December 2025
2,743 clustered stories from December 2025, newest first.
December 2025 — page 23
100 of 2,743
- Iranian APT UNK_SmudgedSerpent Targets US Policy Experts with Phishing Attacks
- Microsoft 365 Copilot Vulnerability Allows Data Theft via Indirect Prompt Injection
- Impact of Cyber Sanctions on Nation-State Threats Analyzed by RUSI
- CISA Issues Alert on Vulnerabilities in Samsung Mobile Devices
- WhatsApp Enumeration Flaw Leads to Largest Data Leak of 3.5 Billion Users
- Android Malware Exploits Google’s Find My Device for Remote Data Wipe
- Django Vulnerabilities Allow SQL Injection and DoS Attacks
- Vulnerabilities in GitHub Copilot and Visual Studio Enable Security Bypass
- openSUSE Ghostscript Moderate Buffer Overflow Vulnerabilities Fixed
- Google Identifies AI-Driven Malware Utilizing LLMs for Evasion
- Critical HashiCorp Vault Vulnerability Enables Authentication Bypass
- Rapid7 Q3 2025 Report Highlights Ransomware Growth and AI Weaponization
- Critical Oracle IAM Vulnerability CVE-2025-61757 Exploited
- Cogent Launches Free AI Tool for Vulnerability Management
- Jaguar Land Rover Cyber Attack Costs £200 Million
- Threat Actors Exploit JSON Storage for Malware Delivery via Trojanized Code
- Lynx Ransomware Deployed via Compromised RDP Logins with Backup Deletion
- Amazon WorkSpaces Linux Flaw Allows Credential Theft
- Co-op Plans Store Openings Amid Cyber Attack Recovery
- Australian Businesses Overconfident in Ransomware Preparedness
- Everest Ransomware Targets Petrobras, Exfiltrates 90GB of Data
- CISA Warns of Active Exploitation of Control Web Panel OS Command Injection Vulnerability
- IGT Targeted by Qilin Ransomware Group with Data Leak Claims
- Exploitation of Triofox Vulnerability CVE-2025-12480 by UNC6485 Threat Group
- Fedora Python Tool Vulnerability Alert
- Revival of 'Finger' Command in ClickFix Malware Attacks
- Fake Bitcoin Tools Distributing DarkComet RAT Malware
- Google Cloud Platform Security Vulnerabilities Disclosed
- Critical FVWM3 Vulnerability Addressed in Fedora Updates
- Cybercriminals Exploit Stolen Insurance Documents for Ransomware Attacks
- CrowdStrike Enhances Falcon Platform with New AI Agents and SOAR
- Cloudflare Experiences Major Outage Affecting X, ChatGPT, and Spotify
- KT Corp. Conceals Malware Infections Leading to Data Breach
- Critical Vulnerabilities in Rust Reqsign Affect Multiple Services
- Kraken Ransomware Emerges from HelloKitty with Advanced Techniques
- Quantum Route Redirect PhaaS Targets Microsoft 365 Users Globally
- Chinese Cyber Threat Targets Critical Australian Infrastructure
- Nation-State Hackers Breach Ribbon Communications for Months
- Checkout.com Refuses Ransom Payment After ShinyHunters Data Breach
- Emergence of New Ransomware Variants: Bactor, ChickenKiller, and Midnight
- UK Investigates Cybersecurity Risks of Chinese Electric Buses
- New Open-Source Framework Enhances LLM Security
- Critical Exploit Crashes Chromium Browsers Worldwide
- New Email Security Technique Blocks Phishing Linked to NPM Breach
- Norton Expands AI Scam Protection Globally and to New Zealand
- European Authorities Dismantle €600 Million Crypto Fraud Network
- Tenable Recognized as Leader in 2025 Gartner Magic Quadrant for Exposure Platforms
- Ransomware Groups Target Retailers During Holiday Shopping Season
- F5 Faces Revenue Impact from Nation-State Cyberattack
