Check Point has detected thousands of phishing emails in the past fortnight, offering fake promotions and special deals – Read More –
Author: Joe-W
The security vulnerability known as React2Shell is being exploited by threat actors to deliver malware families like KSwapDoor and ZnDoor, according to findings from Palo Alto Networks Unit 42 and NTT Security. “KSwapDoor is a professionally engineered remote access tool designed with stealth in mind,” Justin Moore, senior manager of threat intel research at Palo … Read More “React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors – The Hacker News” »
As India moves into the first full year of DPDP Act enforcement, many organisations are realising that compliance is… The post Top 7 DPDP Compliance Challenges for Indian Companies in 2026 appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area – Full Disclosure
Posted by Onur Tezcan via Fulldisclosure on Dec 15 [Attack Vectors] > It was detected that a Stored XSS vulnerability in the “Content Management” > “Blog posts” area. Malicious HTML/JavaScript added to the Body overview field of a blog post is stored in the backend and executes when the blog page is visited (http://localhost/blog/) … Read More “nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Management area – Full Disclosure” »
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. – Full Disclosure
Posted by Onur Tezcan via Fulldisclosure on Dec 15 [Attack Vectors] > It was detected that a Stored XSS vulnerability on the “Currencies” functionality, specifically on the following input field: “Configuration > Currencies > Edit one of the currencies > “Custom formatting” input field. After saving the payload, the vulnerability can be triggered by … Read More “nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. – Full Disclosure” »
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality – Full Disclosure
Posted by Onur Tezcan via Fulldisclosure on Dec 15 [Attack Vectors] > It was detected that multiple Stored Cross-Site Scripting (Stored XSS) vulnerabilities in the product management functionality. Malicious JavaScript payloads inserted into the “Product Name” and “Short Description” fields are stored in the backend database and executed automatically whenever a user (administrator or … Read More “nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality – Full Disclosure” »
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality – Full Disclosure
Posted by Onur Tezcan via Fulldisclosure on Dec 15 [Attack Vectors] > It was identified Cross-Site Request Forgery (CSRF) vulnerability on the “Run now” button of Schedule tasks functionality. Exploiting this vulnerability, an attacker can run a scheduled task without the victim users consent or knowledge. Assigned CVE code: > CVE-2025-65593 [Discoverer] > AlterSec … Read More “nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality – Full Disclosure” »
Posted by Egidio Romano on Dec 15 —————————————————————————– Bitrix24 <= 25.100.300 (Translate Module) Remote Code Execution Vulnerability —————————————————————————– [-] Software Link: https://www.bitrix24.com [-] Affected Versions: Version 25.100.300 and prior versions. [-] Vulnerability Description: The vulnerability is located within the “Translate Module”,… – Read More – Full Disclosure
Posted by Egidio Romano on Dec 15 —————————————————————————— 1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability —————————————————————————— [-] Software Link: https://www.1c-bitrix.ru [-] Affected Versions: Version 25.100.500 and prior versions. [-] Vulnerability Description: The vulnerability is located within the “Translate… – Read More – Full Disclosure
Google has announced that it’s discontinuing its dark web report tool in February 2026, less than two years after it was launched as a way for users to monitor if their personal information is found on the dark web. To that end, scans for new dark web breaches will be stopped on January 15, 2026, … Read More “Google to Shut Down Dark Web Monitoring Tool in February 2026 – The Hacker News” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-2 iOS 18.7.3 and iPadOS 18.7.3 iOS 18.7.3 and iPadOS 18.7.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/125885. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. AppleJPEG Available for: … Read More “APPLE-SA-12-12-2025-2 iOS 18.7.3 and iPadOS 18.7.3 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-3 macOS Tahoe 26.2 macOS Tahoe 26.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/125886. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. App Store Available for: macOS Tahoe Impact: … Read More “APPLE-SA-12-12-2025-3 macOS Tahoe 26.2 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-4 macOS Sequoia 15.7.3 macOS Sequoia 15.7.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/125887. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. AppleJPEG Available for: macOS Sequoia Impact: Processing … Read More “APPLE-SA-12-12-2025-4 macOS Sequoia 15.7.3 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-5 macOS Sonoma 14.8.3 macOS Sonoma 14.8.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/125888. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. AppleJPEG Available for: macOS Sonoma Impact: Processing … Read More “APPLE-SA-12-12-2025-5 macOS Sonoma 14.8.3 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-6 tvOS 26.2 tvOS 26.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/125889. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. AppleJPEG Available for: Apple TV HD and Apple TV … Read More “APPLE-SA-12-12-2025-6 tvOS 26.2 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-7 watchOS 26.2 watchOS 26.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/125890. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. App Store Available for: Apple Watch Series 6 and … Read More “APPLE-SA-12-12-2025-7 watchOS 26.2 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-8 visionOS 26.2 visionOS 26.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/125891. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. App Store Available for: Apple Vision Pro (all models) … Read More “APPLE-SA-12-12-2025-8 visionOS 26.2 – Full Disclosure” »
