5 threats that reshaped web security this year [2025]

As 2025 draws to a close, security professionals are faced with the sobering realization that traditional strategies for web security are dangerously outdated. AI-powered attacks, evolving injection techniques, and supply chain breaches affecting hundreds of thousands of websites have required a fundamental rethink of defense strategies. Here are five threats that reshaped web security this […]
GoldFactory hits Southeast Asia with modified banking app, infecting over 11,000 people

Cybercriminals associated with a financially motivated group known as GoldFactory have been observed launching new attacks targeting mobile users in Indonesia, Thailand, and Vietnam by impersonating government services. The activity, which has been observed since October 2024, involves the distribution of modified banking applications that act as a conduit for Android malware, Group-IB said in […]
Recorded 29.7 Tbps DDoS attack linked to AISURU botnet, infected up to 4 million hosts

December 4, 2025Ravi LakshmananDDoS attack/network security Cloudflare announced Wednesday that it detected and mitigated the largest distributed denial of service (DDoS) attack in history, reaching 29.7 terabits per second (Tbps). The web infrastructure and security company said the activity originated from a rental DDoS botnet known as AISURU, which has been linked to numerous high-volume […]
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

December 3, 2025Ravi LakshmananVulnerability / Cloud Security A maximum severity security flaw has been disclosed in React Server Components (RSC) that could allow remote code execution if successfully exploited. This vulnerability is tracked as CVE-2025-55182 and has a CVSS score of 10.0. The React team said in an alert issued today that this allows for […]
Microsoft silently patches Windows LNK flaw after years of active exploitation

December 3, 2025Ravi LakshmananVulnerabilities / Endpoint Security According to ACROS Security’s 0patch, Microsoft silently embedded a security flaw that has been exploited by multiple attackers since 2017 as part of the company’s November 2025 Patch Tuesday update. The vulnerability in question is CVE-2025-9491 (CVSS score: 7.8/7.0), which is described as a Windows Shortcuts (LNK) file […]
WordPress King add-on flaw under active attack allows hackers to create administrator accounts

December 3, 2025Ravi LakshmananVulnerabilities / Website Security A critical security flaw affecting a WordPress plugin known as King Addons for Elementor is being exploited in the wild. This vulnerability, CVE-2025-8489 (CVSS score: 9.8), is a privilege escalation case that allows an unauthenticated attacker to grant themselves administrative privileges by simply specifying the administrator user role […]
Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Scam

The threat actor known as Water Saci is actively evolving its tactics, switching to sophisticated, highly layered infection chains that use HTML application (HTA) files and PDFs to propagate a worm that deploys a banking Trojan via WhatsApp in attacks targeting users in Brazil. The latest wave is characterized by attackers moving from PowerShell to […]
Discover the AI tools that will fuel the next cybercrime wave — watch the webinar

December 3, 2025hacker newsCybercrime/Artificial Intelligence Remember when phishing emails were easy to spot? Bad grammar, weird formatting, and a request from a “prince” in a faraway land? Those days are over. Today, a 16-year-old with zero coding skills and $200 in pocket money can launch a campaign that rivals state-sponsored hackers. They don’t have to […]
Turn disruptive technologies into strategic advantages

Most people know the story of Paul Bunyan. Challenges from a giant lumberjack, his trusty axe, and a machine that promises to outdo him. Paul strained and swung harder the way he had before, but still lost a quarter of an inch. His mistake was not losing the contest. His mistake was believing that he […]
Picklescan bug could allow malicious PyTorch models to bypass scanning and execute code

December 3, 2025Ravi LakshmananMachine learning/vulnerabilities Three serious security flaws have been revealed in an open source utility called Picklescan. This flaw could allow a malicious attacker to load an untrusted PyTorch model and execute arbitrary code, effectively bypassing the tool’s protections. Picklescan, developed and maintained by Matthieu Maitre (@mmaitre314), is a security scanner designed to […]