Know What's Happening in Cybersecurity

Today's Cybersecurity Pulse

CISA adds critical Android and Linux flaws to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed two high‑severity vulnerabilities in its Known Exploited Vulnerabilities catalog: Android CVE‑2025‑48595, an integer overflow that enables privilege escalation on Android 14‑16 without user interaction, and Linux CVE‑2022‑0492. Google released patches for the Android bug in June 2026.

The New Surveillance State Is You
NewsDec 29, 2025

The New Surveillance State Is You

In the first year of President Trump’s second term, citizens have flooded social media with videos and apps that track ICE and other federal agents during raids and arrests. The Department of Homeland Security responded with subpoenas to Meta, criminal...

By WIRED (Security)
This Month in Security with Tony Anscombe – December 2025 Edition
NewsDec 29, 2025

This Month in Security with Tony Anscombe – December 2025 Edition

Tony Anscombe, ESET’s chief security evangelist, recaps the year’s most consequential cyber events in his December 2025 roundup. He highlights that U.S. organizations paid more than $2.1 billion in ransomware ransom from 2022‑2024, a figure FinCEN says only scratches the surface. The...

By WeLiveSecurity
MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide
NewsDec 29, 2025

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

MongoDB disclosed a critical vulnerability (CVE‑2025‑14847, CVSS 8.7) that allows unauthenticated attackers to read server memory via a flaw in zlib compression. Over 87,000 internet‑exposed instances have been identified, with 42% of cloud environments hosting at least one vulnerable deployment. The...

By The Hacker News
Travel Plans, IoT Shelly Nirvana, Ubiquiti Security Fusion
SocialDec 28, 2025

Travel Plans, IoT Shelly Nirvana, Ubiquiti Security Fusion

Weekly update is up! Upcoming Travel; Reaching IoT Shelly Nirvana; Physical Security Meets Digital with Ubiquiti: https://www.troyhunt.com/weekly-update-484/

By Troy Hunt
SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847
PodcastDec 28, 20255 min

SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847

The episode warns that a critical MongoDB memory‑disclosure vulnerability (CVE‑2025‑14847), likened to Heartbleed, was patched on December 24 but is already being exploited in the wild. The flaw lets attackers manipulate BSON length fields to retrieve arbitrary memory, potentially exposing...

By SANS Internet StormCast
Security Leadership Master Class 7 : Contrarian Takes
BlogDec 27, 2025

Security Leadership Master Class 7 : Contrarian Takes

The final Security Leadership Master Class pivots to contrarian perspectives, exposing common cognitive traps and ritualistic practices in cybersecurity. It critiques binary thinking, where perfection is equated with success and any flaw signals failure, and highlights the rise of "ceremonial...

By Phil Venables’ Blog
The US Must Stop Underestimating Drone Warfare
NewsDec 27, 2025

The US Must Stop Underestimating Drone Warfare

The article warns that the United States is vulnerable to low‑cost commercial drone attacks, citing recent strikes by Ukraine, Israel, and Houthi rebels that demonstrated drones’ ability to hit high‑value targets far from battlefields. Despite the Pentagon’s 2025 budget allocating...

By WIRED (Security)
Mentorship & Diversity: Shaping the Next Generation of Cyber Experts
NewsDec 26, 2025

Mentorship & Diversity: Shaping the Next Generation of Cyber Experts

Patricia Voight, CISO of Webster Bank, shared her journey from telecom security to leading financial‑services cyber risk, emphasizing the sector’s constant evolution. She highlighted the bank’s mentorship and summer‑intern programs, which deliberately recruit neurodivergent talent and partner with universities. Voight...

By Dark Reading
China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware
NewsDec 26, 2025

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

Kaspersky attributes a two‑year cyber‑espionage campaign to the China‑linked APT group Evasive Panda, which used DNS‑poisoning to deliver its MgBot backdoor. The attacks, observed from November 2022 to November 2024, targeted organizations in Turkey, China and India by hijacking DNS responses for...

By The Hacker News
These Are the Cybersecurity Stories We Were Jealous of in 2025
NewsDec 26, 2025

These Are the Cybersecurity Stories We Were Jealous of in 2025

TechCrunch’s year‑end roundup spotlights the most compelling cybersecurity stories it didn’t publish in 2025, ranging from high‑profile investigations to niche technical exposés. Highlights include The Washington Post revealing a secret UK court order forcing Apple to build a backdoor, The...

