SecurityTicks

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery 2025-12-15 at 16:01 By Eduard Kovacs Google has also mentioned seeing React2Shell attacks conducted by Iranian threat actors. The post Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery Read More »

Roomba maker iRobot gets cleaned out in Chapter 11

Roomba maker iRobot gets cleaned out in Chapter 11 2025-12-15 at 15:06 By Connor Jones Company vacuumed up by its own manufacturer iRobit, the company behind autonomous vacuum cleaner brand Roomba, has filed for Chapter 11 bankruptcy protection, telling investors that its Chinese manufacturer will assume control going forward.… This article is an excerpt from

Roomba maker iRobot gets cleaned out in Chapter 11 Read More »

Delay to European Central Bank messaging project cost the Bank of England £23M

Delay to European Central Bank messaging project cost the Bank of England £23M 2025-12-15 at 15:06 By Lindsay Clark Watchdog links schedule change to replanning of UK payments system overhaul The European Central Bank’s (ECB) decision to delay its move to a new messaging standard in 2022 ended up costing the Bank of England £23

Delay to European Central Bank messaging project cost the Bank of England £23M Read More »

⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More

⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More 2025-12-15 at 14:37 By If you use a smartphone, browse the web, or unzip files on your computer, you are in the crosshairs this week. Hackers are currently exploiting critical flaws in the daily software we all rely on—and in

⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More Read More »

A Browser Extension Risk Guide After the ShadyPanda Campaign

A Browser Extension Risk Guide After the ShadyPanda Campaign 2025-12-15 at 14:37 By In early December 2025, security researchers exposed a cybercrime campaign that had quietly hijacked popular Chrome and Edge browser extensions on a massive scale. A threat group dubbed ShadyPanda spent seven years playing the long game, publishing or acquiring harmless extensions, letting

A Browser Extension Risk Guide After the ShadyPanda Campaign Read More »

Soverli Raises $2.6 Million for Secure Smartphone OS

Soverli Raises $2.6 Million for Secure Smartphone OS 2025-12-15 at 14:02 By Ionut Arghire The sovereign smartphone OS runs along Android or iOS, allowing users to switch between secure, isolated environments. The post Soverli Raises $2.6 Million for Secure Smartphone OS appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Soverli Raises $2.6 Million for Secure Smartphone OS Read More »

Legal protection for ethical hacking under Computer Misuse Act is only the first step

Legal protection for ethical hacking under Computer Misuse Act is only the first step 2025-12-15 at 13:48 By Rupert Goodwins I’m dreaming of a white hat mass Opinion  It was 40 years ago that four young British hackers set about changing the law, although they didn’t know it at the time. It was a cross-platform

Legal protection for ethical hacking under Computer Misuse Act is only the first step Read More »

Threat Intelligence News from LevelBlue SpiderLabs December 2025

Threat Intelligence News from LevelBlue SpiderLabs December 2025 2025-12-15 at 13:48 By LevelBlue SpiderLabs is the threat intelligence unit of LevelBlue and includes a global team of threat researchers and data scientists who, combined with proprietary technology in data analytics and machine learning (ML), analyze one of the largest and most diverse collections of threat

Threat Intelligence News from LevelBlue SpiderLabs December 2025 Read More »

Kali Linux 2025.4: New tools and “quality-of-life” improvements

Kali Linux 2025.4: New tools and “quality-of-life” improvements 2025-12-15 at 13:48 By Zeljka Zorz OffSec has released Kali Linux 2025.4, a new version of its widely used penetration testing and digital forensics platform. Most of the changes are related to appearance and usability: Kali’s GNOME desktop environment now organizes Kali tools into folders via the

Kali Linux 2025.4: New tools and “quality-of-life” improvements Read More »

700Credit Data Breach Impacts 5.8 Million Individuals

700Credit Data Breach Impacts 5.8 Million Individuals 2025-12-15 at 13:48 By Ionut Arghire Hackers stole names, addresses, dates of birth, and Social Security numbers from the credit report and identity verification services provider. The post 700Credit Data Breach Impacts 5.8 Million Individuals appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

700Credit Data Breach Impacts 5.8 Million Individuals Read More »

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw 2025-12-15 at 13:22 By Eduard Kovacs Apple has released macOS and iOS updates to patch two WebKit zero-days exploited in an “extremely sophisticated” attack. The post Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw appeared first on SecurityWeek. This article is an excerpt

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw Read More »

Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector

Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector 2025-12-15 at 13:22 By Cybersecurity researchers have disclosed details of an active phishing campaign that’s targeting a wide range of sectors in Russia with phishing emails that deliver Phantom Stealer via malicious ISO optical disc images. The activity, codenamed Operation MoneyMount-ISO by Seqrite Labs,

Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector Read More »

Apple, Google forced to issue emergency 0-day patches

Apple, Google forced to issue emergency 0-day patches 2025-12-15 at 13:01 By Carly Page Both admit attackers were already exploiting the bugs, with scant detail and hints of spyware-grade abuse Apple and Google have both issued emergency patches after zero-day bugs were caught being actively exploited in what the companies describe as “sophisticated” real-world attacks.…

Apple, Google forced to issue emergency 0-day patches Read More »

Why Facebook is a cesspool of scam ads — and it’s making billions off its phony ‘tax’ on fraudsters

Why Facebook is a cesspool of scam ads — and it’s making billions off its phony ‘tax’ on fraudsters 2025-12-15 at 13:00 By Thomas Barrabi Mark Zuckerberg’s Facebook is blamed more often than any other site for hosting scam advertisements that have cost consumers billions of dollars – even as it pockets the profits, according

Why Facebook is a cesspool of scam ads — and it’s making billions off its phony ‘tax’ on fraudsters Read More »

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529)

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529) 2025-12-15 at 12:58 By Zeljka Zorz Apple has issued security updates with fixes for two WebKit vulnerabilities (CVE-2025-14174, CVE-2025-43529) that have been exploited as zero-days. Several days before the release of these updates, Google fixed CVE-2025-14174 in the desktop version of Chrome, though at

Update your Apple devices to fix actively exploited vulnerabilities! (CVE-2025-14174, CVE-2025-43529) Read More »

Scroll to Top