China-aligned threat group uses Windows Group Policy to deploy espionage malware

December 18, 2025Ravi LakshmananMalware/Cloud Security A previously undocumented Chinese-aligned threat cluster called “LongNosed Goblin” is believed to have resulted from a series of cyberattacks targeting government agencies in Southeast Asia and Japan. Slovak cybersecurity company ESET said in a report released today that the ultimate goal of these attacks is cyber espionage. The threat activity […]

UK NHS technology provider confirms data breach

DXS International, a UK-based company that provides healthcare technology to the UK National Health Service (NHS), disclosed the cyberattack in a statement on Thursday. In a filing to the London Stock Exchange, the company said it had experienced a “security incident impacting its office servers” that was discovered on December 14. The company said it […]

Rivian rolls out new “universal hands-free” driving feature

Rivian’s new second-generation R1 EV receives an update today that introduces new “universal hands-free” driving software. This was announced by the company last week at its first Autonomy & AI Day. The company says this new feature allows drivers to take their hands off the wheel on more than 3.5 million miles of roadways in […]

HPE OneView flaw assessed CVSS 10.0 allows unauthenticated remote code execution

December 18, 2025Ravi LakshmananVulnerabilities / Enterprise Security Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in its OneView software that could allow remote code execution if successfully exploited. This critical vulnerability has been assigned CVE identifier CVE-2025-37164 and has a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that […]

Vibe coding startup Lovable raises $330 million at $6.6 billion valuation

Swedish vibecoding startup Lovable has more than tripled its valuation in just five months. Stockholm-based Lovable announced Thursday that it has raised $330 million in a Series B funding round led by CapitalG and Menlo Ventures at a valuation of $6.6 billion. Khosla Ventures, Salesforce Ventures, and Databricks Ventures also participated, as well as other […]

WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

Dec 18, 2025Ravie LakshmananCybersecurity / Hacking News This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting infrastructures to clever social hooks, the week’s […]

Dynamic AI-SaaS security case study as co-pilot scales

Over the past year, artificial intelligence co-pilots and agents have quietly infiltrated the SaaS applications that enterprises use every day. Tools like Zoom, Slack, Microsoft 365, Salesforce, and ServiceNow have built-in AI assistant or agent-like features. Virtually all major SaaS vendors are rushing to incorporate AI into their products. The result is an explosion of […]