By TechCrunch (Cybersecurity)
IoT Hack
BlogDec 26, 2025

IoT Hack

A recent incident aboard a Mediterranean ferry exposed a remote access tool (RAT) likely introduced via insecure IoT devices. Commentators debated whether the breach qualifies as an IoT hack, noting that shipboard entertainment, CCTV and Wi‑Fi systems often lack proper...

By Schneier on Security
Dark Reading Opens State of Application Security Survey
NewsDec 26, 2025

Dark Reading Opens State of Application Security Survey

Dark Reading has launched its 2026 State of Application Security survey, extending the 2025 study that gathered insights from over 100 cybersecurity professionals. The new questionnaire adds topics like vibe coding and secure‑coding training while retaining core questions for year‑over‑year...

By Dark Reading
How a Spanish Virus Brought Google to Málaga
NewsDec 25, 2025

How a Spanish Virus Brought Google to Málaga

Bernardo Quintero finally identified the anonymous programmer behind the 1992 Virus Málaga, a harmless malware that sparked his fascination with cybersecurity. The discovery linked the virus to Antonio Enrique Astorga, who later became a teacher and left a lasting legacy....

By TechCrunch (Cybersecurity)
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
NewsDec 25, 2025

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

In 2022 LastPass suffered a breach that exposed encrypted vault backups containing cryptocurrency private keys and seed phrases. TRM Labs now reports that weak master passwords allowed attackers to decrypt these vaults offline, siphoning roughly $35 million in crypto assets through...

By The Hacker News
Atomic-Scale Randomness in Graphene Enables Hardware-Level Security Keys
NewsDec 25, 2025

Atomic-Scale Randomness in Graphene Enables Hardware-Level Security Keys

Researchers at UIC, Wayne State and Northwestern have turned random atomic defects in graphene transistors into a physical unclonable function (PUF) for hardware security. Each transistor emits a unique radio signature that encodes its microscopic irregularities, creating a one‑of‑a‑kind cryptographic...

By Graphene-Info
Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability
NewsDec 25, 2025

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

Fortinet disclosed that CVE‑2020‑12812, a case‑sensitivity flaw in its SSL VPN, is being actively exploited in the wild. The vulnerability lets attackers bypass two‑factor authentication when local users are linked to LDAP groups and usernames are entered with different casing....

By The Hacker News
Scammers Are Recruiting.
PodcastDec 25, 202546 min

Scammers Are Recruiting.

The episode spotlights a surge in social engineering threats, beginning with a conference scam warning and a retired federal investigator's "Scammer Psychological Kill Chain" framework for detecting attacks. It highlights a 1,000% rise in job scams targeting desperate job seekers,...

By Hacking Humans
New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper
NewsDec 24, 2025

New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper

Researchers uncovered a new macOS stealer, MacSync, delivered via a digitally signed and notarized Swift application masquerading as a messenger installer. The signed DMG bypasses Apple Gatekeeper and XProtect, allowing the dropper to execute an encoded script after user interaction....

By The Hacker News
Unredaction Isn't Hacking
BlogDec 24, 2025

Unredaction Isn't Hacking

The episode explains that the so‑called "unredaction" of Jeffrey Epstein files isn’t a hack but a failure of proper redaction: the FBI merely overlaid black bars or highlights, leaving the underlying text intact and selectable. By demonstrating how text can...

By Errata Security (Robert Graham)
Industry Continues to Push Back on HIPAA Security Rule Overhaul
NewsDec 23, 2025

Industry Continues to Push Back on HIPAA Security Rule Overhaul

The U.S. Department of Health and Human Services unveiled a sweeping update to the HIPAA Security Rule in January 2025, aiming to tighten cybersecurity across hospitals and clinics. A coalition of 100 health‑care groups led by CHIME has called for...

By Dark Reading
Sprawling 'Operation Sentinel' Neutralizes African Cybercrime Syndicates
NewsDec 23, 2025

Sprawling 'Operation Sentinel' Neutralizes African Cybercrime Syndicates

Operation Sentinel, a 19‑nation Interpol‑led effort, dismantled multiple African cybercrime syndicates, arresting 574 suspects and seizing roughly $3 million in assets. The investigation neutralized over 6,000 malicious links and decrypted six ransomware strains, uncovering $21 million in losses from BEC, extortion and...