Posted by Apple Product Security via Fulldisclosure on Dec 15 APPLE-SA-12-12-2025-9 Safari 26.2 Safari 26.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/125892. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Safari Available for: macOS Sonoma and macOS Sequoia Impact: … Read More “APPLE-SA-12-12-2025-9 Safari 26.2 – Full Disclosure” »
Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group) – Full Disclosure
Posted by Yuffie Kisaragi via Fulldisclosure on Dec 15 UPDATE: The reported vulnerabilities have now been assigned CVE identifiers: CVE-2025-34411: https://www.cve.org/cverecord?id=CVE-2025-34411 [https://www.cve.org/cverecord?id=CVE-2025-34411] CVE-2025-34412: https://www.cve.org/cverecord?id=CVE-2025-34412 [https://www.cve.org/cverecord?id=CVE-2025-34412] – Read More – Full Disclosure
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality – Full Disclosure
Posted by Onur Tezcan via Fulldisclosure on Dec 15 [Attack Vectors] > It was detected that a Stored XSS vulnerability in the Attributes management workflow. An attacker can insert JavaScript into the Name field when adding a new Attribute Group (Catalog > Attributes > Specification attributes > Add Group > Name input field). To … Read More “nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality – Full Disclosure” »
Opexus admits it missed key red flags when it hired twins Muneeb and Sohaib Akhter, as it failed to learn about crimes the brothers pleaded guilty to in 2015, including wire fraud and conspiring to hack into the State Department — offenses committed while they were contractors for federal agencies. The federal government contractor nonetheless … Read More “Opexus claims background checks missed red flags on twins accused of insider breach – CyberScoop” »
The American Bar Association believes the use of artificial intelligence in the legal sector is eroding key procedures, documentary records and evidence relied on to establish ground-level truth in the court system. In a report released this month the ABA, which sets ethical standards for the legal profession and oversees the accreditation of roughly 400,000 … Read More “AI is causing all kinds of problems in the legal sector – CyberScoop” »
Opexus admits it missed key red flags when it hired twins Muneeb and Sohaib Akhter, as it failed to learn about crimes the brothers pleaded guilty to in 2015, including wire fraud and conspiring to hack into the State Department — offenses committed while they were contractors for federal agencies. The federal government contractor nonetheless … Read More “Opexus claims background checks missed red flags on twins accused of insider breach – CyberScoop” »
GitHub Scanner for React2Shell (CVE-2025-55182) Turns Out to Be Malware – Hackread – Cybersecurity News, Data Breaches, AI, and More
A GitHub repository posing as a vulnerability scanner for CVE-2025-55182, also referred to as “React2Shell,” was exposed as… – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
A new phishing campaign has been identified, delivering the Phantom information-stealing malware via an ISO attachment – Read More –
A Minnesota man has pleaded guilty to a credential stuffing scheme that compromised over 60,000 accounts – Read More –
Hamas Linked Hackers Using AshTag Malware Against Diplomatic Offices – Hackread – Cybersecurity News, Data Breaches, AI, and More
New report by Unit 42 reveals the Hamas-linked Ashen Lepus (WIRTE) group is using the AshTag malware suite to target Middle Eastern diplomatic and government entities with advanced, hidden tactics. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
16TB of MongoDB Database Exposes 4.3 Billion Lead Gen Records – Hackread – Cybersecurity News, Data Breaches, AI, and More
Cybersecurity researchers discovered an unsecured 16TB database exposing 4.3 billion professional records, including names, emails, and LinkedIn data. Learn what happened, why this massive data leak enables new scams, and how to protect your PII. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE – The Hacker News
Multiple security vulnerabilities have been disclosed in the open-source private branch exchange (PBX) platform FreePBX, including a critical flaw that could result in an authentication bypass under certain configurations. The shortcomings, discovered by Horizon3.ai and reported to the project maintainers on September 15, 2025, are listed below – CVE-2025-61675 (CVSS score: 8.6) – Numerous – … Read More “FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE – The Hacker News” »
Coupang CEO Steps Down After Data Breach Hits 33.7 Million Users – Hackread – Cybersecurity News, Data Breaches, AI, and More
South Korean e-commerce giant Coupang faces intense scrutiny after CEO Park Dae-jun resigns over a data breach that exposed 33.7 million customer accounts. Read about the police raids, US lawsuit, and regulatory orders from PIPC. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
In early December 2025, security researchers exposed a cybercrime campaign that had quietly hijacked popular Chrome and Edge browser extensions on a massive scale. A threat group dubbed ShadyPanda spent seven years playing the long game, publishing or acquiring harmless extensions, letting them run clean for years to build trust and gain millions of installs, … Read More “A Browser Extension Risk Guide After the ShadyPanda Campaign – The Hacker News” »
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More – The Hacker News
