no alarms and no surprises please..
-
SMS Phishers Pivot to Points, Taxes, Fake Retailers
SMS Phishers Pivot to Points, Taxes, Fake Retailers China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday shopping season: Phishing kits for mass-creating fake but convincing e-commerce websites that convert customer payment card data into…
-
Why the record-breaking 30 Tbps DDoS attack should concern every business
Why the record-breaking 30 Tbps DDoS attack should concern every business A new warning about the threat posed by Distributed Denial of Service (DDoS) attacks should make you sit up and listen. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
How Agentic AI Can Boost Cyber Defense
How Agentic AI Can Boost Cyber Defense Transurban head of cyber defense Muhammad Ali Paracha shares how his team is automating the triaging and scoring of security threats as part of the Black Hat Middle East conference. Jeffrey Schwartz Go to gbhackers.com
-
CISA Warns of ‘Ongoing’ Brickstorm Backdoor Attacks
CISA Warns of ‘Ongoing’ Brickstorm Backdoor Attacks State-sponsored actors tied to China continue to target VMware vSphere environments at government and technology organizations. Rob Wright Go to gbhackers.com
-
CISA Publishes Security Guidance for Using AI in OT
CISA Publishes Security Guidance for Using AI in OT Global cybersecurity agencies published guidance regarding AI deployments in operational technology, a backbone of critical infrastructure. Alexander Culafi Go to gbhackers.com
-
ServiceNow’s Acquisition of NHI Provider Veza Strengthens Governance Portfolio
ServiceNow’s Acquisition of NHI Provider Veza Strengthens Governance Portfolio The deal, believed to be valued at $1 billion, will bring non-human identity access control of agents and machines to ServiceNow’s offerings including its new AI Control Tower. Jeffrey Schwartz Go to gbhackers.com
-
Student Sells Gov’t, University Sites to Chinese Actors
Student Sells Gov’t, University Sites to Chinese Actors It’s the best deal going in cybercrime: fully compromised websites belonging to high-value organizations, for just a couple hundred bucks each. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Critical React and Next.js Flaw Lets Remote Attackers Run Malicious Code
Critical React and Next.js Flaw Lets Remote Attackers Run Malicious Code A critical security vulnerability affecting React Server Components allows unauthenticated attackers to execute malicious code on servers running popular web frameworks. The flaw, tracked as… Go to gbhackers.com
-
Operation DupeHike: DuperRunner Malware Attack on Employees
Operation DupeHike: DuperRunner Malware Attack on Employees The SEQRITE APT-Team has recently uncovered a sophisticated cyberattack campaign designated as Operation DupeHike, targeting Russian corporate entities with precision and technical sophistication. The… Go to gbhackers.com
-
29.7 Tbps DDoS Attack by Aisuru Botnet Becomes the Largest Ever Recorded
29.7 Tbps DDoS Attack by Aisuru Botnet Becomes the Largest Ever Recorded A new and dangerous botnet named “Aisuru” has shattered world records by launching a Distributed Denial of Service (DDoS) attack that peaked at an… Go to gbhackers.com
-
Malicious VSCode Extension Deploys Anivia Loader and OctoRAT
Malicious VSCode Extension Deploys Anivia Loader and OctoRAT In late November 2025, a sophisticated supply-chain attack leveraging the Visual Studio Code extension ecosystem came to light, demonstrating how threat actors are increasingly… Go to gbhackers.com
-
Hackers Actively Exploit New Windows LNK 0-Day Vulnerability
Hackers Actively Exploit New Windows LNK 0-Day Vulnerability A newly discovered security flaw in Windows shortcut files is being actively used by hackers to target diplomatic organisations. The vulnerability allows attackers to conceal… Go to gbhackers.com
-
Marquis data breach impacts over 74 US banks, credit unions
Marquis data breach impacts over 74 US banks, credit unions Financial software provider Marquis Software Solutions is warning that it suffered a data breach that impacted dozens of banks and credit unions across the US. […] Lawrence Abrams Go to bleepingcomputer
-
Critical flaw in WordPress add-on for Elementor exploited in attacks
Critical flaw in WordPress add-on for Elementor exploited in attacks Attackers are exploiting a critical-severity privilege escalation vulnerability (CVE-2025-8489) in the King Addons for Elementor plugin for WordPress, which lets them obtain administrative permissions during the registration process. […] Bill Toulas Go to bleepingcomputer
-
French DIY retail giant Leroy Merlin discloses a data breach
