Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More

Dec 15, 2025Ravie LakshmananHacking News / Cybersecurity If you use a smartphone, browse the web, or unzip files on your computer, you are in the crosshairs this week. Hackers are currently exploiting critical flaws in the daily software we all rely on—and in some cases, they started attacking before a fix was even ready. Below, […]
ShadyPanda Post-Campaign Browser Extension Risk Guide

In early December 2025, security researchers exposed a cybercrime campaign that had quietly taken over popular Chrome and Edge browser extensions on a large scale. A threat group called ShadyPanda spent seven years playing a long game of publishing or acquiring benign extensions, letting them run clean for years to build trust and garner millions […]
Phantom stealer spread by ISO phishing email hits Russian financial sector

December 15, 2025Ravi LakshmananMalware/Cybercrime Cybersecurity researchers have revealed details of an active phishing campaign targeting a wide range of sectors in Russia with phishing emails delivering Phantom Stealer via malicious ISO optical disk images. The operation, codenamed Operation MoneyMount-ISO by Seqrite Labs, primarily targets finance and accounting organizations, with organizations in the procurement, legal, and […]
VolkLocker ransomware exposed with hardcoded master key, allowing free decryption

December 15, 2025Ravi LakshmananRansomware/Cybercrime A pro-Russian hacktivist group known as CyberVolk (also known as GLORIAMIST) has resurfaced with a new ransomware-as-a-service (RaaS) product called VolkLocker, which allows users to decrypt files without paying extortion fees, plagued by a testing artifact implementation error. According to SentinelOne, VolkLocker (also known as CyberVolk 2.x) will appear in August […]
CISA adds actively exploited flaw in Sierra wireless routers that enables RCE attacks

December 13, 2025Ravi LakshmananNetwork security/vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity flaw affecting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog following reports of it being exploited in the wild. CVE-2018-4063 (CVSS score: 8.8/9.9) refers to an unrestricted file upload vulnerability that can be […]
Apple issues security update after two WebKit flaws found to have been exploited

December 13, 2025Ravi LakshmananZero-day/vulnerabilities Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that the company announced were being exploited in the wild. One of them is the same flaw that Google patched in Chrome earlier this week. The vulnerabilities are […]
Fake OSINT and GPT utility GitHub repositories spread PyStoreRAT malware payload

Cybersecurity researchers are calling attention to a new campaign that leverages Python repositories hosted on GitHub to distribute a previously undocumented JavaScript-based remote access Trojan (RAT) called PyStoreRAT. “These repositories, often themed around development utilities or OSINT tools, contain just a few lines of code responsible for silently downloading a remote HTA file and running […]
New advanced phishing kit uses AI and MFA bypass tactics to steal credentials at scale

Cybersecurity researchers have documented four new phishing kits named BlackForce, GhostFrame, InboxPrime AI, and Spiderman that can facilitate large-scale credential theft. First detected in August 2025, BlackForce is designed to steal credentials and perform Man-in-the-Browser (MitB) attacks to capture one-time passwords (OTPs) and bypass multi-factor authentication (MFA). The kit is being sold on Telegram forums […]
Policies, isolation, and data controls that actually work

Browsers are the primary interface to GenAI for most enterprises, from web-based LLM and CoPilot to GenAI-powered extensions and agent browsers like ChatGPT Atlas. Employees leverage GenAI’s capabilities to draft emails, summarize documents, work with code, and analyze data by copying/pasting sensitive information directly into prompts or uploading files. Traditional security controls were not designed […]
New React RSC vulnerability allows DoS and source code disclosure

December 12, 2025Ravi LakshmananSoftware security/vulnerabilities The React team has released fixes for two new types of defects in React Server Components (RSC). Successful exploitation may lead to a denial of service (DoS) or source code disclosure. According to the team, this issue was discovered by the security community while attempting to exploit a patch released […]