101Articles
8Categories
2025-12-08Date
🚨
CISA Adds Critical React2Shell Vulnerability to KEV Catalog After Active ExploitationThe Cybersecurity and Infrastructure Security Agency (CISA) has officially added a high-severity vulnerability affecting Meta’s React Server Components to its Known Exploited Vulnerabilities (KEV) catalog. Assigned the identifier CVE-2025-55182, the security flaw dubbed …
KEV
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2022-37055 D-Link Routers Buffer Overflow Vulnerability CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection Vulnerability  Th…
KEV
πŸ›
Critical Cal.com Flaw Allows Attackers to Bypass Authentication Using Fake TOTP Codes
πŸ›
Critical React2Shell RCE Flaw Actively Exploited to Run Malicious Code
KEV
πŸ›
Exploitation of React2Shell Surges
πŸ›
Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks
KEV
πŸ›
Apache Tika hit by critical vulnerability thought to be patched months ago
πŸ›
CVE-2025-40277 drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE
πŸ›
CVE-2025-40287 exfat: fix improper check of dentry.stream.valid_size
πŸ›
CVE-2025-40275 ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd
πŸ›
CVE-2025-40285 smb/server: fix possible refcount leak in smb2_sess_setup()
πŸ›
CVE-2025-40273 NFSD: free copynotify stateid in nfs4_free_ol_stateid()
πŸ›
CVE-2025-40280 tipc: Fix use-after-free in tipc_mon_reinit_self().
πŸ›
CVE-2025-40281 sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto
πŸ›
CVE-2025-40269 ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
πŸ›
CVE-2025-40289 drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
πŸ›
CVE-2025-40278 net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak
πŸ›
CVE-2025-40268 cifs: client: fix memory leak in smb3_fs_context_parse_param
πŸ›
CVE-2025-40272 mm/secretmem: fix use-after-free race in fault handler
πŸ›
CVE-2025-40288 drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices
πŸ›
CVE-2025-40284 Bluetooth: MGMT: cancel mesh send timer when hdev removed
πŸ›
CVE-2025-40283 Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF
πŸ›
CVE-2025-40286 smb/server: fix possible memory leak in smb2_read()
πŸ›
CVE-2025-40279 net: sched: act_connmark: initialize struct tc_ife to fix kernel leak
πŸ›
CVE-2025-40282 Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
⚠️
DevelopmentTools May Allow Remote Compromise
⚠️
Indonesia’s Gambling Industry Reveals Clues of Nationwide Cyber Involvement
⚠️
Critical Vulnerabilities Found in GitHub Copilot, Gemini CLI, Claude, and Other AI Tools Affect Millions
⚠️
Vaillant CISO: NIS2 complexity and lack of clarity endanger its mission
⚠️
Offensive security takes center stage in the AI era
⚠️
Apache warns of critical vulnerability in Tika toolkit
⚠️
Fix your dumb misconfigurations, AI isn't people, and the weekly news - ESW #436
⚠️
Critical Apache Tika Vulnerability Leads to XXE Injection
⚠️
Android Malware FvncBot, SeedSnatcher, and ClayRat Gain Stronger Data Theft Features
⚠️
LOLPROX Unveils Undetected Exploitation Routes for Stealthy Hypervisor Attacks
⚠️
Next.js Releases Scanner to Detect and Fix Apps Affected by React2Shell Vulnerability
⚠️
Hackers Target Developers Using Malicious VS Code and Cursor AI Extensions
⚠️
WatchGuard Firebox Vulnerabilities Let Hackers Skip Integrity Validation and Plant Malicious Code
⚠️
⚑ Weekly Recap: USB Malware, React2Shell, WhatsApp Worms, AI IDE Bugs & More
⚠️
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
⚠️
KI schafft neue Sicherheitsrisiken fΓΌr OT-Netzwerke
⚠️
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks
⚠️
Hackers Exploit Multiple Ad Networks to Distribute Triada Malware to Android Users
⚠️
US Contributes to 44% of Cyber Attacks; Public Administration Targeted for Financial Gains
⚠️
Hackers Exploit Delivery Receipts in Messaging Apps to Steal Users’ Private Information
⚠️
