RondoDox Botnet Exploits React2Shell Flaw to Compromise Web Servers and IoT Devices

The RondoDox botnet has been found actively exploiting a critical software vulnerability called React2Shell. This flaw affects applications built using React Server Components and Next.js, which are widely used across the internet. By abusing this weakness, attackers are able to remotely access servers without authentication. Security experts warn that the activity is ongoing and widespread. … Continued

Sanctions Lifted on Three Individuals Tied to Predator Spyware After U.S. Review

The U.S. government has lifted sanctions on three individuals previously linked to the Intellexa spyware consortium. The decision was announced in late December 2025. It reflects a change following a formal review by U.S. authorities. The update was recorded in official sanctions listings. The individuals whose sanctions were removed are Sara Hamou, Andrea Gambazzi, and … Continued

Disney to Pay $10 Million Over Children’s Online Privacy Violations

The Walt Disney Company has agreed to pay $10 million to settle a lawsuit related to children’s data privacy violations. The case was brought by U.S. government authorities. It accused Disney of allowing the collection of personal data from children without proper consent. The settlement was approved by a federal court in late December 2025. … Continued

Attackers Used 27 Malicious npm Packages to Host Phishing Pages and Steal Login Credentials

Cybersecurity researchers have uncovered a phishing campaign that abused the npm package registry to steal login credentials. The operation involved 27 malicious npm packages created specifically for phishing purposes. These packages were not designed to provide useful code to developers. Instead, they were used as hosting infrastructure for credential-stealing pages. The campaign remained active for … Continued

A Critical MongoDB Vulnerability Is Being Actively Exploited Worldwide

A critical security vulnerability affecting MongoDB has been discovered and is currently being exploited worldwide. The issue is tracked as CVE-2025-14847 and has raised serious concerns across the cybersecurity community. Experts warn that unpatched MongoDB servers are at high risk of sensitive data exposure. Organizations using MongoDB are being urged to act immediately. The vulnerability … Continued

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

A critical security vulnerability has been identified in the core component of LangChain, a popular framework used to build AI applications. The issue affects how LangChain handles serialized data in its Python implementation. Security researchers warn that the flaw could expose sensitive information. The risk is high due to LangChain’s widespread use. The vulnerability has … Continued

Trust Wallet Browser Extension Incident Exposes Risks of Crypto Supply-Chain Attacks

A major security incident has affected users of the Trust Wallet Chrome browser extension. Many users reported sudden and unauthorized withdrawals from their crypto wallets. These incidents were noticed shortly after installing a recent extension update. Security experts later confirmed that the update itself had been compromised. The issue began around December 24, when a … Continued

Newsletter line