French DIY retail giant Leroy Merlin discloses a data breach Leroy Merlin is sending security breach notifications to customers in France, informing them that their personal data was compromised. […] Bill Toulas Go to bleepingcomputer
-
Freedom Mobile discloses data breach exposing customer data
Freedom Mobile discloses data breach exposing customer data Freedom Mobile, the fourth-largest wireless carrier in Canada, has disclosed a data breach after attackers hacked into its customer account management platform and stole the personal information of an undisclosed number of customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia blocks Roblox over distribution of LGBT “propaganda”
Russia blocks Roblox over distribution of LGBT “propaganda” Roskomnadzor, Russia’s telecommunications watchdog, has blocked access to the Roblox online gaming platform for failing to stop the distribution of what it described as LGBT propaganda and extremist materials. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery
Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery Legitimate administrative tools are increasingly becoming the weapon of choice for sophisticated threat actors aiming to blend in with normal network activity. A recent campaign has highlighted this dangerous trend, where attackers are weaponizing Velociraptor, a widely respected Digital Forensics and Incident Response (DFIR)…
-
Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code
Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code A critical remote code execution vulnerability in the Sneeit Framework WordPress plugin has come under active exploitation by threat actors, posing an immediate risk to thousands of websites worldwide. The vulnerability, tracked as CVE-2025-6389 with a CVSS score of 9.8, exists in versions 8.3 and…
-
Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code
Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code A critical security vulnerability has been discovered in Vim for Windows that could allow attackers to execute malicious code on users’ computers. The vulnerability, identified as CVE-2025-66476, affects Vim versions before 9.1.1947 and has been rated high severity, with a CVSS score of 7.8. The flaw…
-
Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers
Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers A critical HTTP request smuggling vulnerability in Akamai’s edge server infrastructure has been successfully fixed. The vulnerability, identified as CVE-2025-66373, stemmed from improper processing of HTTP requests containing invalid chunk-encoded bodies, potentially exposing thousands of customers to sophisticated attacks. Understanding HTTP Chunked Transfer Encoding HTTP chunked…
-
Kohler’s Encrypted Smart Toilet Camera is not Actually end-to-end Encrypted
Kohler’s Encrypted Smart Toilet Camera is not Actually end-to-end Encrypted Kohler’s $600 smart toilet camera system, marketed with promises of “end-to-end encryption,” does not actually implement the security standard as commonly understood in the cybersecurity industry, raising significant privacy concerns for users uploading intimate health data to the company’s servers. The Dekoda device, launched in…
-
‘MuddyWater’ Hackers Target Israeli Orgs With Retro Game Tactic
‘MuddyWater’ Hackers Target Israeli Orgs With Retro Game Tactic Iran’s top state-sponsored APT is usually rather crass. But in a recent spate of attacks, it tried out some interesting evasion tactics, including delving into Snake, an old-school mobile game. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution A maximum-severity security flaw has been disclosed in React Server Components (RSC) that, if successfully exploited, could result in remote code execution. The vulnerability, tracked as CVE-2025-55182, carries a CVSS score of 10.0. The vulnerability has been codenamed React2shell. It allows “unauthenticated remote…
-
Discover the AI Tools Fueling the Next Cybercrime Wave — Watch the Webinar
Discover the AI Tools Fueling the Next Cybercrime Wave — Watch the Webinar Remember when phishing emails were easy to spot? Bad grammar, weird formatting, and requests from a “Prince” in a distant country? Those days are over. Today, a 16-year-old with zero coding skills and a $200 allowance can launch a campaign that rivals…
-
Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation
Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation Microsoft has silently plugged a security flaw that has been exploited by several threat actors since 2017 as part of the company’s November 2025 Patch Tuesday updates, according to ACROS Security’s 0patch. The vulnerability in question is CVE-2025-9491 (CVSS score: 7.8/7.0), which has been…