By Dark Reading
US Insurance Giant Aflac Says Hackers Stole Personal and Health Data of 22.6 Million People
NewsDec 23, 2025

US Insurance Giant Aflac Says Hackers Stole Personal and Health Data of 22.6 Million People

Aflac announced that hackers accessed personal and health information of 22.65 million customers, including Social Security numbers, medical records, and government IDs. The breach, disclosed in June, is linked to the Scattered Spider cyber‑criminal collective, which has been targeting insurers. Aflac’s...

By TechCrunch (Cybersecurity)
Inside Uzbekistan’s Nationwide License Plate Surveillance System
NewsDec 23, 2025

Inside Uzbekistan’s Nationwide License Plate Surveillance System

Uzbekistan’s Ministry of Internal Affairs operates a national license‑plate‑reading system that monitors traffic with over a hundred high‑resolution cameras across the country. Security researcher Anurag Sen uncovered that the system’s web interface is publicly accessible without authentication, exposing GPS locations...

By TechCrunch (Cybersecurity)
A Brush with Online Fraud: What Are Brushing Scams and How Do I Stay Safe?
NewsDec 23, 2025

A Brush with Online Fraud: What Are Brushing Scams and How Do I Stay Safe?

Global e‑commerce sales are set to surpass $6.4 trillion in 2025, fueling intense competition on marketplace review systems. Brushing scams exploit this pressure by sending low‑value items to random addresses, then posting fabricated 5‑star reviews to inflate product rankings. Victims often...

By WeLiveSecurity
Cybersecurity Stagnation in Healthcare: The Hidden Financial Costs
NewsDec 23, 2025

Cybersecurity Stagnation in Healthcare: The Hidden Financial Costs

Healthcare providers are confronting a stark financial reality: the cost of maintaining an immature cybersecurity program now exceeds the expense of modernizing it. Breach incidents in the sector average $11‑12 million, while prolonged outages and regulatory penalties add further strain....

By Security Magazine (Cybersecurity)
Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
NewsDec 22, 2025

Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices

WatchGuard disclosed a critical zero‑day vulnerability (CVE‑2025‑14733) in its Firebox firewalls, enabling remote code execution via an out‑of‑bounds write in the Fireware OS. The flaw affects multiple firmware versions and specifically targets the IKEv2 VPN processes, with threat actors actively...

By Dark Reading
Uzbek Users Under Attack by Android SMS-Stealers
NewsDec 22, 2025

Uzbek Users Under Attack by Android SMS-Stealers

Group‑IB reported a fresh wave of Android SMS‑stealer campaigns targeting users in Uzbekistan since October 2025. Threat groups such as TrickyWonders, Blazefang and Ajina distribute malicious APKs via sideloading and Telegram, exploiting stolen Telegram accounts to lure contacts into installation....

By Dark Reading
The EU Digital Omnibus
BlogDec 22, 2025

The EU Digital Omnibus

On 19 November 2025 the European Commission unveiled the Digital Omnibus, a package of draft laws that consolidates the EU’s fragmented digital regulatory landscape. It pairs the Data Union Strategy and a proposed European Business Wallet to boost data access for AI...

By BH Consulting Blog
Product Spotlight: 2025 Year in Review
NewsDec 22, 2025

Product Spotlight: 2025 Year in Review

The 2025 Year in Review product spotlight showcases six security‑focused solutions targeting education, enterprise, and financial sectors. Connect ONE’s ERP consolidates school data and grants first‑responder‑only access, while Genetec embeds cloud‑native audio into its Security Center SaaS for real‑time coordination....

By Security Magazine (Cybersecurity)
SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues
PodcastDec 22, 20256 min

SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues

The episode covers three security topics: TLS callbacks (Thread Local Storage) used by malware to execute code before a program's main function, a critical FreeBSD remote code execution flaw in the rtsold daemon that parses unsanitized DNS search lists from...

By SANS Internet StormCast
Hackers Stole Millions of PornHub Users’ Data for Extortion
NewsDec 20, 2025

Hackers Stole Millions of PornHub Users’ Data for Extortion

Hackers from the ShinyHunters subgroup of the Com stole more than 200 million PornHub user records and began extorting the site. At the same time, a critical Cisco AsyncOS zero‑day has been exploited since November with no patch available, threatening enterprise...

