-click Google Drive Wiper technique hinges on…
-
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch A critical security flaw has been disclosed in Apache Tika that could result in an XML external entity (XXE) injection attack. The vulnerability, tracked as CVE-2025-66516, is rated 10.0 on the CVSS scoring scale, indicating maximum severity. “Critical XXE in Apache Tika tika-core…
-
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability Two hacking groups with ties to China have been observed weaponizing the newly disclosed security flaw in React Server Components (RSC) within hours of it becoming public knowledge. The vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), aka React2Shell, which allows unauthenticated remote code execution.…
-
Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery A human rights lawyer from Pakistan’s Balochistan province received a suspicious link on WhatsApp from an unknown number, marking the first time a civil society member in the country was targeted by Intellexa’s Predator spyware, Amnesty International said in a report. The link, the…
-
“Getting to Yes”: An Anti-Sales Guide for MSPs
“Getting to Yes”: An Anti-Sales Guide for MSPs Most MSPs and MSSPs know how to deliver effective security. The challenge is helping prospects understand why it matters in business terms. Too often, sales conversations stall because prospects are overwhelmed, skeptical, or tired of fear-based messaging. That’s why we created ”Getting to Yes”: An Anti-Sales Guide…
-
Sharpening the knife: GOLD BLADE’s strategic evolution
Sharpening the knife: GOLD BLADE’s strategic evolution Updates include novel abuse of recruitment platforms, modified infection chains, and expansion into a hybrid operation that combines data theft and ransomware deployment Mindi McDowell Go to sophos
-
Introducing Sophos Intelix for Microsoft 365 Copilot
Introducing Sophos Intelix for Microsoft 365 Copilot Bringing Sophos threat intelligence directly into Microsoft 365 Copilot. Doug Aamoth Go to sophos
-
Introducing Sophos Intelix for Microsoft Security Copilot
Introducing Sophos Intelix for Microsoft Security Copilot Elevating threat intelligence for all Security Copilot users. Doug Aamoth Go to sophos
-
Friday Squid Blogging: Vampire Squid Genome
Friday Squid Blogging: Vampire Squid Genome The vampire squid (Vampyroteuthis infernalis) has the largest cephalopod genome ever sequenced: more than 11 billion base pairs. That’s more than twice as large as the biggest squid genomes. It’s technically not a squid: “The vampire squid is a fascinating twig tenaciously hanging onto the cephalopod family tree. It’s…
-
New Anonymous Phone Service
New Anonymous Phone Service A new anonymous phone service allows you to sign up with just a zip code. Bruce Schneier Go to bruce schneier
-
AutoIT3 Compiled Scripts Dropping Shellcodes, (Fri, Dec 5th)
AutoIT3 Compiled Scripts Dropping Shellcodes, (Fri, Dec 5th) AutoIT3[1] is a powerful language that helps to built nice applications for Windows environments, mainly to automate tasks. If it looks pretty old, the latest version was released last September and it remains popular amongst developers, for the good… or the bad! Malware written in AutoIt3 has…
-
ISC Stormcast For Friday, December 5th, 2025 https://isc.sans.edu/podcastdetail/9726, (Fri, Dec 5th)
ISC Stormcast For Friday, December 5th, 2025 https://isc.sans.edu/podcastdetail/9726, (Fri, Dec 5th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Weekly Update 481
Weekly Update 481 Twelve years (and one day) since launching Have I Been Pwned, it’s now a service that Charlotte and I live and breathe every day. From the first thing every morning to the last thing each day, from holidays to birthdays, in sickness and in heal… wait a minute – did we marry…
-
India Rolls Back App Mandate Amid Surveillance Concerns
India Rolls Back App Mandate Amid Surveillance Concerns Remember when Apple put that U2 album in everyone’s music libraries? India wanted to do that to all of its citizens, but with a cybersecurity app. It wasn’t a good idea. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Threat Landscape Grows Increasingly Dangerous for Manufacturers
Threat Landscape Grows Increasingly Dangerous for Manufacturers Manufacturers are the top target for cyberattacks in 2025 because of their still-plentiful cybersecurity gaps and a lack of expertise. Robert Lemos, Contributing Writer Go to gbhackers.com
-
CISOs Should Be Asking These Quantum Questions Today
CISOs Should Be Asking These Quantum Questions Today As quantum quietly moves beyond lab experiment and into production workflows, here’s what enterprise security leaders should be focused on, according to Lineswala. Rut Lineswala Go to gbhackers.com
-
CISA, NSA Alert on BRICKSTORM Malware Targeting VMware ESXi and Windows Systems
CISA, NSA Alert on BRICKSTORM Malware Targeting VMware ESXi and Windows Systems The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA), joined by Canadian cyber authorities, have issued a joint alert warning… Go to gbhackers.com
-
New Stealthy Linux Malware Merges Mirai-based DDoS Botnet with Fileless Cryptominer
New Stealthy Linux Malware Merges Mirai-based DDoS Botnet with Fileless Cryptominer Cybersecurity researchers uncover a sophisticated Linux campaign that blends legacy botnet capabilities with modern evasion techniques. A newly discovered Linux malware campaign is demonstrating the… Go to gbhackers.com
-
New SVG Technique Enables Highly Interactive Clickjacking Attacks
New SVG Technique Enables Highly Interactive Clickjacking Attacks A security researcher has unveiled a novel web exploitation technique dubbed “SVG clickjacking,” which significantly elevates the sophistication of traditional user-interface redress attacks. Unlike… Go to gbhackers.com
-
Threat Actors Exploit Foxit PDF Reader to Seize System Access and Steal Data
Threat Actors Exploit Foxit PDF Reader to Seize System Access and Steal Data A sophisticated malware campaign is leveraging a weaponized Foxit PDF Reader to target job seekers through email-based attacks, deploying ValleyRAT. This remote access trojan… Go to gbhackers.com
-