- Vicarius Partners with Pax8 for Vulnerability Management Solutions
- AWS Launches Security AI Agent at Re:Invent Conference
- Cisco Confirms Active Exploitation of ASA and FTD Vulnerabilities
- AGs Secure $5.1 Million from Illuminate Education for Data Protection Failures
- New .NET Malware Hides Lokibot in PNG/BMP Files to Evade Detection
- Using KQL for Audit Log Analysis in Entra ID
- Seven Critical QNAP Zero-Day Vulnerabilities Fixed
- Ransomware Gangs Target AWS S3 Buckets with Evolving Tactics
- Waymo Expands Robotaxi Services to New Cities and Removes Safety Drivers
- Exploitation of Windows Server Update Services Flaw Leads to Data Theft
- Warlock Ransomware Exploits ToolShell SharePoint Vulnerabilities
- Amendment 13 Enhances Data Security Enforcement in Israel
- Debian APT to Require Rust Starting May 2026
- Marks & Spencer Suffers Major Profit Loss Due to Cyber Attack
- Zoom Workplace Vulnerability Allows Privilege Escalation on Windows Systems
- ClickFix Attack Utilizes Weaponized Videos for User Manipulation
- ToddyCat APT Compromises Internal Communications in Targeted Organizations
- Tenda N300 Vulnerabilities Enable Root Command Execution by Attackers
- APT35 Internal Documents Leak Reveals Targets and Attack Methods
- Kingfisher Rejects SAP's ERP Upgrade Strategy
- Zoom Workplace for Windows Vulnerability Enables Privilege Escalation
- EVALUSION and SmartApeSG Campaigns Deploy Amatera Stealer and NetSupport RAT via ClickFix
- ClickFix Malware Campaign Uses Fake Windows Updates to Deploy Infostealers
- Raptor Vulnerabilities Lead to Denial of Service Risks
- Arrest of Meduza Stealer Developers in Russia Following Government Hack
- Widespread Exploitation of XWiki Vulnerability by Threat Actors
- Microsoft Update Health Tools Vulnerability Enables Remote Code Execution
- AI-Enabled Intrusions Linked to China's APT Ecosystem
- Humanitarian Crisis and Trafficking in Central Africa
- Windows 11 Introduces 'Ask Copilot' Feature in Latest Insider Build
- Trump Administration Pushes for Federal AI Regulation Over State Laws
- Protei Hacked: Data Stolen and Website Defaced
- State Websites Breached in Zero-Day Attack, No Data Compromised
- Marks & Spencer Plans 500 New Food Stores After £324m Cyber Attack
- Anthropic Report on AI Attack Agents and Cyberattack Dynamics
- 50,000 Hospital CCTV Footage Hacked and Sold Online in India
- Nova Stealer Malware Targets macOS Users to Steal Cryptocurrency Wallets
- HackGPT: AI-Powered Penetration Testing Platform Integrates GPT
- Critical Vulnerability in .NET 8.0 and Updates for .NET 9.0 and 10.0
- San Joaquin County Superior Court Data Breach Exposes Sensitive Information
- Tsundere Botnet Exploits Node.js and Blockchain for Multi-OS Attacks
- Airstalk Malware Exploits AirWatch MDM for Covert C2 Communication
- Cline Bot AI Agent Exposed to Data Theft and Code Execution Vulnerabilities
- Microsoft Fixes Long-Standing 'Update and Shut Down' Bug in Windows 11
- Critical DoS Vulnerability in ImageMagick Affects Multiple Ubuntu Releases
- Massive Surge in Malicious Android Apps Targeting Indian Users
- Emergence of Tsundere Botnet Targeting Windows Users
- SesameOp Backdoor Exploits OpenAI API for Covert Cyber Operations
- Cavalry Werewolf Backdoor Attack on Government Networks
- Cybercriminals to Weaponize AI and Exploit Open-Source Risks in 2026
- 2.3 Million Attacks Target Palo Alto Networks' GlobalProtect VPN Portals