Disney to Pay $10 Million Over Children’s Online Privacy Violations

The Walt Disney Company has agreed to pay $10 million to settle a lawsuit related to children’s data privacy violations. The case was brought by U.S. government authorities. It accused Disney of allowing the collection of personal data from children without proper consent. The settlement was approved by a federal court in late December 2025. … Continued

Attackers Used 27 Malicious npm Packages to Host Phishing Pages and Steal Login Credentials

Cybersecurity researchers have uncovered a phishing campaign that abused the npm package registry to steal login credentials. The operation involved 27 malicious npm packages created specifically for phishing purposes. These packages were not designed to provide useful code to developers. Instead, they were used as hosting infrastructure for credential-stealing pages. The campaign remained active for … Continued

A Critical MongoDB Vulnerability Is Being Actively Exploited Worldwide

A critical security vulnerability affecting MongoDB has been discovered and is currently being exploited worldwide. The issue is tracked as CVE-2025-14847 and has raised serious concerns across the cybersecurity community. Experts warn that unpatched MongoDB servers are at high risk of sensitive data exposure. Organizations using MongoDB are being urged to act immediately. The vulnerability … Continued

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

A critical security vulnerability has been identified in the core component of LangChain, a popular framework used to build AI applications. The issue affects how LangChain handles serialized data in its Python implementation. Security researchers warn that the flaw could expose sensitive information. The risk is high due to LangChain’s widespread use. The vulnerability has … Continued

Trust Wallet Browser Extension Incident Exposes Risks of Crypto Supply-Chain Attacks

A major security incident has affected users of the Trust Wallet Chrome browser extension. Many users reported sudden and unauthorized withdrawals from their crypto wallets. These incidents were noticed shortly after installing a recent extension update. Security experts later confirmed that the update itself had been compromised. The issue began around December 24, when a … Continued

ServiceNow to Acquire OT Security Firm Armis in $7.75 Billion All-Cash Deal

ServiceNow has announced that it will acquire Armis, a specialist in operational technology (OT) and connected-device security. The deal is valued at $7.75 billion and will be paid fully in cash. This is the largest acquisition ServiceNow has made so far. The move signals a stronger push by the company into the cybersecurity space. The … Continued

Italy Has Fined Apple $116 Million for How It Applied App Store Privacy Policies

Italy’s competition authority has fined Apple €98.6 million, or about $116 million, over how it applied privacy rules in its App Store. The decision follows an investigation into Apple’s App Tracking Transparency system. Regulators said Apple’s actions affected competition in the mobile app market. The fine was announced in December 2025. The case centers on … Continued

Newsletter line