By WIRED (Security)
LongNosedGoblin Caught Snooping on Asian Governments
NewsDec 19, 2025

LongNosedGoblin Caught Snooping on Asian Governments

ESET has identified a new Chinese‑backed advanced persistent threat group, LongNosedGoblin, conducting cyber‑espionage against Japan and other Southeast Asian governments since 2023. The group leverages custom C#/.NET malware and uniquely abuses Windows Group Policy to drop payloads and move laterally...

By Dark Reading
Dismantling Defenses: Trump 2.0 Cyber Year in Review
BlogDec 19, 2025

Dismantling Defenses: Trump 2.0 Cyber Year in Review

The Trump administration’s 2025‑2026 policy agenda has dramatically reshaped U.S. cyber, privacy and law‑enforcement priorities. New directives such as NSPM‑7 and a FBI cash‑reward program broaden the definition of domestic terrorism to include political dissent, while travel‑screening rules force tourists...

By Krebs on Security
Identity Fraud Among Home-Care Workers Puts Patients at Risk
NewsDec 19, 2025

Identity Fraud Among Home-Care Workers Puts Patients at Risk

Home‑care workers are increasingly sending unqualified friends or relatives to patient visits under false identities, a trend highlighted by recent fraud convictions and court cases in the U.S. and U.K. The Department of Health and Human Services reported 298 personal‑care...

By Dark Reading
Hacks, Thefts, and Disruption: The Worst Data Breaches of 2025
NewsDec 19, 2025

Hacks, Thefts, and Disruption: The Worst Data Breaches of 2025

TechCrunch’s 2025 cyber‑horror review highlights unprecedented breaches across government, enterprise and consumer sectors. The U.S. federal system faced multiple intrusions, culminating in the DOGE operation led by Elon Musk that accessed citizen records. ransomware gang Clop exploited a zero‑day in...

By TechCrunch (Cybersecurity)
Criminal IP and Palo Alto Networks Cortex XSOAR Integrate to Bring AI-Driven Exposure Intelligence to Automated Incident Response
BlogDec 19, 2025

Criminal IP and Palo Alto Networks Cortex XSOAR Integrate to Bring AI-Driven Exposure Intelligence to Automated Incident Response

The episode announces the integration of AI‑powered threat intel platform Criminal IP into Palo Alto Networks’ Cortex XSOAR, enabling real‑time exposure intelligence and multi‑stage scanning within automated playbooks. It explains how this AI‑driven enrichment—covering IP/domain behavior, port exposure, CVE links, and SSL...

By Security Ledger
A Cybersecurity Playbook for AI Adoption
NewsDec 19, 2025

A Cybersecurity Playbook for AI Adoption

Artificial intelligence now powers 60 % of enterprise security stacks, accelerating data collection, anomaly detection, and risk scoring across the NIST CSF identify and detect functions. However, the article warns that AI’s nondeterministic nature makes it unsuitable for direct enforcement actions...

By Dark Reading
News Alert: INE Expands Partnerships to Scale Hands-On Cyber Training Across Middle East, Asia
BlogDec 19, 2025

News Alert: INE Expands Partnerships to Scale Hands-On Cyber Training Across Middle East, Asia

INE Security announced a strategic expansion across the Middle East and Asia, adding new academy partners in Saudi Arabia, the United Arab Emirates, Egypt, and other high‑growth markets. The company’s subscription‑based, hands‑on training platform—featuring unlimited virtual labs and the Skill...

By The Last Watchdog
SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog Finds JWTs
PodcastDec 19, 20254 min

SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog Finds JWTs

The episode highlights a positive trend of fewer publicly exposed industrial control system devices and a roughly 50% drop in SSL 2.0/3.0 exposure, indicating improved server hygiene. It warns about a critical, unauthenticated remote‑code‑execution flaw in Hewlett‑Packard Enterprise OneView (CVSS 10.0) that...