Agents at the Door: Vetting Non-Human Identities in External IAM - Rakesh Soni - CSP #219
⚠️
When it comes to security resilience, cheaper isn’t always better
⚠️
Keep AI browsers out of your enterprise, warns Gartner
⚠️
Architecting Security for Agentic Capabilities in Chrome
⚠️
News alert: INE recognized in G2 Winter 2026 rankings for global strength in cyber and IT training
⚠️
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024
⚠️
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat Actors
KEV
πŸ“’
IBM security advisory (AV25-811)
πŸ“’
Ubuntu security advisory (AV25-813)
πŸ“’
Dell security advisory (AV25-812)
πŸ“’
Red Hat security advisory (AV25-814)
πŸ“’
[Control systems] CISA ICS security advisories (AV25–815)
πŸ“’
WatchGuard security advisory (AV25-816)
πŸ”₯
Shanya EDR Killer: The New Favorite Tool for Ransomware Operators
πŸ”₯
LockBit 5.0 Infrastructure Exposed as Hackers Leak Critical Server Data
πŸ”₯
MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign
πŸ”₯
Ransomware Payments Surpassed $4.5 Billion: US Treasury
πŸ”₯
LockBit 5.0 Infrastructure Exposed in New Server, IP and Domain Leak
πŸ”₯
Tri-Century Eye Care Data Breach Impacts 200,000 Individuals
πŸ”₯
US military contractor breach expose employee data | Cybernews
πŸ”₯
Cl0p ransomware stole Barts Health's patient and staff invoice data, trust confirms | Cybernews
πŸ”₯
Operation Kitten: Hacktivist Groups Targeting Israel with Cyberattacks
πŸ”₯
Asus supplier hacked by Everest gang, loses 1 TB of data β€’ The Register
πŸ”₯
Pharma firm Inotiv discloses data breach after ransomware attack
πŸ”₯
Stronger together: New Beazley collaboration enhances cyber resilience
πŸ”₯
Experts Confirm JS#SMUGGLER Uses Compromised Sites to Deploy NetSupport RAT
πŸ”₯
Ransomware gangs turn to Shanya EXE packer to hide EDR killers
πŸ•΅οΈ
ISC Stormcast For Monday, December 8th, 2025 https://isc.sans.edu/podcastdetail/9728, (Mon, Dec 8th)
πŸ•΅οΈ
Portugal updates cybercrime law to exempt security researchers
πŸ•΅οΈ
Porsche Cars Disabled After Major Failure in Installed Satellite Security System
πŸ•΅οΈ
OceanLotus Targets Xinchuang Ecosystem with Sophisticated Supply Chain Attacks
πŸ•΅οΈ
Substitution Cipher Based on The Voynich Manuscript
πŸ•΅οΈ
NVIDIA research shows how agentic AI fails under attack - Help Net Security
πŸ•΅οΈ
Notorious Cybercrime Group is Now Targeting Zendesk Users
πŸ•΅οΈ
Exposing the Core Functionalities of QuasarRAT: Encrypted Configuration and Obfuscation Techniques
πŸ•΅οΈ
NVIDIA and Lakera AI Propose Unified Framework for Agent Safety
πŸ•΅οΈ
Apple, Google, and Samsung May Soon Activate Always-On GPS in India
πŸ•΅οΈ
Resemble AI Raises $13 Million for AI Threat Detection
πŸ•΅οΈ
CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary
πŸ•΅οΈ
How Agentic BAS AI Turns Threat Headlines Into Defense Strategies
πŸ•΅οΈ
ThreatLocker: Zero Trust & Threat Detection
πŸ•΅οΈ
Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks
πŸ•΅οΈ
New FvncBot Android banking trojan targets Poland
πŸ•΅οΈ
INE Earns G2 Winter 2026 Badges Across Global Markets
πŸ•΅οΈ
When the Digital World Turns Physical: The Expanding Role of Threat Intelligence in Executive Protection
🌐
AI-Automated Threat Hunting Brings GhostPenguin Out of the Shadows
🌐
How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year?
🌐
ShellShock Makes a Comeback and RondoDox Changes Tactics
🌐
Malicious VSCode extensions on Microsoft's registry drop infostealers
🌐
ShellShock Makes a Comeback and RondoDox Changes Tactics
πŸ“‘
Privacy concerns raised as Grok AI found to be a stalker’s best friend
πŸ“‘
Petco’s security lapse affected customers’ SSNs, drivers’ licenses and more
πŸ“‘
Google Chrome adds new security layer for Gemini AI agentic browsing
πŸ“‘
Poland arrests Ukrainians utilizing 'advanced' hacking equipment
πŸ“‘
FTC upholds ban on stalkerware founder Scott Zuckerman
πŸ“‘
[webapps] Pluck 4.7.7-dev2 - PHP Code Execution