React2Shell critical flaw added to CISA KEV after active exploitation

December 6, 2025Ravi LakshmananVulnerability/patch management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday officially added a critical security flaw affecting React Server Components (RSC) to its Known Exploited Vulnerabilities (KEV) catalog following reports of it being exploited in the wild. This vulnerability, CVE-2025-55182 (CVSS score: 10.0), is related to remote code execution by […]
Zero-click agent browser attack could delete entire Google Drive using crafted email

December 5, 2025Ravi LakshmananEmail Security/Threat Investigation New agent browser attack targeting Perplexity’s Comet browser. A seemingly innocuous email can be turned into a destructive action that erases the entire contents of a user’s Google Drive, research from Striker STAR Labs reveals. Zero-click Google Drive wiper technology is all about automating everyday tasks by connecting your […]
Critical XXE bug CVE-2025-66516 (CVSS 10.0) in Apache Tika, urgent patch required

December 5, 2025Ravi LakshmananApplication security/vulnerabilities A critical security flaw has been disclosed in Apache Tika that could lead to an XML External Entity (XXE) injection attack. This vulnerability is tracked as CVE-2025-66516 and is rated 10.0 on the CVSS scoring scale, indicating maximum severity. According to the vulnerability advisory, “A critical XXE in the Apache […]
Chinese hackers have begun exploiting newly disclosed React2Shell vulnerabilities

December 5, 2025Ravi LakshmananVulnerabilities/Software Security Two Chinese-linked hacker groups were observed weaponizing a newly revealed security flaw in React Server Components (RSC) within hours of it becoming public knowledge. The vulnerability in question is CVE-2025-55182 (CVSS score: 10.0), also known as React2Shell, which allows unauthenticated remote code execution. This issue is addressed in React versions […]
Intellexa leak reveals zero-day and ad-based vectors for Predator spyware distribution

A human rights lawyer in Pakistan’s Balochistan province received a suspicious link on WhatsApp from an unknown number, marking the first time a member of the country’s civil society has been targeted by Intellexa’s Predator spyware, Amnesty International said in a report. The nonprofit said the link was a “predator attack attempt based on the […]
Anti-sales guide for MSPs

Most MSPs and MSSPs know how to provide effective security. The challenge is to help prospects understand why it’s important from a business perspective. Sales conversations often stall because prospects are overwhelmed, skeptical, or fed up with fear-based messages. That’s why we created “Getting to Yes”: An anti-sales guide for MSPs. This guide helps service […]
CISA reports Chinese hackers are using BRICKSTORM for long-term access to US systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday released details of a backdoor called BRICKSTORM that state-sponsored attackers from the People’s Republic of China (PRC) are using to maintain compromised systems for extended periods of time. “BRICKSTORM is an advanced backdoor for VMware vSphere and Windows environments,” the agency said. “BRICKSTORM enables cyber […]
JPCERT confirms active command injection attack against Array AG Gateway

December 5, 2025Ravi LakshmananVulnerability/Network Security A command injection vulnerability in Array Networks AG series secure access gateways has been exploited since August 2025, according to an alert issued by JPCERT/CC this week. This vulnerability, which does not have a CVE identifier, was resolved by the company on May 11, 2025. The vulnerability is rooted in […]
Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

A threat actor known as Silver Fox was discovered to be orchestrating false flag operations that mimic Russian threat groups in attacks targeting Chinese organizations. Search Engine Optimization (SEO) poisoning campaigns use Microsoft Teams lures to trick unsuspecting users into downloading malicious setup files, which lead to the deployment of ValleyRAT (Winos 4.0), a known […]
Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories

Dec 04, 2025Ravie LakshmananCybersecurity / Hacking News Think your Wi-Fi is safe? Your coding tools? Or even your favorite financial apps? This week proves again how hackers, companies, and governments are all locked in a nonstop race to outsmart each other. Here’s a quick rundown of the latest cyber stories that show how fast the […]