The impact of robotic process automation (RPA) on identity and access management

December 11, 2025hacker newsAutomation/Compliance As companies refine their strategies for handling non-human identifiers (NHI), robotic process automation (RPA) has become a powerful tool for streamlining operations and increasing security. However, RPA bots have different levels of access to sensitive information, so businesses should be prepared to mitigate different challenges. Bots are beginning to outnumber human […]

Port raises $100M at $800M valuation to take on Spotify’s Backstage

Spotify may be synonymous with music streaming, but it also has a sideline in a hugely popular developer tool called “Backstage.” Backstage is an open source project that helps companies build their own internal developer portals. A catalog of developer tools and an easy visualization of the work they did and other metrics. However, like […]

WIRTE uses AshenLoader sideloading to install AshTag spy backdoor

December 11, 2025Ravi LakshmananCyberwarfare/Threat Intelligence The Advanced Persistent Threat (APT), known as WIRTE, is believed to be the result of attacks targeting government and diplomatic organizations across the Middle East since 2020 using a previously undocumented malware suite called AshTag. Palo Alto Networks is tracking an activity cluster named Ashen Lepus. Artifacts uploaded to the […]

Winter Solstice 2025: The Ultimate Guide to the Shortest Day of the Year

When is winter? Forecasters in the Northern Hemisphere report what is known as meteorological winter from December 1st to the end of February. However, based on the Earth’s tilt and orbit around the sun, it will be from December 21, 2025 to March 20, 2026. This is an astronomical winter, beginning at the winter solstice, […]

Unpatched Gog exploits zero-day in over 700 instances in active attack

December 11, 2025Ravi LakshmananVulnerability / Cloud Security New research from Wiz reveals that Gogs is actively exploiting unpatched high-severity security vulnerabilities, with over 700 compromised instances accessible over the internet. This flaw, tracked as CVE-2025-8110 (CVSS score: 8.7), is a case of file overwriting in the file update API of a Go-based self-hosted Git service. […]

Chrome targeted by active field exploit related to undisclosed high-severity flaw

December 11, 2025Ravi LakshmananZero-day/vulnerabilities Google shipped a security update for its Chrome browser on Wednesday that addressed three security flaws, including one it announced was being exploited in the wild. This vulnerability is rated as High Severity and is tracked under Chromium issue tracking ID 466192044. Unlike other disclosures, Google has chosen to keep information […]

Active attack exploits Gladinet’s hard-coded keys to gain unauthorized access and code execution

December 11, 2025Ravi LakshmananVulnerabilities/Encryption Huntress warns that a new vulnerability in Gladinet’s CentreStack and Triofox products due to the use of hard-coded encryption keys is being actively exploited, affecting nine organizations so far. “An attacker could exploit this as a way to access the web.config file, potentially opening the door to deserialization and remote code […]