New Phishing Campaign Impersonates India’s Income Tax Department to Distribute AsyncRAT
New Phishing Campaign Impersonates India’s Income Tax Department to Distribute AsyncRAT In November 2025, security researchers at Raven AI identified a sophisticated zero-day phishing campaign impersonating the Income Tax Department of India, targeting enterprises across… Go to gbhackers.com
-
Cloudflare down, websites offline with 500 Internal Server Error
Cloudflare down, websites offline with 500 Internal Server Error Cloudflare is down, as websites are crashing with a 500 Internal Server Error. Cloudflare is investigating the reports. […] Mayank Parmar Go to bleepingcomputer
-
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells Threat actors have been exploiting a command injection vulnerability in Array AG Series VPN devices to plant webshells and create rogue users. […] Bill Toulas Go to bleepingcomputer
-
NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices
NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices The UK’s National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment. […] Bill Toulas Go to bleepingcomputer
-
Predator spyware uses new infection vector for zero-click attacks
Predator spyware uses new infection vector for zero-click attacks The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed “Aladdin” that compromised specific targets when simply viewing a malicious advertisement. […] Bill Toulas Go to bleepingcomputer
-
Russia blocks FaceTime and Snapchat for alleged use by terrorists
Russia blocks FaceTime and Snapchat for alleged use by terrorists Russian telecommunications watchdog Roskomnadzor has blocked access to Apple’s FaceTime video conferencing platform and the Snapchat instant messaging service, claiming they’re being used to coordinate terrorist attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare Outage Hits Internet with 500 Internal Server Error
Cloudflare Outage Hits Internet with 500 Internal Server Error Cloudflare has confirmed that it is currently experiencing a significant outage that is affecting the Cloudflare Dashboard and several Cloudflare API services. The issue began earlier today and has caused widespread disruptions for users who rely on Cloudflare’s management tools and automation features. According to Cloudflare,…
-
ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos
ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos A dangerous new Android spyware variant called ClayRat has emerged as a significant threat to mobile device security worldwide. First identified in October by the zLabs team, this malware represents a concerning evolution in mobile threats with capabilities that allow attackers to gain…
-
Beware of Solana Phishing Attacks That Let Hackers Initiate Unauthorized Account Transfer
Beware of Solana Phishing Attacks That Let Hackers Initiate Unauthorized Account Transfer A dangerous new wave of phishing attacks is targeting Solana users by changing wallet ownership permissions rather than stealing private keys. A victim lost more than USD 3 million in a single attack, with an additional USD 2 million locked in investment platforms.…
-
Cacti Command Injection Vulnerability Let Attackers Execute Malicious Code Remotely
Cacti Command Injection Vulnerability Let Attackers Execute Malicious Code Remotely A critical command injection vulnerability in the open-source network monitoring tool Cacti allows authenticated attackers to execute arbitrary code remotely, potentially compromising the entire monitoring infrastructure. The flaw, tracked as CVE-2025-66399, affects all versions up to 1.2.28 and stems from inadequate input validation in the…
-
Splunk Enterprise Vulnerabilities Allows Privileges Escalation Via Incorrect File Permissions
Splunk Enterprise Vulnerabilities Allows Privileges Escalation Via Incorrect File Permissions A high-severity vulnerability has been disclosed in Splunk affecting its Enterprise and Universal Forwarder products for Windows, stemming from incorrect file permissions during installation and upgrades. The vulnerability, tracked as CVE-2025-20386 for Splunk Enterprise and CVE-2025-20387 for Universal Forwarder. Allows non-administrator users to access sensitive…
-
JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
JPCERT Confirms Active Command Injection Attacks on Array AG Gateways A command injection vulnerability in Array Networks AG Series secure access gateways has been exploited in the wild since August 2025, according to an alert issued by JPCERT/CC this week. The vulnerability, which does not have a CVE identifier, was addressed by the company on…
-
Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China The threat actor known as Silver Fox has been spotted orchestrating a false flag operation to mimic a Russian threat group in attacks targeting organizations in China. The search engine optimization (SEO) poisoning campaign leverages Microsoft Teams lures to trick unsuspecting users…
-
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories Think your Wi-Fi is safe? Your coding tools? Or even your favorite financial apps? This week proves again how hackers, companies, and governments are all locked in a nonstop race to outsmart each other. Here’s a quick rundown of the latest…
-
5 Threats That Reshaped Web Security This Year [2025]
5 Threats That Reshaped Web Security This Year [2025] As 2025 draws to a close, security professionals face a sobering realization: the traditional playbook for web security has become dangerously obsolete. AI-powered attacks, evolving injection techniques, and supply chain compromises affecting hundreds of thousands of websites forced a fundamental rethink of defensive strategies. Here are…
-
GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections
GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections Cybercriminals associated with a financially motivated group known as GoldFactory have been observed staging a fresh round of attacks targeting mobile users in Indonesia, Thailand, and Vietnam by impersonating government services. The activity, observed since October 2024, involves distributing modified banking applications that act…