12/29/2025

The Worst Hacks of 2025

Happy 16th Birthday, KrebsOnSecurity.com!

Indian Cops Cuff Ex-Coinbase Rep Over Selling Customer Info to Crims

Hacker Arrested for KMSAuto Malware Campaign with 2.8 Million Downloads

Accused Data Thief Threw MacBook Into a River to Destroy Evidence
Korean Air Data Breach Exposes Data of Thousands of Employees

Romanian Energy Provider Oltenia Energy Complex Hit by Gentlemen Ransomware Attack

Two More Banks Notifying Thousands of Victims About Marquis Software Ransomware Attack

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

12/26-28/2025

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

The U.S. Must Stop Underestimating Drone Warfare

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

Death, Torture, and Amputation: How Cybercrime Shook the World in 2025

From Video Games to Cyber Defense: If You Don’t Think Like a Hacker, You Won’t Win

Coupang Founder Kim Bom Apologises for Data Leak, Pledges Compensation

Shaping the Next Generation of Cyber Experts
Trust Wallet Users Lose $7 Million to Hacked Chrome Extension

Fake GrubHub Emails Promise Tenfold Return on Sent Cryptocurrency

Ubisoft Shuts Down ‘Rainbow Six Siege’ Servers Following Hack

Hacker Claims to Leak WIRED Database with 2.3 million Records

Everest Ransomware Group Claims Theft of Over 1TB of Chrysler Data

Exploited MongoBleed Flaw Leaks MongoDB Secrets, 87K Servers Exposed

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

12/25/2025

Why Hackers Love the Holidays, Especially Christmas and the Like

OpenAI is Reportedly Testing Multiple Claude-Like Skills For ChatGPT

Study Reveals Businesses Continue to Underinvest in Cybersecurity and are Neglect in Vulnerability Assessments

The Biggest Cybersecurity Mergers and Acquisitions of 2025
Somerset County (PA) Utilizing New 911 Alert System After Cyber Attack

Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

12/24/2025

Pro-Russian Hackers Noname057 Claim Cyberattack on French Postal Service

NIST, MITRE Partner on $20m AI Centers For Manufacturing and Cybersecurity

The Age of the All-Access AI Agent Is Here

Pen Testers Accused of ‘Blackmail’ After Reporting Eurostar Chatbot Flaws

All I Want for Christmas Is Not a Scam – Tips to Avoid Digital Threats During the Festive Season
AI Powered Cyber Attack Hits Chinese TikTok Short Video Rival Kuaishou

Coordinated Scams Target MENA Region Extensively With Fake Online Job Ads

Fake MAS Windows Activation Domain Used to Spread PowerShell Malware

MongoDB Warns Admins to Patch Severe RCE Flaw Immediately

Cyber Volunteer Effort for Small Water Utilities Announces New MSSP Effort

12/23/2025

86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush

Dozens of Flock AI Camera Feeds Were Just Out There

FCC Bans Foreign-Made Drones and Key Parts Over U.S. National Security Risks

Chinese Crypto Scammers on Telegram Are Fueling the Biggest Darknet Markets Ever

SEC Sues Crypto Firms for Defrauding Investors Out of $14 Million

U.S. DoJ Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

NYPD Sued Over Possible Records Collected Through Muslim Spying Program

Italy Fines Apple $116 Million Over App Store Privacy Policy Issues
More Than 22 Million Aflac Customers Impacted by June Data Breach

Baker University (KS) Says 2024 Data Breach Impacts 53,000 People

Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

WebRAT Malware Spread via Fake Vulnerability Exploits on Github

Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

Microsoft Rolls Out Hardware-Accelerated BitLocker in Windows 11

A Cybersecurity Playbook for AI Adoption

ServiceNow Opens $7.7b Ticket Titled ‘Buy Security Company, Make It Armis’

12/22/2025

Cyber Spies Use Fake New Year Concert Invites to Target Russian Military

Romanian Water Authority Hit by BitLocker Ransomware Attack Over Weekend

Hacktivists Scrape 86M Spotify Tracks, Claim Their Aim Is to Preserve Culture

Microsoft Windows ‘Hack Your Own Password’ Attack Warning Issued

South Korea to Require Facial Recognition for New Mobile Numbers

Judge Rules That NSO Cannot Continue to Install Spyware via WhatsApp Pending Appeal

Interpol-Led Action Decrypts 6 Ransomware Strains, Arrests Hundreds

Nefilim Ransomware Affiliate Pleads Guilty
France’s National Post Office Hit by Suspected Cyber-Attack, Delaying Deliveries

