React2Shell exploit escalates into massive global attack, forcing emergency mitigation

December 12, 2025Ravi LakshmananVulnerability/Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to patch recent vulnerabilities in React2Shell by December 12, 2025, amid reports of widespread exploitation. This critical vulnerability is tracked as CVE-2025-55182 (CVSS score: 10.0) and affects the React Server Components (RSC) Flight protocol. The root cause of […]
CISA reports actively exploited GeoServer XXE flaw in updated KEV catalog

December 12, 2025Ravi LakshmananVulnerabilities / Server Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw affecting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of real-world exploitation. The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an unauthenticated XML external entity (XXE) flaw that […]
Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More Stories

Dec 11, 2025Ravie Lakshmanan This week’s cyber stories show how fast the online world can turn risky. Hackers are sneaking malware into movie downloads, browser add-ons, and even software updates people trust. Tech giants and governments are racing to plug new holes while arguing over privacy and control. And researchers keep uncovering just how much […]
NANOREMOTE malware uses Google Drive API for hidden controls on Windows systems

December 11, 2025Ravi LakshmananCyber Spy / Windows Security Cybersecurity researchers have revealed details of a new full-featured Windows backdoor called NANOREMOTE that uses the Google Drive API for command and control (C2) purposes. According to a report by Elastic Security Labs, the malware shares code similarities with another implant codenamed FINALDRAFT (also known as Squidoor) […]
The impact of robotic process automation (RPA) on identity and access management

December 11, 2025hacker newsAutomation/Compliance As companies refine their strategies for handling non-human identifiers (NHI), robotic process automation (RPA) has become a powerful tool for streamlining operations and increasing security. However, RPA bots have different levels of access to sensitive information, so businesses should be prepared to mitigate different challenges. Bots are beginning to outnumber human […]
WIRTE uses AshenLoader sideloading to install AshTag spy backdoor

December 11, 2025Ravi LakshmananCyberwarfare/Threat Intelligence The Advanced Persistent Threat (APT), known as WIRTE, is believed to be the result of attacks targeting government and diplomatic organizations across the Middle East since 2020 using a previously undocumented malware suite called AshTag. Palo Alto Networks is tracking an activity cluster named Ashen Lepus. Artifacts uploaded to the […]
Unpatched Gog exploits zero-day in over 700 instances in active attack

December 11, 2025Ravi LakshmananVulnerability / Cloud Security New research from Wiz reveals that Gogs is actively exploiting unpatched high-severity security vulnerabilities, with over 700 compromised instances accessible over the internet. This flaw, tracked as CVE-2025-8110 (CVSS score: 8.7), is a case of file overwriting in the file update API of a Go-based self-hosted Git service. […]
Chrome targeted by active field exploit related to undisclosed high-severity flaw

December 11, 2025Ravi LakshmananZero-day/vulnerabilities Google shipped a security update for its Chrome browser on Wednesday that addressed three security flaws, including one it announced was being exploited in the wild. This vulnerability is rated as High Severity and is tracked under Chromium issue tracking ID 466192044. Unlike other disclosures, Google has chosen to keep information […]
Active attack exploits Gladinet’s hard-coded keys to gain unauthorized access and code execution

December 11, 2025Ravi LakshmananVulnerabilities/Encryption Huntress warns that a new vulnerability in Gladinet’s CentreStack and Triofox products due to the use of hard-coded encryption keys is being actively exploited, affecting nine organizations so far. “An attacker could exploit this as a way to access the web.config file, potentially opening the door to deserialization and remote code […]
React2Shell exploit delivers crypto miners and new malware across multiple sectors

React2Shell continues to see heavy exploitation, with threat actors leveraging the highest severity security flaws in React Server Components (RSC) to deliver cryptocurrency miners and a range of previously undocumented malware families, according to new research from Huntress. This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel called CowTunnel, and a Go-based post-exploitation […]