React2Shell vulnerability is actively exploited to deploy Linux backdoors

According to findings from Palo Alto Networks Unit 42 and NTT Security, a security vulnerability known as React2Shell is being exploited by threat actors to distribute malware families such as KSwapDoor and ZnDoor. “KSwapDoor is a professionally engineered remote access tool designed with stealth in mind,” Justin Moore, senior manager of threat intelligence research at […]

Google to end dark web monitoring tools in February 2026

December 16, 2025Ravi LakshmananDark Web / Online Safety Google announced it would retire its Dark Web Reporting tool in February 2026, less than two years after launching it as a way for users to monitor whether their personal information was found on the dark web. As a result, scanning for new dark web breaches will […]

FreePBX patches critical SQLi, file upload, and AUTHTYPE bypass flaws that enable RCE

December 15, 2025Ravi LakshmananVulnerabilities/Software Security Multiple security vulnerabilities have been disclosed in the open source private branch exchange (PBX) platform FreePBX, including a critical flaw that could lead to authentication bypass under certain configurations. The shortcomings discovered by Horizon3.ai and reported to the project administrator on September 15, 2025 are as follows: CVE-2025-61675 (CVSS Score: […]

Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More

Dec 15, 2025Ravie LakshmananHacking News / Cybersecurity If you use a smartphone, browse the web, or unzip files on your computer, you are in the crosshairs this week. Hackers are currently exploiting critical flaws in the daily software we all rely on—and in some cases, they started attacking before a fix was even ready. Below, […]

ShadyPanda Post-Campaign Browser Extension Risk Guide

In early December 2025, security researchers exposed a cybercrime campaign that had quietly taken over popular Chrome and Edge browser extensions on a large scale. A threat group called ShadyPanda spent seven years playing a long game of publishing or acquiring benign extensions, letting them run clean for years to build trust and garner millions […]

Phantom stealer spread by ISO phishing email hits Russian financial sector

December 15, 2025Ravi LakshmananMalware/Cybercrime Cybersecurity researchers have revealed details of an active phishing campaign targeting a wide range of sectors in Russia with phishing emails delivering Phantom Stealer via malicious ISO optical disk images. The operation, codenamed Operation MoneyMount-ISO by Seqrite Labs, primarily targets finance and accounting organizations, with organizations in the procurement, legal, and […]

VolkLocker ransomware exposed with hardcoded master key, allowing free decryption

December 15, 2025Ravi LakshmananRansomware/Cybercrime A pro-Russian hacktivist group known as CyberVolk (also known as GLORIAMIST) has resurfaced with a new ransomware-as-a-service (RaaS) product called VolkLocker, which allows users to decrypt files without paying extortion fees, plagued by a testing artifact implementation error. According to SentinelOne, VolkLocker (also known as CyberVolk 2.x) will appear in August […]

CISA adds actively exploited flaw in Sierra wireless routers that enables RCE attacks

December 13, 2025Ravi LakshmananNetwork security/vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity flaw affecting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog following reports of it being exploited in the wild. CVE-2018-4063 (CVSS score: 8.8/9.9) refers to an unrestricted file upload vulnerability that can be […]

Apple issues security update after two WebKit flaws found to have been exploited

December 13, 2025Ravi LakshmananZero-day/vulnerabilities Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that the company announced were being exploited in the wild. One of them is the same flaw that Google patched in Chrome earlier this week. The vulnerabilities are […]