If you use a smartphone, browse the web, or unzip files on your computer, you are in the crosshairs this week. Hackers are currently exploiting critical flaws in the daily software we all rely on—and in some cases, they started attacking before a fix was even ready. Below, we list the urgent updates you need … Read More “⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More – The Hacker News” »
MITRE has released its Top 25 CWE list for 2025, compiled from software and hardware flaws behind almost 40,000 CVEs – Read More –
Asahi Group’s CEO said he is considering creating a dedicated cyber unit following the ransomware attack that crippled the company – Read More –
Cybersecurity researchers have disclosed details of an active phishing campaign that’s targeting a wide range of sectors in Russia with phishing emails that deliver Phantom Stealer via malicious ISO optical disc images. The activity, codenamed Operation MoneyMount-ISO by Seqrite Labs, has primarily singled out finance and accounting entities, with those in the procurement, legal, payroll … Read More “Phantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector – The Hacker News” »
Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide – Hackread – Cybersecurity News, Data Breaches, AI, and More
Torrance, United States / California, December 12th, 2025, CyberNewsWire In December 2025, CVE-2025-55182 (React2Shell), a vulnerability in React… – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
The UK’s National Cyber Security Centre has called on businesses to apply Cyber Essentials to suppliers – Read More –
A fundamental change is in progress across the GCC: data privacy is to no longer be a box that… The post Data Privacy vs Compliance: Why Zero Trust Is the Future for GCC Companies appeared first on JISA Softech Pvt Ltd. – Read More – JISA Softech Pvt Ltd
The pro-Russian hacktivist group known as CyberVolk (aka GLORIAMIST) has resurfaced with a new ransomware-as-a-service (RaaS) offering called VolkLocker that suffers from implementation lapses in test artifacts, allowing users to decrypt files without paying an extortion fee. According to SentinelOne, VolkLocker (aka CyberVolk 2.x) emerged in August 2025 and is capable of targeting both Windows … Read More “VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption – The Hacker News” »
UK’s ICO Fine LastPass £1.2 Million Over 2022 Security Breach – Hackread – Cybersecurity News, Data Breaches, AI, and More
UK’s ICO fines LastPass £1.2M for the 2022 data breach that exposed 1.6 million users’ data. Learn how a flaw in an employee’s personal PC led to the massive security failure. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity flaw impacting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. CVE-2018-4063 (CVSS score: 8.8/9.9) refers to an unrestricted file upload vulnerability that could be exploited to achieve remote code – … Read More “CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks – The Hacker News” »
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; … Read More “Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution – Cyber Security Advisories – MS-ISAC” »
Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that it said have been exploited in the wild, one of which is the same flaw that was patched by Google in Chrome earlier this week. The vulnerabilities are listed below – … Read More “Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild – The Hacker News” »
Fake Microsoft Teams and Google Meet Downloads Spread Oyster Backdoor – Hackread – Cybersecurity News, Data Breaches, AI, and More
The Oyster backdoor (also known as Broomstick) is targeting the financial world, using malicious search ads for PuTTY, Teams, and Google Meet. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
Development Team Augmentation: A Strategic Approach for High-Performance Teams – Hackread – Cybersecurity News, Data Breaches, AI, and More
Scale software teams fast with development team augmentation. Learn when it works best, key models, common mistakes, and how to choose the right partner. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
The Department of Justice is suing Fulton County, Georgia and its election clerk over the county’s refusal to hand over voter records, part of a larger nationwide project to collect as much election and voter information as possible from state and local governments ahead of the 2026 and 2028 elections. In a lawsuit announced Thursday, … Read More “DOJ sues Fulton County over 2020 voter data – CyberScoop” »
New PyStoreRAT Malware Targets OSINT Researchers Through GitHub – Hackread – Cybersecurity News, Data Breaches, AI, and More
A new malware called PyStoreRAT is being through fake OSINT tools on GitHub targeting IT and OSINT pros. Read Morphisec’s report detailing how it uses AI and evades security. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
Cybersecurity researchers are calling attention to a new campaign that’s leveraging GitHub-hosted Python repositories to distribute a previously undocumented JavaScript-based Remote Access Trojan (RAT) dubbed PyStoreRAT. “These repositories, often themed as development utilities or OSINT tools, contain only a few lines of code responsible for silently downloading a remote HTA file and executing – Read … Read More “Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads – The Hacker News” »
What Happens Inside PDFAid in Seconds: From Upload to Download – Hackread – Cybersecurity News, Data Breaches, AI, and More
Disclosure: This article was submitted by PDFAid for publication. – Read More – Hackread – Cybersecurity News, Data Breaches, AI, and More
President Donald Trump announced Thursday his intention to issue a federal pardon for an individual convicted in connection with efforts related to challenging the 2020 election results. However, on this occasion, the person in question will remain behind bars. In a statement on Truth Social, Trump said he was pardoning Tina Peters, a former Mesa County … Read More “Trump moves to pardon Colorado election clerk Tina Peters, even though he can’t – CyberScoop” »