New Shai-Hulud Malware Variant Signals Supply-Chain Attack Experimentation

Cybersecurity researchers have identified a modified and highly obfuscated version of the Shai-Hulud malware. The discovery suggests that threat actors are actively experimenting with changes to the malware rather than launching a large-scale attack. The activity appears controlled and deliberate, indicating a testing phase. Experts believe this could be preparation for more advanced campaigns. The … Continued

Attackers Exploit Google Cloud Email Automation in Sophisticated Phishing Campaign

Cybersecurity researchers have uncovered a new phishing campaign where attackers abused a legitimate Google Cloud email feature to trick users. Instead of hacking Google directly, the criminals misused an official automation service to send emails that appeared genuine. Because the messages came from a trusted Google-related address, many recipients did not suspect anything unusual. This … Continued

RondoDox Botnet Exploits React2Shell Flaw to Compromise Web Servers and IoT Devices

The RondoDox botnet has been found actively exploiting a critical software vulnerability called React2Shell. This flaw affects applications built using React Server Components and Next.js, which are widely used across the internet. By abusing this weakness, attackers are able to remotely access servers without authentication. Security experts warn that the activity is ongoing and widespread. … Continued

Sanctions Lifted on Three Individuals Tied to Predator Spyware After U.S. Review

The U.S. government has lifted sanctions on three individuals previously linked to the Intellexa spyware consortium. The decision was announced in late December 2025. It reflects a change following a formal review by U.S. authorities. The update was recorded in official sanctions listings. The individuals whose sanctions were removed are Sara Hamou, Andrea Gambazzi, and … Continued

Disney to Pay $10 Million Over Children’s Online Privacy Violations

The Walt Disney Company has agreed to pay $10 million to settle a lawsuit related to children’s data privacy violations. The case was brought by U.S. government authorities. It accused Disney of allowing the collection of personal data from children without proper consent. The settlement was approved by a federal court in late December 2025. … Continued

Attackers Used 27 Malicious npm Packages to Host Phishing Pages and Steal Login Credentials

Cybersecurity researchers have uncovered a phishing campaign that abused the npm package registry to steal login credentials. The operation involved 27 malicious npm packages created specifically for phishing purposes. These packages were not designed to provide useful code to developers. Instead, they were used as hosting infrastructure for credential-stealing pages. The campaign remained active for … Continued

A Critical MongoDB Vulnerability Is Being Actively Exploited Worldwide

A critical security vulnerability affecting MongoDB has been discovered and is currently being exploited worldwide. The issue is tracked as CVE-2025-14847 and has raised serious concerns across the cybersecurity community. Experts warn that unpatched MongoDB servers are at high risk of sensitive data exposure. Organizations using MongoDB are being urged to act immediately. The vulnerability … Continued

Newsletter line