-
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts
WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts A critical security flaw impacting a WordPress plugin known as King Addons for Elementor has come under active exploitation in the wild. The vulnerability, CVE-2025-8489 (CVSS score: 9.8), is a case of privilege escalation that allows unauthenticated attackers to grant themselves administrative privileges…
-
Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud
Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud The threat actor known as Water Saci is actively evolving its tactics, switching to a sophisticated, highly layered infection chain that uses HTML Application (HTA) files and PDFs to propagate via WhatsApp a worm that deploys a banking trojan in attacks…
-
ISC Stormcast For Thursday, December 4th, 2025 https://isc.sans.edu/podcastdetail/9724, (Thu, Dec 4th)
ISC Stormcast For Thursday, December 4th, 2025 https://isc.sans.edu/podcastdetail/9724, (Thu, Dec 4th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Nation-State Attack or Compromised Government? [Guest Diary], (Thu, Dec 4th)
Nation-State Attack or Compromised Government? [Guest Diary], (Thu, Dec 4th) [This is a Guest Diary by Jackie Nguyen, an ISC intern as part of the SANS.edu BACS program] The ISC internship didn’t just teach me about security, it changed how I thought about threats entirely. There’s something intriguing about watching live attacks materialize on your…
-
Attempts to Bypass CDNs, (Wed, Dec 3rd)
Attempts to Bypass CDNs, (Wed, Dec 3rd) Currently, in order to provide basic DDoS protection and filter aggressive bots, some form of Content Delivery Network (CDN) is usually the simplest and most cost-effective way to protect a web application. In a typical setup, DNS is used to point clients to the CDN, and the CDN…
-
FBI warns of surge in account takeover (ATO) fraud schemes – what you need to know
FBI warns of surge in account takeover (ATO) fraud schemes – what you need to know The FBI has recently issued a public service announcement that warns that since January 2025 there have been more than 5,100 complaints of account takeover fraud, and total reported losses in excess of US $262 million. Read more in…
-
Why Does Have I Been Pwned Contain “Fake” Email Addresses?
Why Does Have I Been Pwned Contain “Fake” Email Addresses? Normally, when someone sends feedback like this, I ignore it, but it happens often enough that it deserves an explainer, because the answer is really, really simple. So simple, in fact, that it should be evident to the likes of Bruce, who decided his misunderstanding…
-
‘ShadyPanda’ Hackers Weaponize Millions of Browsers
‘ShadyPanda’ Hackers Weaponize Millions of Browsers The China-based cyber-threat group has been quietly using malicious extensions on the Google Chrome and Microsoft Edge marketplaces to spy on millions of users. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Critical React Flaw Triggers Calls for Immediate Action
Critical React Flaw Triggers Calls for Immediate Action The vulnerability, which was assigned two CVEs with maximum CVSS scores of 10, may affect more than a third of cloud service providers. Rob Wright Go to gbhackers.com
-
GISEC GLOBAL 2026 – The Middle East & Africa’s Largest Cybersecurity Event
GISEC GLOBAL 2026 – The Middle East & Africa’s Largest Cybersecurity Event Go to gbhackers.com
-
Arizona AG Sues Temu Over ‘Stealing’ User Data
Arizona AG Sues Temu Over ‘Stealing’ User Data The suit alleges the Chinese retailer’s app secretly accesses and harvests users’ sensitive information without their knowledge or consent. Alexander Culafi Go to gbhackers.com
-
The Ransomware Holiday Bind: Burnout or Be Vulnerable
The Ransomware Holiday Bind: Burnout or Be Vulnerable Ransomware groups target enterprises during off-hours, weekends, and holidays when security teams are stretched thin and response times lag. Arielle Waldman Go to gbhackers.com
-
Threat Actors Using Matanbuchus Downloader to Deliver Ransomware and Maintain Persistence
Threat Actors Using Matanbuchus Downloader to Deliver Ransomware and Maintain Persistence Threat actors are increasingly abusing the Matanbuchus malicious downloader as a key enabler for hands-on-keyboard ransomware operations, using its backdoor-like capabilities to deliver secondary… Go to gbhackers.com
-
Authorities Seize Domains Linked to Tai Chang Cryptocurrency Investment Scam
