December 2025

Crypto theft in 2025: North Korean hackers continue to dominate

Crypto theft in 2025: North Korean hackers continue to dominate 2025-12-18 at 17:42 By Zeljka Zorz When they strike cryptocurrency-related targets, North Korean hacking groups are increasingly aiming for large services where a single breach can move serious money, a new Chainalysis report on crypto theft in 2025 revealed. “North Korean hackers stole $2.02 billion

Crypto theft in 2025: North Korean hackers continue to dominate Read More »

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks 2025-12-18 at 17:42 By Eduard Kovacs ASRock, Asus, Gigabyte, and MSI motherboards are vulnerable to early-boot DMA attacks. The post UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks Read More »

HPE Patches Critical Flaw in IT Infrastructure Management Software

HPE Patches Critical Flaw in IT Infrastructure Management Software 2025-12-18 at 17:42 By Ionut Arghire Tracked as CVE-2025-37164, the critical flaw could allow unauthenticated, remote attackers to execute arbitrary code. The post HPE Patches Critical Flaw in IT Infrastructure Management Software appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

HPE Patches Critical Flaw in IT Infrastructure Management Software Read More »

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution 2025-12-18 at 17:42 By Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in OneView Software that, if successfully exploited, could result in remote code execution. The critical vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS score of 10.0. HPE OneView is

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution Read More »

Bitcoin hunts liquidity as US CPI inflation drops to lowest since 2021

Bitcoin hunts liquidity as US CPI inflation drops to lowest since 2021 2025-12-18 at 17:02 By Cointelegraph by William Suberg Bitcoin tagged $89,500 as US CPI data revealed sudden multiyear lows in inflation, but liquidations stayed high as the BTC price spiked. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin hunts liquidity as US CPI inflation drops to lowest since 2021 Read More »

Ethereum down 42% from all-time high: Where will ETH price bottom?

Ethereum down 42% from all-time high: Where will ETH price bottom? 2025-12-18 at 17:02 By Cointelegraph by Nancy Lubale Ethereum has dropped below $3,000 and is down 42% from its record high, prompting traders to question where the next bounce zone for the ETH price might be. This article is an excerpt from Cointelegraph.com News

Ethereum down 42% from all-time high: Where will ETH price bottom? Read More »

Another bad week for SonicWall as SMA 1000 zero-day under active exploit

Another bad week for SonicWall as SMA 1000 zero-day under active exploit 2025-12-18 at 16:59 By Carly Page Flaw in remote-access appliance lets attackers chain bugs for root-level takeover SonicWall has warned customers of a zero-day flaw in its SMA 1000 remote-access appliance that’s being actively exploited, potentially allowing attackers to escalate privileges and take

Another bad week for SonicWall as SMA 1000 zero-day under active exploit Read More »

Apiiro unveils AI SAST built on deep code analysis to eliminate false positives

Apiiro unveils AI SAST built on deep code analysis to eliminate false positives 2025-12-18 at 16:34 By Industry News Apiiro introduced Apiiro AI SAST, a new approach to static application security testing (SAST) that automates code risk detection, validation and fixes with the precision and cognitive process of an expert application security engineer. Grounded in

Apiiro unveils AI SAST built on deep code analysis to eliminate false positives Read More »

DAT longevity hinges on avoiding ‘mNAV roller coaster’: Solmate CEO

DAT longevity hinges on avoiding ‘mNAV roller coaster’: Solmate CEO 2025-12-18 at 16:12 By Cointelegraph by Gareth Jenkinson “Pure play” digital asset treasury companies will have to contend with volatility tied to the net asset value of their token holdings if they don’t build successful business ventures. This article is an excerpt from Cointelegraph.com News

DAT longevity hinges on avoiding ‘mNAV roller coaster’: Solmate CEO Read More »

FBI dismantles alleged $70M crypto laundering operation

FBI dismantles alleged $70M crypto laundering operation 2025-12-18 at 16:12 By Carly Page Justice Department claims unlicensed exchange funneled ransomware profits US feds have dismantled a crypto laundering service that they say helped cybercrooks wash tens of millions of dollars in dirty digital cash, seizing its servers and unsealing charges against an alleged Russian operator.…

FBI dismantles alleged $70M crypto laundering operation Read More »

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring 2025-12-18 at 16:12 By Help Net Security Between June 2024 and December 2025, Fortra analysts tracked a persistent business email compromise (BEC) operation that we have now classified as Scripted Sparrow. The group carries out well-crafted highly targeted phishing campaigns that masquerade as professional services firms

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring Read More »

AppGate extends zero trust to secure AI workloads with Agentic AI Core Protection

AppGate extends zero trust to secure AI workloads with Agentic AI Core Protection 2025-12-18 at 16:12 By Industry News AppGate announced the launch of Agentic AI Core Protection, a new capability within AppGate ZTNA designed to secure AI workloads deployed in enterprise core environments across on-prem and cloud venues. This innovation enables organizations to embrace

AppGate extends zero trust to secure AI workloads with Agentic AI Core Protection Read More »

Microsoft 365 users targeted in device code phishing attacks

Microsoft 365 users targeted in device code phishing attacks 2025-12-18 at 16:12 By Zeljka Zorz Attackers are targeting Microsoft 365 users with device code authorization phishing, a technique that fools users into approving access tokens, Proofpoint warns. The method abuses Microsoft’s OAuth 2.0 device authorization grant flow by presenting users with device codes that, when

Microsoft 365 users targeted in device code phishing attacks Read More »

Isaacman finally confirmed as NASA boss after Trump derailed first attempt

Isaacman finally confirmed as NASA boss after Trump derailed first attempt 2025-12-18 at 15:38 By Richard Speed Billionaire space tourist inherits troubled agency facing budget chaos, workforce cuts, and a Moon race against China NASA has a new administrator. Billionaire and space tourist Jared Isaacman was confirmed by the US Senate by a vote of

Isaacman finally confirmed as NASA boss after Trump derailed first attempt Read More »

CISA Warns of Exploited Flaw in Asus Update Tool

CISA Warns of Exploited Flaw in Asus Update Tool 2025-12-18 at 15:37 By Ionut Arghire Tracked as CVE-2025-59374, the issue is a software backdoor implanted in Asus Live Update in a supply chain attack. The post CISA Warns of Exploited Flaw in Asus Update Tool appeared first on SecurityWeek. This article is an excerpt from

CISA Warns of Exploited Flaw in Asus Update Tool Read More »

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories 2025-12-18 at 15:37 By This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories Read More »

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft 2025-12-18 at 15:37 By Threat actors with ties to the Democratic People’s Republic of Korea (DPRK or North Korea) have been instrumental in driving a surge in global cryptocurrency theft in 2025, accounting for at least $2.02 billion out of more than $3.4

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft Read More »

Scroll to Top