University of Phoenix Data Breach Impacts Nearly 3.5 Million Individuals

Nissan Says Thousands of Customers Exposed in Red Hat Breach

Scripted Sparrow Sends Millions of BEC Emails Each Month

Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

New MacSync Malware Dropper Evades macOS Gatekeeper Checks

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access

12/19-21/2025

Inquiry Ongoing After UK Government Hacked, Says Minister

Firms Warned to Be On ‘High Alert’ for Scam Emails

Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence

Russian Defense Firms Targeted by Hackers Using AI, Other Tactics

Trump Signs Defense Bill Allocating Millions for Cyber Command, Mandating Pentagon Phone Security

Senate Confirms New Pentagon CIO

Krebs on Dismantling Defenses: Trump 2.0 Cyber Year in Review

Here’s What’s in the DOJ’s Epstein Files Release—And What’s Missing

U.S. Charges 54 in Massive ATM Jackpotting Conspiracy

Nigeria Arrests RaccoonO365 Phishing Developer Linked to Microsoft 365 Attacks

Ex-Michigan Assistant Matt Weiss Seen on Video Hacking Into Student Accounts, Security Footage Reveals
Hacks, Thefts, and Disruption: The Worst Data Breaches of 2025

Richmond Behavioral Health Authority (VA) Breach Hits Over 113K

Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware

RansomHouse Upgrades Encryption With Multi-Layered Data Processing

How RomCom Became a Multipurpose Cyberweapon

WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability

Over 25,000 FortiCloud SSO Devices Exposed to Remote Attacks

New UEFI Flaw Enables Pre-Boot Attacks on Motherboards from Gigabyte, MSI, ASUS, ASRock

Docker Hardened Images Now Open Source and Available for Free

Palo Alto Networks Announces Multibillion-Dollar Deal With Google Cloud

FTC: Instacart to Refund $60M Over Deceptive Subscription Tactics

12/18/2025

Denmark Says Russia Was Behind Two ‘Destructive and Disruptive’ Cyber-Attacks

LongNosedGoblin: China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware

New BeaverTail Malware Variant Linked to Lazarus Group

Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

North Korea Steals Over $2bn in Crypto in 2025

Amazon Blocked 1,800 Suspected North Korean Scammers Seeking Jobs

Haotian: The Ultra-Realistic AI Face Swapping Platform Driving Romance Scams

France Arrests Latvian for Installing Malware on Italian Ferry

Austria’s High Court Orders Meta to Change Its Personalized Ad Practices

Pa. High Court Rules That Police Can Access Google Searches Without a Warrant
Tech Provider for NHS England DXS International Confirms Data Breach

University of Sydney Suffers Data Breach Exposing Student and Staff Info

HMRC Warns of Over 135,000 Scam Reports

OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365

Clop Ransomware Targets Gladinet Centrestack in Data Theft Attacks

Your Car’s Web Browser May Be On the Road to Cyber Ruin

New Password Spraying Attacks Target Cisco, PAN VPN Gateways

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

BlackBerry Lifts Lower End of Annual Revenue Forecast on Cybersecurity Demand

12/17/2025

Chinese Ink Dragon Group Hides in European Government Networks

APT28 Targets Ukrainian UKR-net Users in Long-Running Credential Phishing Campaign

New Spyware Discovered on Belarusian Journalist’s Phone After Interrogation

Former Israeli Prime Minister Bennett’s Telegram Hacked, Not Phone, Despite Iranian Group’s Claims

Microsoft Will Finally Kill an Encryption Cipher That Enabled a Decade of Windows Hacks

Border Patrol Bets on Small Drones to Expand U.S. Surveillance Reach

Trump Targets Defense Giants’ Shareholder Payouts as Cost Overruns Mount, Sources Say

Blockchain Company Nomad to Repay Users Under FTC Deal After $186M Cyberattack

FBI Takes Down Alleged Money Laundering Service for Ransomware Groups

France Arrests Suspect Tied to Cyberattack on Interior Ministry

TikTok Tracked User’s Grindr Activity in Violation of European Law, Rights Group Alleges

Privacy Advocates See Risk in New Meta Policy That Uses AI Chats to Serve Targeted Ads
U.S. Autoparts Maker LKQ Confirms Oracle EBS Breach

New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Critical React2Shell Flaw Exploited in Ransomware Attacks

Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks

Cellik Android Malware Builds Malicious Versions From Google Play Apps

WhatsApp Device Linking Abused in Account Hijacking Attacks

New “Lies-in-the-Loop” Attack Undermines AI Safety Dialogs

Motors WordPress Vulnerability Exposes Sites to Takeover

Cisco Warns of Unpatched AsyncOS Zero-Day Exploited in Attacks

SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances

Zeroday Cloud Hacking Event Awards $320,0000 for 11 Zero Days

Think Like an Attacker: Cybersecurity Tips From a CISO

Roblox in Talks With Russia to Restore Access After Platform Ban Sparks Backlash

12/16/2025

Amazon Warns Russian GRU Hackers Target Western Firms via Edge Devices

Cyberattack Disrupts Venezuelan Oil Giant PDVSA’s Operations

Venezuela State Oil Company Blames Cyberattack on U.S. After Tanker Seizure

House Homeland Security Chairman Keeps Attention on Cyber Issues

Senior Official at Indo-Pacific Command Is Set to Be Trump’s Pick to Lead Cyber Command, NSA

React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors

Phishing Messages and Social Scams Flood Users Ahead of Christmas

Krebs: Most Parked Domains Now Serving Malicious Content

European Authorities Dismantle Call Center Fraud Ring in Ukraine

Still Using Windows 10? You’re a Prime Target for Ransomware Now – Unless You Do This
Hacking Group ‘ShinyHunters’ Threatens to Expose Premium Users of Sex Site PornHub

Analytics Provider Mixpanel: We Didn’t Expose You to Crims

City of Westminster (SC) Missing Public Funds After Cyber Attack, Officials Say

Madison Healthcare (MN) Confirms Data Breach After Ransomware Attack

Urban VPN Proxy Accused of Harvesting AI Chat Conversations

GhostPoster Attacks Hide Malicious JavaScript in Firefox Addon Logos

Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

JumpCloud Windows Agent Flaw Enables Local Privilege Escalation

Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass

12/15/2025

Suspected Russian Hackers Step Up Attacks on U.S. Energy Firms, Research Shows

German Parliament Suffers Suspected Cyber Attack During Zelenskyy’s Visit

French Interior Ministry Confirms Cyberattack on Email Servers

Google Links More Chinese Hacking Groups to React2Shell Attacks

MI6 Chief Warns ‘Front Line Is Everywhere’ and Signals Intent to Pressure Putin

U.S. Government Launches Campaign to Hire Engineers for AI, Tech Roles

Starlink Claims Chinese Launch Came Within 200 Meters of Broadband Satellite

Google’s Turning off Its Dark Web Monitoring Service That Scoured Data Breaches for Your Info

Texas Sues 5 Smart TV Manufacturers Over Data Collection Practices

Third Defendant Pleads Guilty in Fantasy Sports Betting Hack Case

Vibe Coding: Innovation Demands Vigilance
700Credit Data Breach Impacts 5.8 Million Vehicle Dealership Customers

Nearly 20 Million Affected by Prosper, 700Credit Data Breaches

Askul Confirms Theft of 740K Customer Records in Ransomware Attack

PornHub Extorted After Hackers Steal Premium Member Activity Data

More Than 238K Hit by Akira-Claimed Fieldtex Product Hack

Ongoing SoundCloud Issue Blocks VPN Users With 403 Server Error

SoundCloud Confirms Breach After Member Data Stolen, VPN Access Disrupted

Russian Phishing Campaign Delivers Phantom Stealer Via ISO Files

New SantaStealer Malware Steals Data From Browsers, Crypto Wallets

Featured Chrome Browser Extension Caught Intercepting Millions of Users’ AI Chats

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE

12/12-14/2025

React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation

Germany Summons Russian Ambassador Over Cyberattack, Election Disinformation

Announced Pick for No. 2 at NSA Won’t Get the Job as Another Candidate Surfaces

Trump Order on AI May Not Deter State Laws

AI Toys for Kids Talk About Sex and Issue Chinese Communist Party Talking Points, Tests Show

U.S. Bill Seeks Phase-Out of Chinese Sensors in Self-Driving Cars, After Space Hack Fears

ServiceNow in Talks to Acquire Cybersecurity Startup Armis in Potential $7 Billion Deal

Uncle Sam Sues Ex-Accenture Manager Over Army Cloud Security Claims

Coupang Data Breach Traced to Ex-Employee Who Retained System Access

MKVCinemas Streaming Piracy Service With 142M Visits Shuts Down

Canada’s Privacy Regulator to Probe Billboards Equipped With Facial Scanning Tech