Authorities Seize Domains Linked to Tai Chang Cryptocurrency Investment Scam The United States Justice Department has seized a website domain used to steal money from Americans through fake cryptocurrency investments. The domain, tickmilleas.com, was… Go to gbhackers.com
-
New Stealth K.G.B RAT Marketed by Threat Actors on Underground Forums
New Stealth K.G.B RAT Marketed by Threat Actors on Underground Forums Threat actors on an underground cybercrime forum are allegedly promoting a new remote access Trojan (RAT) bundle dubbed “K.G.B RAT + Crypter + HVNC,”… Go to gbhackers.com
-
Critical Elementor Plugin Flaw Allows Attackers to Seize WordPress Admin Control
Critical Elementor Plugin Flaw Allows Attackers to Seize WordPress Admin Control A severe privilege escalation vulnerability in the King Addons for Elementor WordPress plugin has exposed thousands of websites to complete administrative compromise. The flaw,… Go to gbhackers.com
-
New “Executive Award” Scam Exploits ClickFix to Deliver Stealerium Malware
New “Executive Award” Scam Exploits ClickFix to Deliver Stealerium Malware A sophisticated new phishing campaign is targeting company executives with a double-pronged attack that steals credentials and deploys information-stealing malware in a single coordinated… Go to gbhackers.com
-
Korea arrests suspects selling intimate videos from hacked IP cameras
Korea arrests suspects selling intimate videos from hacked IP cameras The Korean National Police have arrested four individuals suspected of hacking over 120,000 IP cameras across the country and then selling stolen footage to a foreign adult site. […] Bill Toulas Go to bleepingcomputer
-
FTC settlement requires Illuminate to delete unnecessary student data
FTC settlement requires Illuminate to delete unnecessary student data The Federal Trade Commission (FTC) is proposing that education technology provider Illuminate Education to delete unnecessary student data and improve its security to settle allegations related to an incident in 2021 that exposed info of 10 million students. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT is down worldwide, conversations disappeared for users
ChatGPT is down worldwide, conversations disappeared for users OpenAI’s AI-powered ChatGPT is down worldwide with users receiving errors when attempting to access chats, with no reasons currently given. […] Mayank Parmar Go to bleepingcomputer
-
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender portal outage disrupts threat hunting alerts
Microsoft Defender portal outage disrupts threat hunting alerts Microsoft is working to mitigate an ongoing incident that has been blocking access to some Defender XDR portal capabilities, including threat hunting alerts. […] Sergiu Gatlan Go to bleepingcomputer
-
BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters
BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion…
-
Threat Actors Leveraging Matanbuchus Malicious Downloader to Ransomware and Establish Persistence
Threat Actors Leveraging Matanbuchus Malicious Downloader to Ransomware and Establish Persistence Matanbuchus represents a significant threat in the cybercriminal landscape as a dangerous malware downloader written in C++. Since 2020, this tool has been sold as Malware-as-a-Service, allowing threat actors to rent access and deploy it against targeted organizations. In July 2025, security researchers discovered…
-
Let’s Encrypt to Reduce Certificate Validity from 90 Days to 45 Days
Let’s Encrypt to Reduce Certificate Validity from 90 Days to 45 Days Let’s Encrypt has officially announced plans to reduce the maximum validity period of its SSL/TLS certificates from 90 days to 45 days. The transition, which will be completed by 2028, aligns with broader industry shifts mandated by the CA/Browser Forum Baseline Requirements. This…
-
Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks
Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks The development team has officially released essential security updates to address two significant vulnerabilities found in the popular web framework. These issues range from high to moderate severity. They could allow attackers to compromise database integrity or crash servers through resource exhaustion. The most critical flaw,…
-
Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution
Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40/41 for Windows and Mac. This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary code or…
-
MuddyWater: Snakes by the riverbank
MuddyWater: Snakes by the riverbank MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook Go to eset
-
