MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More

Dec 29, 2026Ravie LakshmananHacking News / Cybersecurity Last week’s cyber news in 2025 was not about one big incident. It was about many small cracks opening at the same time. Tools people trust every day behave in unexpected ways. Old flaws resurfaced. New ones were used almost immediately. A common theme ran through it all […]
27 malicious npm packages used as phishing infrastructure to steal login credentials

Cybersecurity researchers have revealed details of what they say is a “persistent and targeted” spear-phishing campaign that published more than 20 packages in the npm registry to facilitate credential theft. According to Socket, the activity uploaded 27 npm packages from six different npm aliases and primarily targeted sales and sales personnel at organizations adjacent to […]
MongoDB vulnerability CVE-2025-14847 is being actively exploited worldwide

December 29, 2026Ravi LakshmananDatabase security/vulnerabilities A recently disclosed security vulnerability in MongoDB has been exploited in the wild, with over 87,000 potentially vulnerable instances identified worldwide. The vulnerability in question, CVE-2025-14847 (CVSS score: 8.7), could allow an unauthenticated remote attacker to leak sensitive data from the memory of a MongoDB server. The code name is […]
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In August 2025, malicious Nx packages leaked 2,349 GitHub, cloud, and AI credentials. Throughout 2024, ChatGPT vulnerabilities allowed unauthorized extraction of user data from AI memory. The result: 23.77 million secrets were leaked through AI […]
New flaw in MongoDB allows unauthenticated attacker to read uninitialized memory

December 27, 2025Ravi LakshmananDatabase security/vulnerabilities A high-severity security flaw has been identified in MongoDB that could allow an unauthenticated user to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), is described as a case of improper handling of length parameter mismatch. Length parameter mismatch occurs when a program fails to adequately […]
Trust Wallet Chrome Extension Compromise Causes $7M in Cryptocurrency Loss due to Malicious Code

December 26, 2025Ravi LakshmananCryptocurrency/Incident Response TrustWallet is urging users to update their Google Chrome extension to the latest version following what it calls a “security incident” that resulted in approximately $7 million in losses. The issue affects version 2.68, according to the multichain non-custodial cryptocurrency wallet service. According to the Chrome Web Store listing, the […]
China-linked evasive panda runs DNS poisoning campaign delivering MgBot malware

A China-linked Advanced Persistent Threat (APT) group has been implicated in targeted cyber espionage operations. In this campaign, adversaries compromised domain name systems (DNS) and requested delivery of its signature MgBot backdoor in attacks targeting victims in Turkiye, China, and India. Kaspersky said the activity was observed from November 2022 to November 2024. The activity […]
Critical vulnerability in LangChain core exposes secrets via serialization injection

December 26, 2025Ravi LakshmananAI Security / DevSecOps A critical security flaw has been revealed in LangChain Core. It can also be exploited by an attacker to steal sensitive secrets and influence large-scale language model (LLM) responses through prompt injection. LangChain Core (i.e. langchain-core) is a core Python package that is part of the LangChain ecosystem […]
Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories

Dec 25, 2025Ravie LakshmananCybersecurity / Hacking News It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — they’re blending in, hijacking everyday tools, trusted apps, and even AI assistants. What used to feel like clear-cut “hacker stories” now looks more like a mirror of […]
LastPass 2022 breach led to years of crypto theft, TRM Institute finds

December 25, 2025Ravi LakshmananData breach/financial crime Encrypted vault backups stolen in the 2022 LastPass data breach allowed attackers to exploit weak master passwords to crack passwords and exfiltrate cryptocurrency assets, according to new research from TRM Labs. The blockchain intelligence firm said there is evidence that Russian cybercriminals are involved in this activity, and that […]