Streisand Effect: Businesses That Pay Ransomware Gangs Are More Likely to Hit the Headlines

CyberVolk’s Ransomware Debut Stumbles on Cryptography Weakness
More Than 340,000 Impacted by Cyberattack on Library System of Pierce County (WA)

Hamas-Affiliated APT Targeting Government Agencies in the Middle East, Morocco

Beware: PayPal Subscriptions Abused to Send Fake Purchase Emails

Fake ‘One Battle After Another’ Torrent Hides Malware in Subtitles

New Advanced Phishing Kits Use AI and MFA Bypass Tactics to Steal Credentials at Scale

Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads

New React RSC Vulnerabilities Enable DoS and Source Code Exposure

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks

New Windows RasMan Zero-Day Flaw Gets Free, Unofficial Patches

Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

MITRE Shares 2025’s Top 25 Most Dangerous Software Weaknesses

Kali Linux 2025.4 Released With 3 New Tools, Desktop Updates

12/11/2025

Hackers Reportedly Breach Developer Involved With Russia’s Military Draft Database

OpenAI Enhances Defensive Models to Mitigate Cyber-Threats

Google Ads for Shared ChatGPT, Grok Guides Push macOS Infostealer Malware

Russian Hackers Debut Simple Ransomware Service, but Store Keys in Plain Text

Lawmaker Calls Facial Recognition on Doorbell Cameras a ‘Privacy Nightmare’

Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data

LastPass Hammered With £1.2M Fine for 2022 Breach Fiasco

Federal Agencies Now Only Have One More Day to Patch React2Shell Bug
Data Breach at 700Credit Impacts 160,000 Michiganders

WIRTE Leverages AshenLoader Sideloading to Install the AshTag Espionage Backdoor

New ConsentFix Attack Hijacks Microsoft Accounts via Azure CLI

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems

Malware Discovered in 19 Visual Studio Code Extensions

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw

Unpatched Gogs Zero-Day Exploited Across 700+ Instances Amid Active Attacks

Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution

Notepad++ Fixes Flaw That Let Attackers Push Malicious Update Files

12/10/2025

React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors

U.S. Says Russia-Backed Hacks Targeted Critical Infrastructure

U.S. Extradites Ukrainian Woman Accused of Hacking Meat Processing Plant for Russia

2 Men Linked to China’s Salt Typhoon Hacker Group Likely Trained in a Cisco ‘Academy’

U.S. Halts Plans to Sanction Chinese Spy Agency

British Government Sanctions Russian and Chinese Groups Over Information Warfare

OpenAI Warns New Models Pose ‘High’ Cybersecurity Risk

Log4Shell Downloaded 40 Million Times in 2025

Nvidia Builds Location Verification Tech That Could Help Fight Chip Smuggling

Coupang CEO Resigns Over Data Breach in South Korea

Senators Return to Effort to Boost Cybersecurity for Commercial Satellite Industry

Coalition Adds Deepfake Response to Cyber Insurance Policies Globally
Petco Takes Down Vetco Website After Exposing Customers’ Personal Information

Russia’s Flagship Airline Aeroflot Hacked Through Little-Known Tech Vendor Bakka Soft, According to New Report

ClickFix Social Engineering Sparks Rise of CastleLoader Attacks

New Spiderman Phishing Service Targets Dozens of European Banks

New DroidLock Malware Locks Android Devices and Demands a Ransom

Over 10,000 Docker Hub Images Found Leaking Credentials, Auth Keys

Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups

.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling

Google Fixes Zero Click Gemini Enterprise Flaw That Exposed Corporate Data

Microsoft Teams to Warn of Suspicious Traffic With External Domains

12/9/2025

React2Shell Exploit Campaigns Tied to North Korean Cyber Intrusion Tactics

Deploy New EtherRAT Malware

Gartner Calls For Pause on AI Browser Use

Analysts Warn of Cybersecurity Risks in Humanoid Robots

How to Answer the Door When the AI Agents Come Knocking

Trump Plans Executive Order Curbing State AI Law

Cyber Startup Saviynt Raises $700 Million to Secure Identity and Access

California Man Pleads Guilty to Rico Charges as DOJ Indicts Crypto Theft Gang

Spain Arrests Teen Who Stole 64 Million Personal Data Records

Seoul Cyber Investigators Seize Data, Devices From ‘South Korea’s Amazon’ Following Data Breach

Khashoggi Widow Files Complaint in France Alleging Saudi Government Infected Devices With Spywares
Space Bears Ransomware Claims Comcast Data Breach via Contractor Quasar Inc.

Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading

STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware

DeadLock Ransomware Uses BYOVD to Evade Security Measures

Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data

Fortinet Warns of Critical FortiCloud SSO Login Auth Bypass Flaws

Ivanti Warns of Critical Endpoint Manager Code Execution Flaw

SAP Fixes Three Critical Vulnerabilities Across Multiple Products

Krebs: Microsoft Patch Tuesday, December 2025 Edition

Windows PowerShell Now Warns When Running Invoke-WebRequest Scripts

12/8/2025

MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign

Three Hacking Groups, Two Vulnerabilities and All Eyes on China

U.S. to Allow Nvidia H200 Chip Shipments to China, Trump Says

Meta Proposal for Less Data Sharing Is Approved by European Commission

UK Moves to Strengthen Undersea Cable Defenses as Russian Snooping Ramps Up

Home Office Kept Police Facial Recognition Flaws to Itself, UK Data Watchdog Fumes

Poland Arrests Ukrainians Utilizing ‘Advanced’ Hacking Equipment

193 Cybercrims Arrested, Accused of Plotting ‘Violence-As-A-Service’

Russian Police Bust Bank-Account Hacking Gang That Used NFCGate-Based Malware

Russian Kids Revolt as Kremlin Bans Roblox, Other Popular Apps
Researchers Track Dozens of Organizations Affected by React2Shell Compromises Tied to China’s MSS

Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT

Malicious VSCode Extensions on Microsoft’s Registry Drop Infostealers

Ransomware Gangs Turn to Shanya EXE Packer to Hide EDR Killers

ClayRat Android Spyware Expands Capabilities

Malware Families FvncBot, and SeedSnatcher Too

Total Ransomware Payments Surpass $4.5 Billion Since 2013

Over $2.1B From 2022 To 2024

Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks

UK Intelligence Warns AI ‘Prompt Injection’ Attacks Might Never Go Away

12/5-7/2025

China-Linked Warp Panda Targets North American Firms in Espionage Campaign

Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability

React2Shell Flaw Exploited to Breach 30 Orgs, 77K IP Addresses Vulnerable

Cloudflare Restores Services After Minor Dashboard Outage

Cloudflare Blames Today’s Outage on react2shell Mitigations

Krebs: SMS Phishers Pivot to Points, Taxes, Fake Retailers

Krebs: Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

Crims Using Social Media Images, Videos in ‘Virtual Kidnapping’ Scams

Louvre to Bolster Its Security, Issues €57m Public Tender

Portugal Updates Cybercrime Law to Exempt Security Researchers

Maryland Man Sentenced for N. Korea IT Worker Scheme Involving U.S. Government Contracts

EU Fines X $140 Million Over Deceptive Blue Checkmarks

SolarWinds’ Tim Brown Escaped the SEC. Future Cyber Chiefs Might Not.
Pharma Firm Inotiv Discloses Data Breach After Ransomware Attack

Barts Health NHS Discloses Data Breach After Oracle Zero-Day Hack

Huge Trove of Nude Images Leaked by AI Image Generator Startup’s Exposed Database

New Wave of VPN Login Attempts Targets Palo Alto GlobalProtect Portals

Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails

Novel Clickjacking Attack Relies on CSS and SVG

Hackers are Exploiting ArrayOS AG VPN Flaw to Plant Webshells

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch

NCSC’s ‘Proactive Notifications’ Warns Orgs of Flaws in Exposed Devices

Death to One-Time Text Codes: Passkeys Are the New Hotness in MFA

A Tale of Two CISOs: Why An Engineering-Focused CISO Can Be a Liability

12/4/2025

Amid Rising Threats, NATO Holds Its Largest-Ever Cyberdefense Exercise

Twins Who Hacked State Dept Hired to Work for Gov Again, Now Charged With Deleting Databases

UK Sanctions Russia’s GRU Agency and Cyber Spies Over Deadly Nerve Agent Attack

FBI Says DC Pipe Bomb Suspect Brian Cole Kept Buying Bomb Parts After January 6

Pentagon’s Signalgate Report Finds Pete Hegseth Violated Military Policies

Taiwan to Ban China’s Xiaohongshu App for One Year on Fraud Concerns

A New Anonymous Phone Carrier Lets You Sign Up With Nothing but a Zip Code

British Officials Seek to Expand Facial Recognition Technology Use

Cybersecurity Startup 7AI Raises $130 Million in Series A Funding

I Saw Drone Deliveries Launch in Atlanta – How They Work and Which Cities Are Next
CISA Warns of Chinese “BrickStorm” Malware Attacks on VMware Servers