TR-25-0426 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0426 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0425 (Sprecher Automation Güvenlik Bildirimi)
TR-25-0425 (Sprecher Automation Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0424 (Datateam Bilgi Teknolojileri – Datactive Güvenlik Bildirimi)
TR-25-0424 (Datateam Bilgi Teknolojileri – Datactive Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0423 (Argus Teknoloji – BİLGER Güvenlik Bildirimi)
TR-25-0423 (Argus Teknoloji – BİLGER Güvenlik Bildirimi) Go to usom.gov
-
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse India’s Department of Telecommunications (DoT) has issued directions to app-based communication service providers to ensure that the platforms cannot be used without an active SIM card linked to the user’s mobile number. To that end, messaging apps like WhatsApp,…
-
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera A joint investigation led by Mauro Eldritch, founder of BCA LTD, conducted together with threat-intel initiative NorthScan and ANY.RUN, a solution for interactive malware analysis and threat intelligence, has uncovered one of North Korea’s most persistent infiltration schemes: a network of remote IT workers tied to…
-
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools The supply chain campaign known as GlassWorm has once again reared its head, infiltrating both Microsoft Visual Studio Marketplace and Open VSX with 24 extensions impersonating popular developer tools and frameworks like Flutter, React, Tailwind, Vim, and Vue. GlassWorm was first documented in October 2025,…
-
Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools
Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools Cybersecurity researchers have disclosed details of an npm package that attempts to influence artificial intelligence (AI)-driven security scanners. The package in question is eslint-plugin-unicorn-ts-2, which masquerades as a TypeScript extension of the popular ESLint plugin. It was uploaded to the registry by…
-
Iran-Linked Hackers Hit Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks
Iran-Linked Hackers Hit Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks Israeli entities spanning academia, engineering, local government, manufacturing, technology, transportation, and utilities sectors have emerged as the target of a new set of attacks undertaken by Iranian nation-state actors that have delivered a previously undocumented backdoor called MuddyViper. The activity has been attributed…
-
ISC Stormcast For Wednesday, December 3rd, 2025 https://isc.sans.edu/podcastdetail/9722, (Wed, Dec 3rd)
ISC Stormcast For Wednesday, December 3rd, 2025 https://isc.sans.edu/podcastdetail/9722, (Wed, Dec 3rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
China Researches Ways to Disrupt Satellite Internet
China Researches Ways to Disrupt Satellite Internet While satellite constellations — such as Starlink — are resilient, 2,000 drones could cut communications to a region the size of Taiwan, researchers find. Robert Lemos, Contributing Writer Go to gbhackers.com
-
The AI Fix #79: Gemini 3, poetry jailbreaks, and do we even need safe robots?
The AI Fix #79: Gemini 3, poetry jailbreaks, and do we even need safe robots? In episode 79 of The AI Fix, Gemini 3 roasts the competition, scares Nvidia, and can’t remember what year it is. Meanwhile, Graham investigates a fight between a fridge and robot, and Mark discovers that poetry could be a universal…
-
Asahi cyber attack spirals into massive data breach impacting almost 2 million people
Asahi cyber attack spirals into massive data breach impacting almost 2 million people Asahi Group Holdings, the makers of the popular Japanese beer Asahi Super Dry, has confirmed that the ransomware attack that disrupted its operations in late September also saw a significant data breach that affects more than 1.5 million customers and approximately 275,000…
-
166: Maxie
166: Maxie Maxie Reynolds loves an adventure, especially the kind where she’s breaking into buildings (legally). In this episode, she shares stories from her time as a professional penetration tester, including high-stakes physical intrusions, red team chaos, and the unique adrenaline of hacking the real world. Her book: The Art of Attack: Attacker Mindset for…
-
Iran’s ‘MuddyWater’ Levels Up With MuddyViper Backdoor
Iran’s ‘MuddyWater’ Levels Up With MuddyViper Backdoor New Fooder loader and memory-only tactics suggest MuddyWater has evolved from its usual noisy ops to more stealthy espionage operations. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Researchers Use Poetry to Jailbreak AI Models