By SANS Internet StormCast
SonicWall Edge Access Devices Hit by Zero-Day Attacks
NewsDec 18, 2025

SonicWall Edge Access Devices Hit by Zero-Day Attacks

SonicWall disclosed a medium‑severity zero‑day vulnerability, CVE‑2025‑40602, affecting the SMA1000 access platform’s management console. The flaw, rated 6.6 CVSS, is being actively exploited in chained attacks that also leverage the critical CVE‑2025‑23006 vulnerability. SonicWall released hotfixes in firmware versions 12.4.3‑03245...

By Dark Reading
ICE Seeks Cyber Upgrade to Better Surveil and Investigate Its Employees
NewsDec 18, 2025

ICE Seeks Cyber Upgrade to Better Surveil and Investigate Its Employees

Immigration and Customs Enforcement is renewing its Cyber Defense and Intelligence Support Services contract to broaden digital surveillance of employee activity. The updated agreement mandates continuous network monitoring, automated anomaly detection, and systematic archiving of logs from servers, workstations, and...

By WIRED (Security)
Dormant Iran APT Is Still Alive, Spying on Dissidents
NewsDec 18, 2025

Dormant Iran APT Is Still Alive, Spying on Dissidents

Iran’s long‑standing state‑level threat group, known as Prince of Persia or Infy, has resurfaced after years of apparent inactivity. SafeBreach’s latest report shows the APT has been continuously spying on Iranian citizens and dissidents across Iraq, Turkey, India, Europe and...

By Dark Reading
LongNosedGoblin Tries to Sniff Out Governmental Affairs in Southeast Asia and Japan
NewsDec 18, 2025

LongNosedGoblin Tries to Sniff Out Governmental Affairs in Southeast Asia and Japan

ESET has identified a previously unknown China‑aligned advanced persistent threat (APT) group, dubbed LongNosedGoblin, targeting governmental entities in Southeast Asia and Japan. The group’s hallmark is the abuse of Windows Group Policy to distribute a suite of custom C#/.NET tools,...

By WeLiveSecurity
630M Passwords Stolen, FBI Reveals: What This Says About Credential Value
NewsDec 18, 2025

630M Passwords Stolen, FBI Reveals: What This Says About Credential Value

The FBI transferred a list of 630 million stolen credentials to Troy Hunt of Have I Been Pwned after seizing devices from a single suspect. Approximately 46 million of those passwords were new to HIBP, expanding its breach database. Security experts say...

By Security Magazine (Cybersecurity)
Trust No Link, My Darling.
PodcastDec 18, 202552 min

Trust No Link, My Darling.

The episode covers the latest social engineering threats, from AI‑driven virtual kidnapping extortion and celebrity impersonation scams to Google’s dual strategy of suing phishing operations while supporting new anti‑scam legislation and AI tools. It offers practical home‑network advice, emphasizing IoT...

By Hacking Humans
SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory
PodcastDec 18, 20256 min

SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory

The episode highlights evolving React2Shell attacks that now target less‑common endpoints and non‑Next.js applications, urging operators to assume compromise if systems remain unpatched. It also covers active exploits in Cisco Secure Email Gateway (UAT‑9686) and a SonicWall SMA1000 local privilege...

By SANS Internet StormCast
'Cellik' Android RAT Leverages Google Play Store
NewsDec 17, 2025

'Cellik' Android RAT Leverages Google Play Store

Cellik is a Remote Access Trojan offered as a service that automatically wraps malicious payloads around legitimate Android apps downloaded from the Google Play Store. The RAT provides full device control, including screen streaming, keylogging, file system access, and encrypted...

By Dark Reading
Securing the Network Edge: A Comprehensive Framework for Modern Cybersecurity
NewsDec 17, 2025

Securing the Network Edge: A Comprehensive Framework for Modern Cybersecurity

Enterprise computing is rapidly moving to the edge, with analysts forecasting more than $100 billion in annual edge spend by 2030. The proliferation of IoT, AI, 5G and data‑sovereignty mandates is pushing workloads beyond centralized clouds, creating latency, cost and compliance...

By Dark Reading
'Fake Proof' And AI Slop Hobble Defenders
NewsDec 17, 2025

'Fake Proof' And AI Slop Hobble Defenders

Exploitation attempts have surged around the React2Shell vulnerability, a CVSS 10.0 flaw in the popular React UI library. While researchers have published roughly 145 public exploits, many are AI‑generated proof‑of‑concepts that fail to trigger the flaw. These fake PoCs mislead...

By Dark Reading