Predator Spyware Uses New Infection Vector for Zero-Click Attacks

Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China

GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

New GhostFrame Phishing Framework Hits Over One Million Attacks

Critical React, Next.js Flaw Lets Hackers Execute Code on Servers

CISA and International Partners Issue Guidance for Secure AI in Infrastructure

Russia Blocks FaceTime and Snapchat for Alleged Use by Terrorists

Russian Scientist Sentenced to 21 Years on Treason, Cyber Sabotage Charges

12/3/2025

French NGO Reporters Without Borders Targeted by Star Blizzard

Disinformation and Cyber-Threats Among Top Global Business Exec Concerns

‘Exploitation Is Imminent’ as 39 Percent of Cloud Environs Have Max-Severity React Hole

UK Ransomware Payment Ban to Come with Exemptions, Security Minster Say

India Revokes Order to Preload Cybersecurity App on Smartphones After Outcry

FDA Scrutiny of WHOOP Signals Challenges for Niche Wearable Device Makers

Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

Security Startup Verkada Hits $5.8 Billion Valuation in Latest Funding Round Led by CapitalG

How Amazon Finds Its Cybersecurity Weak Spots

Russia Blocks Roblox Over Distribution of LGBT “Propaganda”

Google Expands Android Scam Protection Feature to Chase, Cash App in U.S.

DOJ Takes Down Myanmar Scam Center Website Spoofing TickMill Trading Platform

Canadian Police Department Becomes First to Trial Body Cameras Equipped With Facial Recognition Technology
French DIY Retail Giant Leroy Merlin Discloses a Data Breach

University of Phoenix Discloses Data Breach After Oracle Hack

Japan’s Askul Resumes Limited Online Sales 6 Weeks After Ransomware Attack

ASUS Listed by Everest Ransomware Group, 1 TB Data Stolen

Freedom Mobile Discloses Data Breach Exposing Customer Data

Fintech Firm Marquis Alerts Dozens of U.S. Banks and Credit Unions of a Data Breach After Ransomware Attack

Impacts Over 74 U.S. Banks, Credit Unions

Yearn Finance yETH Pool Hit by $9M Exploit

Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud

Aisuru Botnet Behind New Record-Breaking 29.7 Tbps DDoS Attack

Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

WordPress King Addons Flaw Under Active Attack Lets Hackers Make Admin Accounts

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

12/1-2/2025

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

ShadyPanda’s Seven-Year Campaign Infects 4.3M Chrome and Edge Users

Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks

Officials Accuse North Korea’s Lazarus of $30 Million Theft From Crypto Exchange

Most Companies Fear State-Sponsored Cyber-Attacks and Want More Government Help

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

Flock Uses Overseas Gig Workers to Build its Surveillance AI

Former Cyber Spy Raises $60 Million to Fight AI Threats

CrowdStrike Forecasts Upbeat Quarterly Revenue as AI Adoption Fuels Growth

Okta Projects Strong Quarterly Revenue on Rising Demand for Cybersecurity Tools

Axiado Raises $100 Million for Chip to Save Space, Power in AI Data Centers

Your Data Might Determine How Much You Pay for Eggs

ICO Set to Check If Mobile Games Comply with Children’s Code

FTC Settlement Requires Illuminate to Delete Unnecessary Student Data

Korea Arrests Suspects Selling Intimate Videos From Hacked IP Cameras

Europol Nukes Cryptomixer Laundering Hub, Seizing €25M in Bitcoin
India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud

Faces Backlash

ChatGPT Is Down Worldwide, Conversations Dissapeared for Users

Microsoft Defender Portal Outage Disrupts Threat Hunting Alerts

Google Deletes X Post After Getting Caught Using a ‘Stolen’ AI Recipe Infographic

University of Pennsylvania Joins List of Victims From Clop’s Oracle EBS Raid

Shai-Hulud 2.0 NPM Malware Attack Exposed Up To 400,000 Dev Secrets

Southold (NY) Police Are Reporting With Pen and Paper After Cyber Attack

Fake Calendly Invites Spoof Top Brands to Hijack Ad Manager Accounts

SmartTube YouTube App for Android TV Breached to Push Malicious Update

Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

New Android Albiriox Malware Gains Traction in Dark Web Markets

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

Critical PickleScan Vulnerabilities Expose AI Model Supply Chains

Google Releases Patches for Android Zero-Day Flaws Exploited in the Wild