Researchers Use Poetry to Jailbreak AI Models When prompts were presented in poetic rather than prose form, attack success rates increased from 8% to 43%, on average — a fivefold increase. Alexander Culafi Go to gbhackers.com
-
DPRK’s ‘Contagious Interview’ Spawns Malicious Npm Package Factory
DPRK’s ‘Contagious Interview’ Spawns Malicious Npm Package Factory North Korean attackers have delivered more than 197 malicious packages with 31K-plus downloads since Oct. 10, as part of ongoing state-sponsored activity to compromise software developers. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Google Fixes Android Zero-Day Flaws Actively Exploited in the Wild
Google Fixes Android Zero-Day Flaws Actively Exploited in the Wild Google has released critical security patches addressing two high-severity zero-day vulnerabilities in Android that are currently being exploited in limited, targeted attacks. The vulnerabilities,… Go to gbhackers.com
-
Apache Struts Flaw Allows Attackers to Launch Disk Exhaustion Attacks
Apache Struts Flaw Allows Attackers to Launch Disk Exhaustion Attacks A new security flaw has been found in Apache Struts, a popular open‑source web application framework used by many companies worldwide. The issue, tracked… Go to gbhackers.com
-
Glassworm Malware Targets OpenVSX and Microsoft Visual Studio with 24 New Malicious Packages
Glassworm Malware Targets OpenVSX and Microsoft Visual Studio with 24 New Malicious Packages Security threats rarely adhere to holiday schedules, and while developers may take time off, malicious actors are working overtime. A significant new wave of… Go to gbhackers.com
-
OpenAI Codex CLI Flaw Allows Attackers to Run Arbitrary Commands
OpenAI Codex CLI Flaw Allows Attackers to Run Arbitrary Commands OpenAI’s Codex CLI, a command-line tool designed to bring AI-powered reasoning into developer workflows, contains a critical vulnerability that allows attackers to execute arbitrary… Go to gbhackers.com
-
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign Koi researchers have uncovered a seven-year browser extension operation that has silently compromised at least 4.3 million Chrome and Edge users worldwide. The threat… Go to gbhackers.com
-
Glassworm malware returns in third wave of malicious VS Code packages
Glassworm malware returns in third wave of malicious VS Code packages The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms. […] Bill Toulas Go to bleepingcomputer
-
SmartTube YouTube app for Android TV breached to push malicious update
SmartTube YouTube app for Android TV breached to push malicious update The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer’s signing keys, leading to a malicious update being pushed to users. […] Bill Toulas Go to bleepingcomputer
-
Microsoft says new Outlook can’t open some Excel attachments
Microsoft says new Outlook can’t open some Excel attachments Microsoft is working to resolve a known issue that prevents some users from opening Excel email attachments in the new Outlook client. […] Sergiu Gatlan Go to bleepingcomputer
-
Retail giant Coupang data breach impacts 33.7 million customers
Retail giant Coupang data breach impacts 33.7 million customers South Korea’s largest retailer, Coupang, has suffered a data breach that exposed the personal information of 33.7 million customers. […] Bill Toulas Go to bleepingcomputer
-
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats Hackers impersonate IT pros with deepfakes, fake resumes, and stolen identities, turning hiring pipelines into insider threats. Huntres sLabs explains how stronger vetting and access controls help stop these threats. […] Sponsored by Huntress Labs Go to bleepingcomputer
-
Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration
Sonesta International Hotels Implements Industry-Leading Cloud Security Through AccuKnox Collaboration Travel and hospitality industry leader Sonesta International Hotels partners with AccuKnox to deploy Zero Trust Integrated Application and Cloud Security [ASPM and CNAPP (Cloud Native Application Protection Platform)] for Microsoft Azure. AccuKnox, Inc., announced that Sonesta International Hotels has partnered with AccuKnox to deploy Zero…
-
Google Patches Android 0-Day Vulnerabilities Exploited in the Wild
Google Patches Android 0-Day Vulnerabilities Exploited in the Wild Google has released critical security updates to address multiple zero-day vulnerabilities affecting Android devices worldwide. The December 2025 security bulletin reveals that threat actors are actively exploiting at least two of these vulnerabilities in real-world attacks, prompting urgent action from the tech giant. Critical Vulnerabilities Under…
-
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign A sophisticated threat group operating under the name ShadyPanda has successfully compromised millions of browser users through a methodical seven-year campaign targeting popular Chrome and Edge extensions. The attack represents a significant breach of user trust, as the malicious extensions gained verified status…
-
OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks
OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks OpenVPN has released critical security updates for its 2.6 stable and 2.7 development branches, addressing three vulnerabilities that could lead to local denial-of-service (DoS), security bypasses, and buffer over-reads. The patches, included in the newly released version 2.6.17 and 2.7_rc3, fix issues ranging from…
-
India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones
India Mandates ‘Undeletable’ Government Cybersecurity App for All Smartphones India’s Department of Telecommunications (DoT) has ordered smartphone manufacturers to preload a government-backed cybersecurity app, “Sanchar Saathi,” on all new devices sold in the country. The order, issued privately on November 28, 2025, gives major players like Apple, Samsung, Xiaomi, Vivo, and Oppo 90 days to…
-
TR-25-0422 (Seneka Yazılım Donanım Bilişim – Onaylarım Güvenlik Bildirimi)
TR-25-0422 (Seneka Yazılım Donanım Bilişim – Onaylarım Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0421 (Tekrom Teknoloji – T-Soft E-Commerce Güvenlik Bildirimi)
TR-25-0421 (Tekrom Teknoloji – T-Soft E-Commerce Güvenlik Bildirimi) Go to usom.gov
-
TR-25-0420 (WordPress Eklenti Güvenlik Bildirimi)
TR-25-0420 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud
India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud India’s telecommunications ministry has ordered major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days. According to a report from Reuters, the app cannot be deleted or disabled from users’ devices. Sanchar Saathi,…
-
ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware
ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware A threat actor known as ShadyPanda has been linked to a seven-year-long browser extension campaign that has amassed over 4.3 million installations over time. Five of these extensions started off as legitimate programs before malicious changes were introduced in mid-2024, according to a report…
-
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More
⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More Hackers aren’t kicking down the door anymore. They just use the same tools we use every day — code packages, cloud accounts, email, chat, phones, and “trusted” partners — and turn them against us. One bad download can leak your…
-
Webinar: The “Agentic” Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams
Webinar: The “Agentic” Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams The AI browser wars are coming to a desktop near you, and you need to start worrying about their security challenges. For the last two decades, whether you used Chrome, Edge, or Firefox, the fundamental paradigm remained the…
-
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control A new Android malware named Albiriox has been advertised under a malware-as-a-service (MaaS) model to offer a “full spectrum” of features to facilitate on-device fraud (ODF), screen manipulation, and real-time interaction with infected devices. The malware embeds a hard-coded list comprising over…
-
Banning VPNs
Banning VPNs This is crazy. Lawmakers in several US states are contemplating banning VPNs, because…think of the children! As of this writing, Wisconsin lawmakers are escalating their war on privacy by targeting VPNs in the name of “protecting children” in A.B. 105/S.B. 130. It’s an age verification bill that requires all websites distributing material that…
-
ISC Stormcast For Tuesday, December 2nd, 2025 https://isc.sans.edu/podcastdetail/9720, (Tue, Dec 2nd)
ISC Stormcast For Tuesday, December 2nd, 2025 https://isc.sans.edu/podcastdetail/9720, (Tue, Dec 2nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
[Guest Diary] Hunting for SharePoint In-Memory ToolShell Payloads, (Tue, Dec 2nd)
[Guest Diary] Hunting for SharePoint In-Memory ToolShell Payloads, (Tue, Dec 2nd) [This is a Guest Diary by James Woodworth, an ISC intern as part of the SANS.edu Bachelor’s Degree in Applied Cybersecurity (BACS) program [1]. In July 2025, many of us were introduced to the Microsoft SharePoint exploit chain known as ToolShell. ToolShell exploits the…